Most hacks exploit outdated software and weak passwords, so start there.
- Keep WordPress core, themes and plugins updated, and delete anything you don't use.
- Use strong, unique passwords and enable two-factor authentication for admin logins.
- Install a reputable security plugin (Wordfence or Sucuri Security) for a firewall and malware scanning.
- Limit login attempts and never use the username
admin. - Make sure your free SSL is active so logins are encrypted.
Take regular backups (UpdraftPlus or cPanel backups) so you can restore quickly. Only install plugins and themes from trusted sources. If you suspect your site is already compromised, open a ticket so we can help check the server side.