Patch on a schedule

Core, themes and plugins, checked weekly. The overwhelming majority of compromised sites were running a version with a published fix available for months.

Reduce what is exposed

Practical measures:

  • Remove themes and plugins you do not use
  • Disable file editing in the dashboard
  • Enforce strong passwords and 2FA for admins
  • Limit login attempts

Assume it will happen anyway

Keep off-server backups and know how to restore them. Recovery time is what turns a compromise into an inconvenience rather than a crisis.