Fresh WordPress installs all look alike: a “Hello world!” post, links like ?p=1, comments open to every spam bot out there, and a tagline that says “Just another WordPress site.” None of that stops your site from working. Some of it will quietly cost you traffic and time if you leave it.
Here are the nine settings worth changing before you publish anything, in the order you’ll find them in the dashboard.
1. Site Title and Tagline
Where: Settings → General
Your site title shows in browser tabs and often in search results. The default tagline, “Just another WordPress site”, can show up in search snippets and social previews, which looks unfinished. Replace it with a short line that says what your site is about, or clear it completely.
2. Site Address and https
Where: Settings → General
Check that both URL fields start with https://. If they show http:// and your SSL certificate is active, switch them to https. Be careful: if SSL isn’t active yet and you change these, you can lock yourself out of the dashboard. Confirm with your host first.
3. Timezone, Date Format and Week Start
Where: Settings → General
Pick a city in your own timezone rather than a UTC offset. City-based settings adjust for daylight saving automatically. This matters as soon as you schedule a post for 8am and it goes live at 1pm.
4. Permalinks (the Most Important One)
Where: Settings → Permalinks
Select Post name. Your links go from this:
yourdomain.com/?p=247
to this:
yourdomain.com/best-budget-hosting
Clean URLs are easier to share and easier for readers (and search engines) to understand. Change this before you publish. Changing it later breaks existing links unless you set up redirects.
5. Discussion Settings (Stop the Spam)
Where: Settings → Discussion
Out of the box, WordPress lets almost anyone comment, and spam bots find new sites fast. Here’s a sensible starting setup:
| Setting | Recommended | Why |
|---|---|---|
| Allow link notifications (pingbacks) | Off | Mostly spam these days |
| Comment author must fill out name and email | On | Cuts low-effort spam |
| Automatically close comments after X days | On, 30–60 days | Old posts attract the most spam |
| Comment must be manually approved | On at first | You stay in control while you’re small |
| Email me whenever anyone posts a comment | Your choice | Useful early, noisy later |
If you don’t want comments at all, turn off “Allow people to submit comments on new posts”.
6. Reading Settings and Search Visibility
Where: Settings → Reading
Two things to check here:
- “Discourage search engines from indexing this site” must be unchecked once you’re ready to go live. Some hosts tick it during setup. If it stays ticked, Google won’t index your site, and many beginners don’t notice for weeks.
- Your homepage display. Choose whether visitors land on your latest posts or on a static page. Most blogs that want to guide readers use a static homepage with sections for each topic.
7. Your User Profile
Where: Users → Profile
Set a nickname and choose it under “Display name publicly as”. Otherwise WordPress may show your login username on every post, which gives attackers half of what they need to log in. While you’re here, add a short bio. Many themes show it under your posts, and it helps readers trust you.
8. Delete Unused Themes and Plugins
Where: Appearance → Themes, and Plugins
WordPress comes with several default themes. Keep your active theme plus one default theme as a fallback (useful for troubleshooting), and delete the rest. Do the same with plugins: if it’s not active and you have no plan for it, delete it. Inactive code can still have security holes, and it adds clutter to your update list.
9. Clear Out the Sample Content
Where: Posts, Pages, Comments
Trash the “Hello world!” post, the “Sample Page”, and the sample comment. If you forget, the sample post can end up in your homepage feed, in your sitemap, and eventually in Google.
A 45-Minute Setup Walkthrough
If you want to get it all done in one sitting, here’s the order that avoids backtracking:
- Confirm SSL is active with your host (5 min)
- General settings: title, tagline, https, timezone (5 min)
- Permalinks → Post name (1 min)
- Discussion settings (5 min)
- Reading settings: search visibility and homepage (3 min)
- User profile: nickname, display name, bio (5 min)
- Delete sample content (2 min)
- Remove unused themes and plugins (5 min)
- Install your core plugins: see our list of plugins every new blog needs (15 min)
Bonus: Turn On Two-Factor Login
This isn’t in the Settings menu, but it belongs on this list. Weak or reused passwords are one of the most common ways small WordPress sites get broken into. Most security plugins (and many hosts) let you add two-factor authentication, so logging in needs both your password and a code from an app on your phone.
Set it up for every administrator account. It takes about five minutes:
- Install a security plugin that supports two-factor login, or check your host’s dashboard for the option.
- Scan the QR code with an authenticator app on your phone.
- Save the backup codes somewhere safe, away from your computer.
- Log out and back in once to confirm it works.
What You Don’t Need to Touch Yet
Beginners often lose a day on settings that don’t matter at this stage: media image sizes, writing settings, the “Update Services” ping list, and advanced caching options. Leave the defaults. Come back when you have a specific reason to change them.
Takeaway
The settings that matter most are the ones that are painful to change later: permalinks, https and search visibility. Get those right today and the rest can be tweaked whenever you like.
[…] four right today and you won’t need to revisit this setup for years. Next, go through the settings worth changing right after install and your site will be ready for its first real […]