Great mate.
There's a very powerful plugin available named Gotmls on wordpress plugin directory and the best part its free.
It will save you from malware and other ddos attacks, xss or injections.
I tweak my wp with some httaccess and wp-config settings.
I will try to put all the tweaks here...