All Posts

[ WordPress ]

WordPress Security Checklist for Small Businesses: 15 Steps That Actually Matter

Most hacked WordPress sites aren’t targeted — they’re found by automated bots looking for easy weaknesses. This checklist closes the gaps that matter most.

T
Tocal IT Works

We build the funnels, stores and CRMs we write about — this isn't outsourced content.

8 min read
WordPress security checklist for small businesses — 15 steps that matter

This WordPress security checklist is written for small business owners, not security specialists. WordPress itself is well maintained, but because it powers so many websites, it attracts a constant stream of automated attacks. Bots scan the web around the clock for out-of-date plugins, weak passwords and forgotten admin accounts. Most hacked small-business sites weren’t singled out — they were simply easy.

The good news is that a handful of habits block most of those attacks. Below are the 15 steps we apply to client sites, grouped and roughly in order of impact. WordPress’s own documentation on hardening covers the technical detail; this guide focuses on what to actually do.

Why small business WordPress sites get hacked

  • Out-of-date plugins and themes with known security holes.
  • Weak or reused passwords, especially on admin accounts.
  • Old user accounts belonging to former staff, freelancers or agencies.
  • Nulled (pirated) themes and plugins, which often contain hidden malware.
  • Cheap or poorly configured hosting shared with compromised sites.
  • No backups, which turns a fixable problem into a disaster.

The results range from spam links and redirects to fake pages, stolen form data and Google warning visitors away from your site. Cleaning up is almost always more expensive than preventing it.

Updates: the single biggest factor

1. Keep WordPress core up to date

WordPress installs minor security releases automatically by default — don’t switch that off. Apply major version updates promptly too, after a quick test.

2. Update plugins and themes every week

Most WordPress hacks come through plugins, not WordPress itself. Check for updates at least weekly. WordPress lets you turn on automatic updates for individual plugins and themes — a sensible choice for well-maintained ones.

3. Delete what you don’t use

A deactivated plugin can still be a risk if its files remain on the server. Delete unused plugins and themes completely, keeping only your active theme and one default theme as a fallback.

4. Only install from trusted sources

Use the official WordPress plugin directory or reputable developers. Check when a plugin was last updated and whether the developer responds to support questions. Never install nulled premium plugins or themes.

Logins and users

5. Use strong, unique passwords and a password manager

Every account — especially administrators — needs a long, unique password. A password manager makes this painless and lets you share access safely without sending passwords over WhatsApp or email.

6. Turn on two-factor authentication

Two-factor authentication (2FA) means a stolen password alone isn’t enough to log in. Add it with a reputable security or 2FA plugin, at least for every administrator.

7. Limit login attempts

Bots repeatedly try to guess passwords on your login page. Limiting failed attempts, or adding a firewall that blocks repeated failures, stops these brute-force attacks.

8. Give people only the access they need

Not everyone needs to be an administrator. Use the Editor or Author role for content writers, and remove accounts for former staff and agencies as soon as their work ends. Never use “admin” as a username.

Hosting and configuration

9. Choose good hosting

Quality managed WordPress hosting includes a server firewall, malware scanning, isolated accounts, automatic backups and a recent PHP version. Cheap shared hosting rarely does all of this well — and it’s usually slower too.

10. Use HTTPS everywhere

An SSL certificate encrypts data between visitors and your site — essential for contact forms and logins. Most hosts provide one free. Make sure every page redirects to the secure https:// version.

11. Disable file editing in the dashboard

WordPress lets administrators edit theme and plugin code from the dashboard. If an attacker gets in, that editor lets them inject code instantly. Your developer can turn it off with a single setting (DISALLOW_FILE_EDIT) in the wp-config.php file.

12. Add a web application firewall

A firewall — from your host, a CDN service or a security plugin — filters malicious traffic before it reaches your site, blocking many common attacks automatically.

Backups and recovery

13. Back up automatically, and store copies off the server

Back up both your files and your database, daily if your site changes often. Keep copies somewhere other than your hosting account, so a problem with the host doesn’t take your backups with it.

14. Test a restore

A backup you’ve never restored is a guess. Once every few months, restore a backup to a staging site to confirm it actually works.

Monitoring

15. Watch for problems

  • Uptime monitoring alerts you if the site goes down.
  • Malware scanning checks for changed files and known infections.
  • Google Search Console warns you if Google detects security issues on your site.
  • Login alerts tell you when an administrator logs in.

Don’t forget your forms

Contact and booking forms are a common target for spam and abuse. Add spam protection such as a CAPTCHA, only ask for the information you need, and make sure submissions are sent securely. Avoid collecting sensitive data like ID numbers or card details through a basic contact form.

What to do if your site is hacked

  1. Don’t panic, and don’t start deleting files at random.
  2. Change all passwords — WordPress users, hosting, database and email.
  3. Contact your host; many can help isolate the problem.
  4. Restore a clean backup from before the hack, or have the site professionally cleaned.
  5. Update everything and remove anything unused.
  6. Check Google Search Console and request a review if Google flagged your site.
  7. Find out how the attacker got in, so it doesn’t happen again.

A simple monthly security routine

  • Weekly: apply plugin, theme and core updates; check uptime and security alerts.
  • Monthly: review user accounts, remove unused plugins, confirm backups are running.
  • Quarterly: test-restore a backup and review hosting and firewall settings.

If you’d rather not do this yourself, our WordPress care plans cover updates, backups, security monitoring and fixes. Running an online store on WordPress? The same checklist applies to WooCommerce, with extra care around payments and customer data.

Still deciding on a platform? Hosted platforms handle much of this for you — see our comparison of Shopify vs WooCommerce.

Frequently asked questions

Yes, when it is kept up to date and set up properly. Most WordPress hacks come from outdated plugins, weak passwords and poor hosting rather than WordPress itself.

[ Tags ]

  • WordPress
  • Website Security
  • Maintenance
  • Small Business
  • Backups

[ Need a hand? ]

Let Us Build It For You.

20 minutes, no pressure — we’ll look at your setup and tell you honestly what to fix first.