Article Background
Back to Knowledgebase

Best Practices for Website Security: WordPress, Joomla, and Drupal

Web
Cubes Support
July 20, 2026

Popular Content Management Systems (CMS) such as WordPress, Joomla, and Drupal power over 40% of the web. Because of their popularity, unmaintained CMS websites are prime targets for automated bot scanners searching for outdated plugins, weak passwords, and vulnerable scripts.

Implementing solid website security protects your brand reputation, prevents Google blacklist penalties, and keeps your customer data safe.

This comprehensive guide covers essential security best practices for WordPress, Joomla, and Drupal websites hosted on Cubes Hosting.


1. Enable Free SSL/TLS (HTTPS) Certificates

An SSL Certificate encrypts all data sent between your visitors' web browsers and your website server. Without SSL, admin passwords, session cookies, and user form entries are transmitted as unencrypted plain text.

Enable Free SSL on Cubes Hosting:

  1. Log in to your Cubes Hosting DirectAdmin Control Panel.
  2. Navigate to Account Manager > SSL Certificates.
  3. Select Free & automatic certificate from Let's Encrypt.
  4. Check your domain name and click Save.
  5. Enable Force SSL/HTTPS Redirect under Domain Setup.

2. Keep CMS Core, Plugins, and Themes Updated

Over 95% of CMS hacks exploit known security vulnerabilities in outdated plugins, modules, or themes.

  • WordPress: Go to Dashboard > Updates and enable Automatic Updates for core releases, plugins, and themes.
  • Joomla: Enable automatic update notification emails under System > Update.
  • Drupal: Monitor security updates under Manage > Reports > Available updates and update core files immediately when a security advisory is released.

Rule of Thumb: Delete unused or deactivated plugins and themes. Unused files can still be scanned and exploited by malicious bots!


3. Enforce Strong Passwords & Two-Factor Authentication (2FA)

Brute-force attacks use automated scripts to guess thousands of username/password combinations every minute.

  • Strong Passwords: Never use simple passwords like admin123 or password2026. Use a password manager to generate complex 32+ character passwords.
  • Enable Two-Factor Authentication (2FA): 2FA requires an authentication code from an app (like Google Authenticator or Authy) when logging in:
    • WordPress: Install plugins like Wordfence, Two-Factor, or iThemes Security.
    • Joomla: Enable built-in 2FA under Users > Multi-Factor Authentication.
    • Drupal: Install the official TFA (Two-Factor Authentication) module.

4. Protect Login Pages & Limit Login Attempts

By default, CMS login pages reside at predictable URLs (/wp-admin/, /administrator/, or /user/login/).

  • Limit Login Attempts: Lock out IP addresses that fail password checks 3–5 times in a row:
    • WordPress: Use Limit Login Attempts Reloaded or Wordfence.
    • Joomla: Use Admin Tools by Akeeba.
  • Hide Default Login URLs: Change your login URL from /wp-login.php to a custom secret path (e.g. /secret-entry/) using plugins like WPS Hide Login.

5. Never Use Nulled or Pirated Themes & Plugins

Downloading "nulled" or pirated premium themes and plugins from unauthorized file-sharing sites is the #1 cause of website malware infections.

Nulled scripts almost always contain hidden PHP backdoors, malicious redirect scripts, and SEO spam injectors designed to compromise your web hosting account. Always purchase themes and plugins directly from official developers or trusted marketplaces.


6. Secure File Permissions & Configuration Files

Incorrect file permissions allow malicious scripts to modify core system files:

  • Standard Folder Permissions: Set directories to 755 (drwxr-xr-x).
  • Standard File Permissions: Set website files to 644 (-rw-r--r--).
  • Sensitive Configuration Files: Set strict 600 or 644 permissions on sensitive files:
    • WordPress: wp-config.php
    • Joomla: configuration.php
    • Drupal: settings.php

7. Maintain Regular Off-Site Backups

If a site issue or compromise occurs, having a recent backup allows you to restore your website in seconds.

  • Cubes Hosting Automated Backups: Enable scheduled backups in DirectAdmin under Advanced Features > Create/Restore Backups.
  • CMS Backup Plugins: Use trusted CMS backup plugins like UpdraftPlus (WordPress) or Akeeba Backup (Joomla/WordPress) to store copies off-site on Google Drive or Dropbox.

Conclusion

Securing your WordPress, Joomla, or Drupal website requires minimal ongoing effort: enable Let's Encrypt SSL in DirectAdmin, keep core files and plugins updated, enforce 2FA, and avoid nulled plugins. Implement these best practices today to keep your website safe and fast!

Special Offer

Ready to Start Your Server?

Get 10% OFF your first month on any server with promo code CUBES10 at checkout!

24/7 Assistance

Need Help With Your Server?

Already a Cubes Hosting customer and couldn't find your answer? Our dedicated support team is available 24/7.