There are various steps to secure your Wordpress wesite.
1. First update all plugins and themes regularly in Wordpress.
2. Always use STRONG and COMPLEX password for login.
3. Avoid to use "Admin" username.
4. Use plugin to limit login attempts in wordpress.
5. Prevent directory listing.
There are various other ways to
secure your wordpress. But above are basic steps which everyone should follow.