Skip to content
UK web hosting, domain names, email, website security and online services.

Secure a new WordPress website Print

  • security, hosting, wordpress, malware
  • 0

Harden WordPress without relying on one plugin or hiding the login page as the only security control.

Applies to: WordPress on Tudor Internet Web Hosting

WordPress problems often come from the interaction between PHP, plugins, themes, caching, scheduled tasks and database state. Change one item at a time, record what you changed and keep a known-good backup before updates or repairs.

Before you start

  • Sign in to the Customer Portal and open the affected hosting service.
  • Take a current backup before changing website files, databases, DNS or application configuration.

How to use this service

  1. Update WordPress core, every active theme and every plugin before adding content or opening the site to visitors.
  2. Remove unused plugins and themes rather than merely deactivating them, while keeping one current default theme for recovery testing.
  3. Give each administrator an individual account, use strong unique passwords and avoid routine publishing from a full administrator account.
  4. Confirm that file permissions are restrictive, wp-config.php is not writable by the web application unnecessarily and no backup archive is stored in the public document root.
  5. Enable automatic maintenance updates appropriate to the site and create a documented process for testing feature updates.
  6. Protect forms and login endpoints with rate limiting, CAPTCHA or application controls where abuse is observed; do not block legitimate administrators without a recovery route.
  7. Review Imunify360 and SiteLock results, but also monitor WordPress users, scheduled tasks and recent file changes because a scanner cannot prove the site is uncompromised.
  8. Keep an independent backup and test a restore before making major security or plugin changes.

Confirm the result

  • The intended hostname loads over HTTPS from a private browser session and serves the correct website.
  • Forms, database-driven pages and the administration area work without a new PHP, permission or redirect error.

Common problems

SymptomLikely causeWhat to do
WordPress shows a critical error or blank page.A plugin, theme, PHP version or exhausted resource caused a fatal error.Check the PHP error log, disable only the last changed component and restore a known-good copy if the administration area is unavailable.
The site works until cache is cleared or a plugin updates.Generated cache, stale object data or incompatible code is masking the underlying fault.Test with caching disabled on a staging copy, update one component at a time and confirm PHP compatibility before re-enabling cache.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The affected domain and SiteWorx account
  • The exact error text and time
  • The last change made
  • Relevant log lines with passwords and personal data removed
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back