Use this as a working checklist, not a brochure. Tick what you can today, schedule the rest, and revisit monthly. For config how-tos, see the hardening guide. For habits and routines, see best practices.

HTTPS and transport
Core and updates
Passwords, 2FA, and least privilege
Admin and login hardening
Remove unused software
Backups and recovery
See backup plan.
WAF, scans, and monitoring
Hosting and access
Suggested order (if starting from zero)
- Confirm backups
- Force HTTPS if it is not already
- Update everything; delete unused plugins/themes
- Fix admins, passwords, 2FA, login limits
- Turn on firewall + scanning if available
- Harden
wp-config and permissions
- Run security tests and fix what is easy
- Set a monthly reminder and stick to it
Monthly revisit (10 minutes)
Security Ninja is a WordPress security plugin that covers many of these checks in one place. Free for tests, vulnerability scanning, and core integrity; Pro for Cloud Firewall, malware scanning, scheduled scans, and stronger login tools. The install wizard helps turn defaults on without guessing. Comparing suites? See best WordPress security plugins.
Deeper reading: hardening guide, best practices, beginners guide, login security. Not sure if you are compromised? Check if your WordPress site is hacked. Already sure? Recovery steps or hire cleanup.