> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.ex2.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Why secure a WordPress website?

A secure Wordpress website allows, first of all, to protect the data that circulates between your website and your visitors. 

Second, it helps to strengthen the visitor’s confidence in your website and finally it allows to be better referenced by the natural referencing.

# Here are a few steps to make your Wordpress website safer.

1.  Keep your Wordpress [CMS](https://help.ex2.com/en/article/what-is-a-content-management-system-or-cms-1c48kdh/?bust=1784052067814) up to date. Be sure to always keep your Wordpress website up to date. When you go to your Wordpress dashboard, they will warn you when your website is not up to date.

2.  Keep your plugins and themes up to date. In your dashboard, in the updated option, Wordpress will tell you if there are any updates to be made.
3.  Backups regularly. By holding several backups of your website, in case of problems you can easily put a functional backup online in a few seconds. The plugins we recommend for backups: [JetPack](https://fr.wordpress.org/plugins/jetpack/) or [Duplicator](https://wordpress.org/plugins/duplicator/).

4.  Limit login attempts and change passwords regularly. Several plugins allow. It’s about finding the best one for you. Here are two free examples: [Login LockDown](https://wordpress.org/plugins/login-lockdown/) or [WP Limit Login Attempts](https://fr.wordpress.org/plugins/wp-limit-login-attempts/).

5.  You can install a firewall on your website. Again, this will be through plugins. Here are two good examples: (https://wordpress.org/plugins/better-wp-security/) and [Wordfence Security](https://wordpress.org/plugins/wordfence/).

6.  Rename your Wordpress access. The url to access your Wordpress (www.example.com/wp-admin). You can do this easily and quickly with the plugin [iThemes Security](https://wordpress.org/plugins/better-wp-security/).

7.  Finally, protect your wp-config.php by moving it from the root directory. Hackers can no longer find it.