- remove default "admin" user, because many bots try to brute-force login via "admin" username
- install captcha for login plugin or "limit-login-attempts" plugin
- update WordPress, theme and plugins if update is available
that's it, all other is paranoia.

