• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / Security: Protecting WordPress Site

Security: Protecting WordPress Site

  • Unknown's avatar
    koolbeanz247 · Member · Aug 29, 2025 at 3:11 am
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    Does wordpress have security settings to enable 2FA verification and passkeys etc. I currently login with password and receive a six digit code to login. Is this method secure. I also heard passkeys are secure as well. The only thing i hate about this is that once I receive the code to my phone I don’t know if its encrypted or not cuz sms messages are usually not encrypted. And I don’t want anybody else having access to the verification code like scammers hackers etc. Is having my phone number connected to my site also secure

    But does wordpress.com have security measures already in place to protect your site as well or is security only on us

    I just wanna make sure my site is protected 💯. God for bid if my site was to ever get hacked how would I know. I don’t know anything about hacking

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar
    sajjadisbrilliant · Member · Sep 15, 2025 at 3:47 pm
    • Copy link Copy link

    Hey, I hear you—keeping your site and account secure is really important, and it’s great that you’re already using two-step authentication with SMS. Just keep in mind that SMS can sometimes be intercepted (through SIM swapping, phone theft, and similar risks). A stronger and more modern option is using passkeys. While having your phone number connected is useful, it also means that if someone gains access to your phone or SIM, they could receive your codes. And if backup codes aren’t saved (or you lose access to your authenticator device), recovering your account can be difficult.

    Here are some options you have on WordPress.com:

    • Two-Step Authentication (2FA): Already enabled on your account. Along with SMS codes, you can use an authenticator app (more secure than SMS) or add a passkey/physical security key for the strongest protection.
      Learn more:
      https://wordpress.com/support/security/two-step-authentication/
      https://wordpress.com/support/security/two-step-authentication/security-key-authentication/
    • Backup codes: These are one-time codes you can keep somewhere safe. They’re a lifesaver if you lose access to your phone.
    • Passkeys / Security Keys: These use your device’s biometrics (like fingerprint or face ID) or a USB key. Unlike SMS, they can’t be intercepted and are resistant to phishing.
      Setup guide: https://wordpress.com/support/security/two-step-authentication/security-key-authentication/
    • Account & site monitoring: WordPress.com handles server-level security (SSL, automatic updates, and suspicious login monitoring). If anything unusual happens, you’ll get alerts right away.

    Signs something might be wrong: You’d notice strange login notifications, changes to your account info you didn’t make, missing content, or unexpected login failures.

    You’re already on the right path with 2FA — switching from SMS to a passkey or authenticator app will give you even stronger peace of mind.

    If you’d like to discuss these options in more detail, please do let me know.

  • Unknown's avatar
    koolbeanz247 · Member · Sep 23, 2025 at 2:18 am
    • Copy link Copy link

    OK. I heard passkeys are more secure than passwords etc but are there downsides to using passkeys

    Is having my phone number connected to my account required? I assume so to revceive verification codes. How can I unlink my phone number to my wordpress account

    Does wordpress itself backup and secure your site or is security all on us

  • The topic ‘Security: Protecting WordPress Site’ is closed to new replies.

Tags

  • account

About this topic

  • In: Support
  • 2 participants
  • 2 replies
  • Last activity 3 months
  • Latest reply from koolbeanz247

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions