0
Skip to content
WordPress security: passkeys, MFA and WAF

Technology

WordPress security: passkeys, MFA and WAF

Passkeys, MFA and a WAF address different parts of the problem. WordPress security needs layers: restricted accounts, current code, traffic protection, tested backups and an incident-response procedure.

Reduce the attack surface

We remove unused plugins and themes, update supported components and restrict roles to what each person needs. People use separate accounts rather than shared administrator credentials. Hosting and domain access follow the same discipline.

Strengthen sign-in

MFA adds another factor, while passkeys can reduce password and phishing risk when the full recovery process is protected just as carefully. We test sign-in, a lost device, employee departure and emergency access.

Treat a WAF as one layer

The official WordPress guide describes filtering traffic through a web application firewall before WordPress handles a request. A WAF does not replace updates or correct permissions. We monitor rules for blocking legitimate users.

Documentation: WordPress Developer Resources.

Prepare recovery

A backup includes files and the database from a consistent point. It is kept outside the live environment with defined retention. We perform recovery tests, because the mere existence of an archive does not show it can be used.

Monitor changes and incidents

We record administrative sign-ins, updates, file changes and material alerts. The procedure identifies who isolates the problem, preserves evidence, restores service and changes credentials. After an incident, we remove the cause rather than only the visible symptom.

Newsletter

Join our newsletter for updates and practical insights on digital marketing.