Install And Review Locally
Install the WordPress plugin, open the Security Center area in wp-admin, and start with local checks for suspicious file changes, public-risk indicators, risky configuration, administrator drift, uploads, debug logs, and component changes.