Security
Security and SSL how-to
Browser warnings and mixed content hurt trust and SEO. These guides walk through certificates, WordPress URL settings, and safe HTTPS redirects.
SSL problems often sit outside WordPress core: expired certificates, wrong Cloudflare modes, or hardcoded http links in the database. Work through these tutorials in order when you see padlock warnings.
Tutorials in this topic
SSL
How to fix WordPress SSL certificate errors
Fix WordPress SSL certificate errors: renew certs, correct siteurl/home, force HTTPS, fix mixed content, and align Cloudflare SSL modes with your host.
Read tutorialMixed content
How to fix WordPress mixed content warnings
Fix WordPress mixed content warnings: find http assets on https pages, search-replace database URLs, update hardcoded links, and clear CDN cache for UK sites.
Read tutorialHTTPS
How to force HTTPS redirect on WordPress
Force HTTPS on WordPress: set siteurl to https, add Apache or nginx redirects, fix Cloudflare SSL modes, and avoid login redirect loops on UK hosting.
Read tutorialLogin loop
How to fix a WordPress login redirect loop
Fix WordPress login redirect loops: correct siteurl and home URLs, fix HTTPS and cookie settings, clear browser cookies, and resolve plugin conflicts on wp-login.
Read tutorialSalts
How to change WordPress salts and security keys
Change WordPress salts and security keys in wp-config.php: invalidate all sessions after a hack, generate new keys from WordPress.org, and recover admin access safely.
Read tutorialXML-RPC
How to disable WordPress XML-RPC
Disable WordPress XML-RPC safely: block pingback attacks, turn off xmlrpc.php via .htaccess or plugins, and keep Jetpack or mobile apps working if needed.
Read tutorialPermissions
How to fix WordPress file permissions
Fix WordPress file permissions on Linux hosting: set 755 for directories and 644 for files, secure wp-config.php, and fix uploads folder write errors safely.
Read tutorialMalware
How to remove WordPress malware manually
Remove WordPress malware manually: find suspicious PHP in wp-content, clean infected .htaccess, scan the database for spam links, and harden after cleanup on UK sites.
Read tutorial2FA
How to enable WordPress two-factor authentication
Enable two-factor authentication on WordPress: protect admin accounts with TOTP apps, enforce 2FA for editors, and recover access if you lose your phone.
Read tutorialwp-config
How to secure wp-config.php
Secure wp-config.php: move it above web root, set DISALLOW_FILE_EDIT, block direct access, tighten permissions, and add security constants for UK WordPress sites.
Read tutorialMore topics
Errors
WordPress error how-to
Diagnose and fix common WordPress failures yourself. These tutorials cover debug mode, plugin isolation, theme recovery, and when to call a developer.
10 tutorialsPlugins
Plugins and themes how-to
Plugins extend WordPress but also cause most outages. Learn how to add, test, and remove plugins without taking the whole site offline.
10 tutorialsAdministration
Site administration how-to
Backups, staging, and configuration changes should not be guesswork. These tutorials cover the admin tasks site owners ask about most.
10 tutorialsWooCommerce
WooCommerce how-to
Shop problems cost orders every minute. These guides cover checkout debugging, payment gateways, and email failures on WooCommerce stores.
10 tutorialsPerformance
Performance how-to
Slow sites hurt SEO and conversions. These tutorials cover caching layers, bloated plugins, and realistic speed wins without breaking checkout.
10 tutorialsNeed a developer instead?
Confirmed pricing on one-off fixes from £49.99. Direct chat with your BugShield developer.
Request a Fix