WordPress Security Checklist for Small Business Websites (20 Steps)
Most hacked WordPress sites aren't targeted personally. Automated bots scan millions of websites looking for known weaknesses like outdated plugins and weak passwords. The good news is that a handful of basic steps block the vast majority of these attacks. Use this checklist to secure your business website.
Updates and software
- Keep WordPress core updated. Minor security releases often install automatically; apply major updates after a backup.
- Update plugins and themes promptly. Outdated plugins are the most common way into WordPress sites.
- Delete unused plugins and themes. Deactivated code can still be exploited if it's vulnerable.
- Avoid abandoned plugins. If a plugin hasn't been updated in a long time, look for a maintained alternative.
- Never use "nulled" (pirated) themes or plugins. They frequently contain hidden malware.
- Run a current PHP version supported by your host.
Logins and users
- Use strong, unique passwords for every admin, with a password manager.
- Turn on two-factor authentication (2FA) for all administrator accounts.
- Limit login attempts to slow down password-guessing bots.
- Don't use "admin" as a username.
- Give people the lowest role they need. Editors and authors don't need administrator access.
- Remove old users such as former staff, agencies and freelancers once their work is done.
Backups
- Automatic daily backups of files and database.
- Store backups off-site (cloud storage), not only on the same server.
- Test restoring a backup occasionally. An untested backup might fail when you need it.
Hosting and server
- Choose reputable hosting with malware scanning, firewalls and account isolation.
- Use HTTPS everywhere with a valid SSL certificate.
- Use SFTP, not FTP, and secure your hosting control panel with 2FA.
Monitoring and protection
- Install a reputable security plugin or firewall to block malicious traffic and scan for malware.
- Monitor Google Search Console for security warnings, and set up uptime monitoring so you know quickly if the site goes down.
Signs something is already wrong
Unexpected redirects, strange pages in Google results, unknown admin users or browser warnings are signs of an existing infection. See our guide to the signs of a hacked WordPress site, and get it cleaned properly before hardening.
Make security routine
Security isn't a one-time task. Updates, backups and checks need to happen every month. Many businesses put their site on a maintenance plan so this happens consistently without them having to remember.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.