New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Security

Security and SSL how-to

Browser warnings and mixed content hurt trust and SEO. These guides walk through certificates, WordPress URL settings, and safe HTTPS redirects.

SSL problems often sit outside WordPress core: expired certificates, wrong Cloudflare modes, or hardcoded http links in the database. Work through these tutorials in order when you see padlock warnings.

Tutorials in this topic

SSL

How to fix WordPress SSL certificate errors

Fix WordPress SSL certificate errors: renew certs, correct siteurl/home, force HTTPS, fix mixed content, and align Cloudflare SSL modes with your host.

Read tutorial

Mixed content

How to fix WordPress mixed content warnings

Fix WordPress mixed content warnings: find http assets on https pages, search-replace database URLs, update hardcoded links, and clear CDN cache for UK sites.

Read tutorial

HTTPS

How to force HTTPS redirect on WordPress

Force HTTPS on WordPress: set siteurl to https, add Apache or nginx redirects, fix Cloudflare SSL modes, and avoid login redirect loops on UK hosting.

Read tutorial

Login loop

How to fix a WordPress login redirect loop

Fix WordPress login redirect loops: correct siteurl and home URLs, fix HTTPS and cookie settings, clear browser cookies, and resolve plugin conflicts on wp-login.

Read tutorial

Salts

How to change WordPress salts and security keys

Change WordPress salts and security keys in wp-config.php: invalidate all sessions after a hack, generate new keys from WordPress.org, and recover admin access safely.

Read tutorial

XML-RPC

How to disable WordPress XML-RPC

Disable WordPress XML-RPC safely: block pingback attacks, turn off xmlrpc.php via .htaccess or plugins, and keep Jetpack or mobile apps working if needed.

Read tutorial

Permissions

How to fix WordPress file permissions

Fix WordPress file permissions on Linux hosting: set 755 for directories and 644 for files, secure wp-config.php, and fix uploads folder write errors safely.

Read tutorial

Malware

How to remove WordPress malware manually

Remove WordPress malware manually: find suspicious PHP in wp-content, clean infected .htaccess, scan the database for spam links, and harden after cleanup on UK sites.

Read tutorial

2FA

How to enable WordPress two-factor authentication

Enable two-factor authentication on WordPress: protect admin accounts with TOTP apps, enforce 2FA for editors, and recover access if you lose your phone.

Read tutorial

wp-config

How to secure wp-config.php

Secure wp-config.php: move it above web root, set DISALLOW_FILE_EDIT, block direct access, tighten permissions, and add security constants for UK WordPress sites.

Read tutorial

Need a developer instead?

Confirmed pricing on one-off fixes from £49.99. Direct chat with your BugShield developer.

Request a Fix