There are 2 plugins you should use to secure your website. After tuning both those plugins your site would be secured.
1) All In One WP Security & Firewall - Using this plugin take care of below things.
- Change your wp-admin login path
- Change the WordPress database prefix ( let the plugin decide the prefix )
- Check database permissions
- Enable firewalls ( there are multiple options ) - My suggestion is to enable all firewall options.
- There is an option to disable PHP file editing, you can enable it so hackers cannot modify your PHP files in future but mind well, you will not be able to edit PHP files too without disabling that option.
- Check other options one by one and enable/disable as per your requirement. ( Don't worry, it's very easy to understand each options )
Plugging would show you your security score. More score is better but some features may not support your coding or theme so make changes accordingly.
2) Wordfence - This plugin is for checking malware in your files and help to remove them
This plugin is paid plugin but you can find the nulled version from many websites.
- After installing the plugin, go step by step as it guides you.
- After setting up, scan your files. Once Scanning gets completed, it will show you infected files. You can remove the suspicious code from the files or remove file completely ( Take proper decision if you are deleting the file )
- It will show you live traffic/ attacks as well and it will block the attackers as per the rules you have set.
- If you have nulled or purchased addon, it will keep monitor your files and keep scanning files regularly and will mail you the report.
P.S. Use your intelligence to enable/disable options on both of these plugins as per your requirement. but after installing both these plugins with proper tuning, it will make your site very much secure.