This document provides tips and recommendations for hardening a WordPress site against hacking and security threats. It discusses typical paths of infection like insecure server configurations or outdated code. It recommends various security measures including keeping backups, using strong passwords, updating software regularly, and restricting access to admin areas and important files. It also suggests security plugins that can help scan sites for vulnerabilities, limit login attempts, backup data, and more. The document emphasizes that while no site is completely hack-proof, administrators can make sites much more difficult to compromise through diligent security practices.