The WordPress security checklist: 54 checks, explained
A WordPress security checklist is only useful if it tells you what to look at first and what to do next. A list with no order leaves you guessing which items matter on your site.
BetterShield runs a WordPress security audit of 54 read-only checks in five areas: Access, Exposure, Updates & extensions, Server and Configuration. This guide covers the checks that matter most in each area, how the score works, and a sensible order for working through what the audit finds.
Quick summary
- The audit is 54 read-only checks. Running it changes nothing on your site.
- The score starts at 100. Each open finding takes off 25, 12, 7, 3 or 0 points by severity, and 90 or more is an A.
- Five checks have an Apply fix button. Others link to the screen that handles them, where there is one.
- Work from the most severe finding down. Snooze what has a real reason to wait, and mark Not applicable only what never applies.
- The vulnerability check is built, but 1.1.0 connects no data source for it, and the Findings screen says so.
How the score and grade work
The score starts at 100. Each open finding takes points off by severity, down to 0: 25 for Critical, 12 for High, 7 for Medium, 3 for Low and none for Info.
The grade follows: A from 90, B from 75, C from 60, D from 45, and F below that. One High finding and two Low ones give 82, a B.
- A snoozed finding still counts. One marked Not applicable does not.
- A check that could not run is never counted as a pass. The Overview lists it under What could not be checked.
- The audit runs on activation, once a day, and when you press Run audit in the bar at the top of each BetterShield screen.
The WordPress security checklist, area by area
The full checklist has all 54 checks. Below are the few in each area most worth knowing, titled as they appear on BetterShield › Findings.
Access (14 checks)
Access is who can sign in, and as whom. Most of these are settings, so they are quick to put right.
| Finding | Severity | What to do |
|---|---|---|
| Nothing is limiting sign-in attempts | High | Switch on Pause sign-in after repeated failures under Protect › Login & Access. It usually appears when a security plugin kept that job during setup and was later removed. |
| Anyone can register, and new accounts get more than reader access | High | Press Open the membership setting, then set the default role to Subscriber or turn off open registration. |
| An account that can change this site has not been used for a long time | Medium | Press Open Users and remove or demote the account. Check first: it may belong to someone on leave. |
| User profiles are publicly listable | Low | Apply fix turns on Block public user listing. |
If “Sign-in lockouts are not running” appears instead, name the proxy in front of your site under Trusted proxies on the same screen. See the Login & Access guide.
Exposure (14 checks)
Exposure is what the site hands to a stranger who asks. The two most serious checks here do not guess: they request each address and report only what came back.
| Finding | Severity | What to do |
|---|---|---|
| A stranger can download something from this site that should not be there | Critical | Remove the file, keeping a copy outside the web root first. These are usually deploy leftovers or editor backups, and often hold credentials. |
| A leftover installer or database tool can be opened from the web | Medium to Critical, by tool | Press Quarantine beside the tool. You can put it back from the quarantine list on the Files screen. |
| XML-RPC is enabled | Medium | Apply fix turns on Disable XML-RPC. It can break publishing from the WordPress mobile app, so if you use it, try Monitor first on Protect › Hardening. |
| The dashboard file editor is enabled | Medium | Apply fix. Files stay editable over SFTP and through your host. |
Two Low findings here also have one-click fixes: “Common security response headers are missing” and “The WordPress version is published in every page”.
Updates & extensions (11 checks)
This area is code that came from somewhere else, and how current it is.
| Finding | Severity | What to do |
|---|---|---|
| Files no longer match the official copies | Critical (Medium when the only changes are extra files at the install root) | Press Open the file report. For a core or directory plugin file, Show the difference compares it line by line, and Put the official file back restores it, keeping your copy in quarantine. Expected marks a deliberate edit. |
| A WordPress core update is available | High | Press Open Updates and update. |
| Plugins have updates available | Medium | Update from Dashboard › Updates. Test on staging first if a plugin is business-critical. |
| An installed plugin is no longer in the WordPress.org directory | Medium | No further updates will come. Check the author’s own site, then decide whether to replace or remove it. |
Note: The check against published vulnerability advisories is built, but no data source is connected in 1.1.0. The Findings screen says so rather than showing an empty list as clean. More on files in the File changes guide.
Server (8 checks)
Server checks cover the machine underneath, and the fix is usually in your hosting panel.
| Finding | Severity | What to do |
|---|---|---|
| The site address is not HTTPS | Critical on a live site, High on a local or staging one | Get a certificate from your host, then switch the address under Settings › General. On a development machine, set WP_ENVIRONMENT_TYPE to local in wp-config.php. |
| This PHP version no longer receives security fixes | High | Choose a newer PHP version in your hosting control panel, then test the site. |
| wp-config.php can be written by other accounts on the server | High | Set the file to 0644 or stricter in your host’s file manager or SFTP client. |
| Scheduled work has stopped running | Medium | Set up a system cron that runs wp-cron.php, or wp cron event run --due-now, every few minutes. |
Configuration (7 checks)
Configuration is how this installation was set up, mostly in wp-config.php and your domain’s DNS.
| Finding | Severity | What to do |
|---|---|---|
| The secret keys in wp-config.php are missing or unchanged | High | Replace the eight key lines in wp-config.php with a fresh set from the WordPress.org secret-key generator. Everyone is signed out once; no password changes. |
| Debug output is shown to visitors | High on a live site, Medium elsewhere | Set WP_DEBUG_DISPLAY to false in wp-config.php. |
| The domain’s mail policy or certificate record could be stronger | Low | Add or correct SPF, DMARC and CAA records where your domain is managed. Start DMARC at p=none and read its reports before tightening it. If mail could pass as the site’s own, the finding is Medium, with a title that says so. |
| No recognized backup plugin is active | Low | Confirm where your backups live and that one can be restored. If your host handles them, mark it Not applicable, and it stays settled. |
How to secure a WordPress site, one finding at a time
- Start with Worth doing first. On BetterShield › Overview, up to three open findings with a one-click fix are listed, most serious first.
- Work down Findings. On BetterShield › Findings, the area with the most serious finding comes first, and rows run from most to least serious.
- Read before you act. Explain shows Why it matters, What could break, Effect on the score and the Evidence.
- Act on it. Apply fix turns the fix on straight away; undo it from Protect › Hardening, where Preview the change shows what a fix does first. A finding without a one-click fix offers a button to its screen where there is one, such as Open Users.
- Snooze what has to wait. Remind me later offers In 7 days or In 30 days. The finding moves to Snoozed, still counts, and comes back early if it gets worse.
- Mark Not applicable only what will never apply. It leaves the score, and Put back in the report returns it.
- Confirm. After a change made by hand, press Run audit. A finding that now passes moves to Fixed.
The full guide is Score and findings.
Common mistakes
- Using Not applicable to lift the score. If the reason is temporary, snooze the finding instead and let it keep counting.
- Applying a fix without reading What could break. Disabling XML-RPC, for example, can stop publishing from the WordPress mobile app.
- Hardening sign-in with no way back in. Keep the recovery link emailed at activation (single use, valid for 90 days), and issue and print eight recovery codes under Protect › Recovery. See the Locked out guide.
- Assuming every change undoes cleanly. People signed out by a sign-in key rotation stay signed out, and a browser that saw a six-month HSTS setting keeps insisting on HTTPS until it expires. See Hardening.
- Expecting the key rotation fix to clear the secret-keys finding. Strengthen and rotate the sign-in keys mixes a stored secret into the keys. It does not change the wp-config.php lines the check reads.
Frequently asked questions
Does the WordPress security audit change anything on my site?
No. All 54 checks only read, and nothing is changed to produce the score. The 16 one-click fixes are all off until you choose one, and each can show what it will change first.
Does BetterShield detect vulnerable plugins?
Not yet. The check against published advisories is built, but no data source is connected in 1.1.0. Today it flags plugins the WordPress.org directory has closed or that have had no update for years, and any core or directory plugin file that no longer matches the official copy.
How often does the audit run?
On activation, once a day, and whenever you press Run audit. From the terminal, wp bettershield audit prints the score, grade and open findings, and --fail-under=80 or --fail-on=high make it exit non-zero for a script. See WP-CLI commands.
Does a snoozed finding still lower my score?
Yes. It stays open and keeps its points off until it is fixed. Only a finding marked Not applicable leaves the score.
Conclusion
A good WordPress security checklist has a clear top: the few findings that cost the most points and have an obvious next step. Start with Worth doing first, work down Findings by severity, and let Run audit confirm each change.
BetterShield is free on WordPress.org. Keep the checklist open beside the Findings screen as you go.