Home / Blog / Securing WordPress
Blog · Speed & security

SECURING WORDPRESS IN 2026: THE EIGHT SETTINGS THAT PREVENT 90% OF HACKS

Hidden login, user enumeration, XML-RPC, updates, backups, headers, firewall, AI bots: the concrete settings, and how to check yours in thirty seconds.


By Arnaud Poirier, freelance web & software developer, Antibes
In brief
  • Eight settings: updates, hidden login, enumeration blocked, XML-RPC disabled, limited attempts, headers, backups, monitoring.
  • Hacks come from bots testing known vulnerabilities, not targeted attacks.
  • AI bots are managed in robots.txt depending on whether you want to be cited or save the server.

WordPress hacks are not targeted attacks. They are bots testing thousands of sites per hour for the same known vulnerabilities. Closing those doors takes an hour.

The eight settings

  1. Updates applied, core, theme, extensions, within the week. It is the first door, by far.
  2. Hidden login page : wp-login.php is known to every bot. A different address cuts attempts by 95%.
  3. User enumeration blocked : by default, WordPress lists your login names to anyone who asks. The bot only has the password left to guess.
  4. XML-RPC disabled : an old interface used for brute-force attacks, useless for most sites.
  5. Limited attempts at login and two-factor authentication for administrators.
  6. Security headers (HSTS, X-Frame-Options, Content-Security-Policy): they protect your visitors, and Google looks at them.
  7. Off-server backups, daily, and a tested restore. The day it happens, that is what saves you.
  8. Monitoring : modified files, unusual logins, site no longer responding. Someone must be alerted.

New in 2026: AI bots

Bots crawl sites to train models or feed answer engines. They consume bandwidth and can slow down a small host. We allow or block them in the robots.txt file and at server level, depending on what you want: to be cited by assistants, or to save your server.

Check in thirty seconds

The free audit tests points 2, 3, 4 and 6 on your home page and tells you which are open. The others are checked in your maintenance contract. If you do not have one, now is the time to talk about it.

Frequently asked questions

How do I know if my WordPress is exposed?+
The free audit tests the login page, user enumeration, XML-RPC and security headers in thirty seconds.
Should AI bots be blocked?+
It is a choice: allow them to be cited by assistants, or limit them to protect a small host.
Is two-factor authentication necessary?+
Yes for administrator accounts, with a limit on login attempts.
Free · no sign-up

How is your website doing? Answer in 30 seconds.

Loading, SEO, security, calls to action: more than forty criteria, a score out of 100, your strengths, your weaknesses and an explained action plan. Brochure site or store. Completely free.

Instant result on audit.arnaud-poirier.com. No data kept without your consent.

READY
TO LAUNCH
YOUR PROJECT ?
Calendly — 30 min Contact form ⚡ Free audit of my website 07 64 02 74 14
First call free, no contract.
Reply within 24 working hours, French Riviera & France.
Free auditof your website · 30 s