I can’t say it emphatically enough, if you only use one plugin on your WordPress website to protect it from malicious attacks, make sure it is Wordfence. You don’t need to fork out for the paid version, the free one is awesome enough.
Please note I am in no way affiliated with Wordfence nor do I get any benefit from recommending it. But, it is the first plugin I install on all WordPress websites.
Check it out, and join their mailing list at https://www.wordfence.com/