Small business websites are rarely hacked by someone targeting them personally. They are hacked by automated tools that scan millions of sites for known weaknesses: an outdated plugin, a reused password, an exposed admin page. That is good news, because it means a handful of basic precautions stop the vast majority of attacks.
This checklist is ordered by impact. If you only have an hour, do the first two sections. If you have an afternoon, add backups and the firewall. Everything after that is about closing smaller gaps and noticing problems early, which matters most for sites that take payments, bookings or personal details.
Most of it applies to any platform. WordPress owners will find extra items in their own section near the end.
1. Lock down access
- Everyone has their own login. No shared accounts. When someone leaves, remove their account the same day.
- Strong, unique passwords stored in a password manager, for the website, hosting, domain registrar and email.
- Two-factor authentication on every admin account, and on your hosting, domain registrar and DNS provider.
- Least privilege. People who only write blog posts do not need administrator access.
- Know who has access. Review users on the website and hosting at least twice a year. Old developers and agencies are a common forgotten door.
2. Keep software up to date
- Update the CMS, themes and plugins promptly, especially when the update mentions security.
- Remove what you do not use. Deactivated plugins and old themes can still be exploited.
- Replace abandoned components. If a plugin has not been updated in over a year, find a maintained alternative.
- Keep server software current, including the PHP version your host runs.
How much does this matter? In 2025 security firm Patchstack recorded 11,334 new vulnerabilities in the WordPress ecosystem. 91 percent were in plugins and 9 percent in themes, with only six low-priority issues in WordPress core itself. The platform is not the weak point; the add-ons are.
Source: Patchstack, State of WordPress Security in 2026.
3. Have backups you can actually restore
- Automatic backups of files and database, daily for busy sites, weekly at minimum.
- Stored off the server, so a hacked or failed server does not take the backups with it.
- Several versions kept, because infections often go unnoticed for weeks.
- Test a restore at least once a year. An untested backup is a hope, not a plan.
4. Put a firewall in front of the site
- Use a web application firewall such as Cloudflare or Sucuri to filter malicious traffic before it reaches your server.
- Limit login attempts and block repeated failures.
- Turn on bot protection for forms and login pages.
5. Encrypt everything
- HTTPS on every page, with http redirecting to https.
- Certificates renew automatically, and someone gets alerted if renewal fails.
- Security headers such as HSTS, X-Content-Type-Options and a sensible Referrer-Policy.
6. Protect forms and the data they collect
- Spam protection (a honeypot or a privacy-friendly challenge) on every form.
- Collect only what you need. Do not ask for sensitive information through an ordinary contact form.
- Restrict file uploads to the types you expect, and scan them.
- Do not store submissions forever in the website database if they are also emailed to you.
7. Watch for trouble
- Uptime monitoring so you know within minutes if the site goes down.
- Malware scanning and file-change alerts.
- Search Console security alerts turned on.
- Domain renewal on auto-renew, with a current payment card. An expired domain is one of the most damaging and avoidable outages.
8. Protect your email domain
- SPF, DKIM and DMARC records set up for your domain, so others cannot easily send email pretending to be you.
- The website’s contact form sends from an authenticated address, so enquiries do not land in spam.
WordPress-specific checks
- No user called “admin”, and author archives do not reveal admin usernames.
- File editing in the dashboard disabled (
DISALLOW_FILE_EDIT). - Correct file permissions, with
wp-config.phpprotected. - XML-RPC disabled if you do not use it.
- Security keys and salts rotated after any suspected compromise.
- Premium plugins and themes kept licensed so updates arrive.
- A reputable security plugin, alongside (not instead of) the steps above.
If you think your site has been hacked
- Do not panic and do not delete files at random; you may destroy evidence of how they got in.
- Change passwords for the website, hosting and email from a clean device.
- Contact your host and check Search Console for security warnings.
- Restore a clean backup from before the infection, or get professional malware removal.
- Find and fix the way in, then work through this checklist so it does not happen again.
Frequently asked questions
What is the most important website security step?
Keeping software updated and protecting logins with strong unique passwords and two-factor authentication. Together these stop most automated attacks.
Are small business websites really targeted?
Yes. Most attacks are automated and look for known weaknesses on any site, regardless of size or industry.
Is WordPress less secure than other platforms?
WordPress core is well maintained. Most WordPress vulnerabilities are in plugins and themes, which is why updates and careful plugin choices matter.
How often should I check my website security?
Updates and backups should run continuously. Review users, plugins and settings at least twice a year, and immediately after any staff or contractor change.
