How to choose a secure WordPress password

What makes a password secure?

It might be hard to understand the way a hacker thinks, but doing so helps you keep your login screen secure. Your business name or personal details about you like your address, children’s names or pets all make for weak passwords.

(I bet it would take you less than 5 minutes to learn the names of my dogs, which means someone that wants to break into my site could do the same.)

Beyond avoiding the basic details of your life, picking a winning password means avoiding patterns, making sure it’s not common + that it’s hard, if not impossible, to guess.

Which means that this list of popular passwords is bad news bears for your WordPress site security —

  • 123456789
  • 111111
  • password

It doesn’t have to be impossible for you to pick a strong password though! In fact, there are tools that will help you make sure your site password is secure —

  • Trust WordPress to tell you if your new password really is strong
  • Or use a password generator to create a random password
  • Save your new + secure password to a password vault
how to choose a secure WordPress password // tiny blue orange

See, even WordPress knows brutus would be a terrible password for me to use. Sorry Brubru!

Set your new secure password

Changing your WordPress password to the option you just picked is really easy. It’s 4 steps + will take you less than 60 seconds if you’re already logged into your site.

  1. From your dashboard, head to Users > Your Profile
  2. Scroll to the bottom Account Management section
  3. Click “Generate Password”
    (Either use what WordPress suggests or type in your new one)
  4. Click “Update Profile”

Voila! now your WordPress site is way more secure than it was for however long you were using your old + weak password. Feels good, doesn’t it?

If you have any other administrator level users on your website, share this article with them so they can update their passwords too.

Remember, your site is only as secure as the weakest link — whether that’s your weaksauce password, another user or another site on your shared server.

on your keyboard hit enter to search or esc to close