
ALWAYS use MultiFactor authentication.
Wordfence is excellent and free.
- Don’t save your passwords in a password manager online.
- Use WordPress plugins that have good reputation.
- Never use the default “admin” as the username for the login.
- Keep WordPress core things and plugins updated.
- Use strong login protection, because brute force attacks target weak passwords and default user names.
- Regular backups are important.
- Enforce SSL on HTTPS because it encrypts the data.
