iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The gaps that most often weaken a WordPress site are rarely exotic. In a review of 20 WordPress security audits, Elsie Rainee of WPWeb Infotech found the same five kinds of problem recurring: outdated software, weak account and permission controls, backups that were never restored, hosting and configuration issues, and security tools that were installed but never properly set up or treated as a complete defense. Those findings are the author’s account of the audits she read. The article does not name or link the 20 reports, and it does not describe how they were selected or scored, so the patterns should be read as observations rather than measured prevalence.
What the review can and cannot tell you
The author compared the issues each audit uncovered, then looked for patterns that repeated across reports. That approach is useful for spotting where routine maintenance tends to slip. It does not show how common any single problem is across all WordPress sites. Official WordPress documentation can confirm whether the recommended fixes are sensible, but it cannot confirm the cross-audit pattern itself. Treat the five areas below as a checklist of places to look, not as a ranking of risk.
Blind spot 1: Outdated software, beyond WordPress core
Most site owners know to update WordPress itself. The review’s recurring concern is that core is only one layer. Plugins, themes, and anything installed on the site can each carry their own exposure, and an update to core does nothing for a plugin that has been left behind.
WordPress core
WordPress’s official Advanced Administration Handbook, last published on March 28, 2023, states: “Older versions of WordPress are not maintained with security updates.” WordPress.org says its security team officially supports only the latest release and backports some fixes to older versions as a courtesy. Running a version that is one release behind is therefore not the same as running a supported one. Check the current support statement on WordPress.org before deciding how far behind is acceptable, because support windows change.
#1 Best Overall
Inactive plugins and themes
The review flagged components that remain installed but are no longer used. Deactivating a plugin does not remove its files from the server, and each installed component is something that must be kept current or removed. A practical rule: if you would not reinstall it today, delete it, and do not leave unused themes sitting in the directory as spares.
Custom and theme code
The WordPress Theme Handbook, last updated January 26, 2024, describes cross-site scripting (XSS) as JavaScript injection into a page and states: “To avoid XSS vulnerabilities, any output should be escaped.” The handbook recommends using the escaping function appropriate to the type of data being output. If you commission custom functionality, ask the developer to confirm that dynamic output is escaped. That question is easy to ask and easy to overlook.
Blind spot 2: Old administrator accounts and loose permissions
The review repeatedly found accounts that no longer matched anyone’s current job: former contractors, old editors promoted to administrator, and shared logins. Official hardening guidance points in the same direction. It recommends reviewing whether each account still needs access and whether its role is appropriate.
Rank #2
To check this in the WordPress admin, go to Users > All Users and filter by role. For each account with the Administrator role, confirm that the person still works on the site, that they need full administrative rights, and that they use their own login. Downgrade accounts that only need to publish content to Editor or Author, and delete accounts for people who have left. Before deleting, reassign any content the account owns.
Blind spot 3: Backups that were never restored
The author’s central point on recovery is direct: “A backup is only useful if you can actually restore the website from it.” Official WordPress guidance recommends regular backups and addresses integrity and trusted storage. It does not require a particular backup product or physical medium, so the important question is whether your backup can be restored when needed, not which tool created it.
A restore test is the only way to find out. Run it on a staging copy or a separate environment so the live site is not affected:
- Restore the most recent backup to a separate environment, including both files and the database.
- Load the public front end and check that the pages, images, and menus appear as expected.
- Log in to /wp-admin with an existing account to confirm the admin area works.
- Open the Plugins screen and confirm that every plugin that should be active is active and loads without errors.
- Submit a test form or check a feature that depends on the database, such as a search or a cart.
- Record how long the restore took and any steps that needed manual fixes, then update your recovery notes.
A backup that restores cleanly once is still worth retesting after major changes to plugins, hosting, or the database.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Blind spot 4: Hosting and environment-specific configuration
The review grouped hosting and configuration together because settings that suit a development site can be unsafe on a live one, and the host’s responsibilities are not always clear to the owner. The official hardening guidance says to use secure, stable server software or a trusted host, and it advises keeping the administrator’s own computer free of malware, since a compromised admin machine can expose the site.
When you review configuration, focus on the points where the site and the host overlap:
Rank #4
- Is debugging output turned off on the live site, so errors are not displayed to visitors?
- Are file permissions set so that the web server can read what it needs but visitors cannot change core files?
- Is login access restricted to secure connections, and is access to the database limited to the site itself?
- Does the host provide a documented backup schedule, and is it clear whether restores are your job or theirs?
- Who applies server software updates, and how do you find out when a patch has been applied?
Written answers to these questions make it clear where the host’s responsibility ends and yours begins.
Blind spot 5: Security tools installed but not configured
The author states the most common shortcut bluntly: “Plugin installed = website protected.” She rejects the idea, noting that a plugin cannot decide who should keep administrator access, and cannot guarantee that a backup will restore. A security plugin is one control among several. It works only when it is configured for your site and its alerts reach someone who acts on them.
Free tools Windows power users keep installed
One-click scans. No signup required.
After installing or reviewing a security plugin, confirm the following: which features are switched on, who receives alert emails, how often logs are reviewed, and what happens when the plugin flags a problem. A plugin that sends alerts to a former employee’s inbox provides little protection.
Best Value
Reading the 2024 disclosure figures in context
Several statistics about WordPress vulnerabilities are often quoted without their meaning. Wordfence’s 2024 Annual WordPress Security Report, published April 2025, reports the following for vulnerabilities disclosed in 2024:
| Vulnerability type | Disclosures in 2024 | Share reported by Wordfence |
|---|---|---|
| Cross-site scripting (XSS) | 3,795 | 46% |
| Missing authorization | 1,178 | 13% |
Wordfence also reports that plugins accounted for 96% of WordPress vulnerabilities disclosed in 2024. These are counts of published disclosures. They are not a count of vulnerable live sites, and they do not measure the probability that any particular site will be compromised. The same report distinguishes factors such as whether an attack requires authentication or user interaction, which affect how serious a given disclosure is for a specific site. Use the figures to decide where to look first, not to estimate your own risk.
A routine check built from these patterns
The review does not set a fixed schedule. As a practical starting point, many site owners review updates and accounts monthly, and run a restore test after any significant change. Work through these steps in order:
- Open Dashboard > Updates and confirm that WordPress core, plugins, and themes are current. Confirm that the core version is still one that WordPress.org supports.
- Open Plugins and delete any plugin or theme that is inactive and no longer needed.
- Open Users > All Users, review every Administrator account, and reduce roles or remove accounts that are no longer needed.
- Restore your latest backup to a separate environment and complete the test steps listed in the backup section.
- Check the configuration questions in the hosting section, and write down the host’s answers about backups, updates, and responsibilities.
- Confirm that your security plugin’s alerts reach an active address, and that someone reviews them on a schedule.
Each step is small, and most of them can be completed in under an hour on a typical site. Their value comes from repeating them, because the blind spots the review describes tend to reappear after updates, staff changes, and host migrations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

