One of the simplest and most effective ways to improve your WordPress site security is to change the standard database prefix from "wp_" to something unique and hard to guess.

By default, all WordPress installations use "wp_" as the prefix for tables in the database. This makes sites vulnerable to SQL injection attacks, as hackers know the exact names of the tables and can direct their attacks directly at them.

Why change the database prefix?

The standard "wp_" prefix is widely known and used by millions of WordPress sites. This creates several problems:

Risks with the standard prefix:

  • Predictability: Hackers know that tables are called wp_users, wp_posts, wp_options, etc.
  • SQL Injection: Automated attacks can directly target known table names
  • Mass Exploits: Malicious scripts massively attack WordPress sites using the standard structure
  • Brute Force: It is easier to perform brute force attacks when the structure is known

Benefits of changing the prefix:

  • Additional layer of protection against SQL injection
  • Hinders automated attacks
  • Makes the database structure unpredictable
  • Minimal effort for significant security improvement

Changing the database prefix is not a panacea, but it is an important part of a comprehensive WordPress security strategy.

— WordPress Security Best Practices

How to change the database prefix step by step

⚠️ IMPORTANT: Before you start, mandatory create a full backup of the database and site files!

Step 1: Backup the database

Use phpMyAdmin, cPanel, or a WordPress backup plugin to create a full backup. This is critically important - if an error occurs, you may lose the entire site!

Step 2: Choose a new prefix

Choose a unique prefix that is:

  • 3-8 characters long
  • Contains only letters and an underscore (_)
  • Mandatory ends with an underscore (_)
  • Examples: ci47_, secure_, mydb_

Step 3: Edit wp-config.php

Open the wp-config.php file in the root directory and find the line:

$table_prefix = 'wp_';

Change it to your new prefix, for example:

$table_prefix = 'ci47_';

Save the file.

Step 4: Rename the tables in the database

Open phpMyAdmin and execute the following SQL commands. Replace "ci47_" with your chosen prefix!

RENAME TABLE wp_commentmeta TO ci47_commentmeta;\nRENAME TABLE wp_comments TO ci47_comments;\nRENAME TABLE wp_links TO ci47_links;\nRENAME TABLE wp_options TO ci47_options;\nRENAME TABLE wp_postmeta TO ci47_postmeta;\nRENAME TABLE wp_posts TO ci47_posts;\nRENAME TABLE wp_terms TO ci47_terms;\nRENAME TABLE wp_termmeta TO ci47_termmeta;\nRENAME TABLE wp_term_relationships TO ci47_term_relationships;\nRENAME TABLE wp_term_taxonomy TO ci47_term_taxonomy;\nRENAME TABLE wp_usermeta TO ci47_usermeta;\nRENAME TABLE wp_users TO ci47_users;

Note: If you use multisite or have additional plugins, you may have other tables with a "wp_" prefix. Rename them all!

Step 5: Update the options in the database

Some entries in the options table contain the old names. Execute the following UPDATE commands:

UPDATE ci47_options\nSET option_name = REPLACE(option_name, 'wp_', 'ci47_')\nWHERE option_name LIKE '%wp_%';\n\nUPDATE ci47_usermeta\nSET meta_key = REPLACE(meta_key, 'wp_', 'ci47_')\nWHERE meta_key LIKE '%wp_%';

Step 6: Check and test

  • Open the site and check that loading is normal
  • Log in to the admin panel
  • Check that all pages and posts load correctly
  • Test basic functions (comments, search, forms)
  • Check that plugins are working normally
  • Review the Error Log for errors
  • If everything is fine - make a new backup with the new prefix!

Possible problems and solutions

Problem: White Screen of Death

Solution: Restore the backup and check if you executed all SQL commands correctly.

Problem: Cannot log in

Solution: Check if you updated the usermeta table with the UPDATE command from step 5.

Problem: Plugins not working

Solution: Some plugins create their own tables with a wp_ prefix. Check in phpMyAdmin and rename them manually.

Problem: Missing some settings

Solution: Execute the UPDATE commands for the wp_options and wp_usermeta tables again.

Conclusion

Changing the database prefix is an important step towards a more secure WordPress site. Although the process requires attention and precision, it significantly hinders automated attacks and SQL injection attempts.

Remember that this is just one of many security measures you should apply. Combine it with:

  • Strong passwords and two-factor authentication
  • Regular updates of WordPress, theme, and plugins
  • SSL certificate and HTTPS
  • Security plugin (Wordfence, iThemes Security, etc.)
  • Regular backups
  • Firewall and malware scanning

If you don't feel comfortable making changes to the database, the Creative Idea team can help you with professional WordPress security services.

Share article: