Special OfferSave up to 35% on multi-year hosting plans + Free AutoSSL & Domain setup!
Get Started
GuideSSL & Security

Website Hardening Guide: Defending Against Brute Force, Malware, and Exploits

Essential security measures: protecting wp-login.php, file permissions (644/755), disabling XML-RPC, and cPanel virus scanning.

Hostinov Engineering TeamUpdated: 2026-09-173 min read6,100 views285 found helpful
Tags:#SSL & Security#Hosting#Cloud

Core Security Hardening Steps#

  1. 1
    Protect wp-login.php: Limit login attempts using plugins like Wordfence or LiteSpeed Cache reCAPTCHA.
  2. 2
    Disable XML-RPC: If you do not use the WordPress mobile app, block XML-RPC in .htaccess to prevent DDoS amplification:
apache
<Files xmlrpc.php>
Order Allow,Deny
Deny from all
</Files>
  1. 1
    Correct File Permissions: Folders must be 0755 and files 0644. Sensitive files like wp-config.php should be 0600 or 0640.
  2. 2
    Virus Scanner: Run periodic scans in cPanel -> Virus Scanner to inspect public_html for known webshells and malware.

Was this article helpful to you?

Your feedback helps our sysadmins keep technical guides accurate.

24/7 Priority Support

Need a sysadmin to configure this for you?

Our tier-3 systems architects are available 24/7 to assist with migration, DNS records, or SSL issues.