954-539-5678Free audit
Menu

Web design · Security

The WordPress security checklist we actually use

Six areas cover most of the risk: logins, updates, plugins, hosting, backups and monitoring. Here is what to check in each, and how often.

Logins, updates and plugins first

Hosting and backup settings

A monthly and quarterly routine

Talk to us

Tell us what you need and we’ll get back to you. Or book a free 30-minute call. Or call 954-539-5678.

The short answer

A WordPress security checklist for a business site comes down to six areas. Lock down logins with unique passwords and two-step authentication. Keep core, plugins and themes updated. Remove plugins you do not need and avoid abandoned ones. Use hosting with a firewall, current PHP and isolation between sites. Keep automated off-site backups and test restores. Monitor for changes and malware so you hear about problems before customers do. Do those six well and you prevent most of the attacks that hit small business sites.

Below is the full checklist, grouped by area, followed by a simple routine to run monthly and quarterly. If your site has already been compromised, clean it up first, then use this list to keep it clean.

Why plugins are where the risk is

WordPress core is well maintained. The risk lives in the add-ons. Patchstack’s State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 42% more than in 2024. Of those, 91% were in plugins and 9% in themes, and only six were in core. The same report found 46% had no fix available from the developer when they were made public, and that heavily exploited flaws were attacked at scale within a median of about five hours. That is why the checklist leans so hard on fewer plugins, fast updates and a firewall that can block attacks before a patch exists.

1. Logins and user accounts

  • Every user has their own account. No shared “admin” login.
  • Two-step authentication is required for administrators and editors. CISA recommends multifactor authentication as one of the simplest ways to block account takeover.
  • Passwords are long, unique and stored in a password manager.
  • Only people who need full control are administrators. Content staff are editors or authors.
  • Former staff and agencies are removed the day they leave. Review the user list every quarter.
  • Login attempts are rate limited. The WordPress brute force guidance explains the options.
  • XML-RPC is disabled unless an app or service needs it.

2. Updates

  • WordPress core minor and security releases install automatically.
  • Plugins and themes are updated at least weekly, with automatic updates on for trusted, low-risk plugins.
  • Major updates are tested on a staging copy first if the site takes payments or bookings.
  • Someone owns this job by name. “The developer will do it” is not an owner.
  • PHP runs on a version that still receives security fixes. As of 2026, the WordPress requirements page recommends PHP 8.3 or greater.

3. Plugins and themes

  • Every installed plugin has a clear job. Deactivated plugins are deleted, not just switched off, because inactive code can still be exploited.
  • Plugins come from the official directory or a known vendor. No “nulled” or pirated premium plugins, which often ship with backdoors.
  • Each plugin has been updated by its developer within the last several months. Abandoned plugins get replaced.
  • Only one theme is installed, plus a default theme as a fallback.
  • File editing in the dashboard is turned off with DISALLOW_FILE_EDIT in wp-config.php.

4. Hosting and server

  • The site runs on HTTPS everywhere, with HTTP redirected.
  • A web application firewall filters traffic, from your host or a security service.
  • Each site is isolated, so one hacked site cannot infect others on the same account.
  • File permissions follow the WordPress hardening guide, and wp-config.php is not readable from the web.
  • SFTP or SSH keys replace plain FTP.
  • The database user has only the permissions WordPress needs, and the database password is unique.
  • Directory browsing is off.

5. Backups

  • Files and database are backed up automatically, at least daily for sites that change often.
  • Backups are stored off the server, so a hacked or failed server does not take the backups with it.
  • Several weeks of history are kept, because some infections go unnoticed for a while.
  • A restore is tested at least twice a year. A backup you have never restored is a hope, not a plan.

6. Monitoring and response

  • Uptime monitoring alerts someone when the site goes down.
  • Malware scanning and file change detection run automatically.
  • Google Search Console is set up, with alerts going to a monitored inbox, so you hear about security issues Google finds.
  • Admin login activity is logged.
  • There is a one-page plan: who to call, where backups live and how to take the site offline.

Not sure how your site scores against this list? Book a free 30-minute call. We look at your current setup and tell you what we’d tighten first. No obligation.

7. Forms, customer data and third parties

Many small business sites collect more than they realize. Contact forms, quote requests, job applications and booking tools all gather personal information, and that is what makes a breach expensive rather than just embarrassing.

  • Form entries are not stored in the WordPress database longer than needed. If your form plugin keeps every submission forever, set a retention period or turn storage off and rely on email or your CRM.
  • File uploads, such as resumes or documents, are limited by type and size, and stored outside public folders where possible.
  • Spam protection is on every form, so bots cannot use your site to send junk or probe for weaknesses.
  • Payment pages use a hosted checkout or a payment provider’s own fields, so card numbers never touch your server.
  • Third-party scripts, such as chat widgets, tracking pixels and embeds, are reviewed once a year. Each one runs code on your pages, and old ones you no longer use should go.
  • Your domain registrar and DNS account have two-step login too. Whoever controls DNS can redirect your whole site.

Run it as a routine

Weekly

Apply plugin and theme updates. Glance at the security scanner and uptime reports.

Monthly

Check Search Console for security and indexing issues. Search site:yourdomain.com for spam pages. Confirm backups ran.

Quarterly

Review users and roles. Delete unused plugins. Check PHP version. Test a full restore to staging.

Mistakes that undo the checklist

  • Stacking security plugins. Two firewalls or scanners fighting each other slow the site and create blind spots. Pick one good tool and configure it properly.
  • Hiding instead of fixing. Renaming the login page reduces noise but does not replace strong passwords and two-step login.
  • Leaving old copies online. A forgotten staging site at dev.yourdomain.com with old plugins is an open door.
  • Agencies with permanent admin access. Give vendors their own accounts, and remove them when the job ends.

How JLB USA handles this

Our hosting and support covers updates, constant automated monitoring and malware cleanup, so the checklist above gets done without someone on your team remembering it. Sites we build are custom WordPress with a lean plugin list from the start. The same habits apply to the rest of your business systems, which our cybersecurity service covers.

Book it now · Free

Book a free 30-minute call

Pick a time. We look at what you have now with you and tell you what we would change first. No obligation.

Prefer to talk now? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

Do I need a security plugin for WordPress?

A good security plugin or a host-level firewall helps, but it is one layer. Updates, two-step login, fewer plugins and tested backups do more of the work. Avoid running several security plugins at once.

How often should I update WordPress plugins?

At least weekly. Patchstack’s 2026 report found heavily exploited vulnerabilities were attacked at scale within a median of about five hours of disclosure, so slow updates leave a real gap.

Is WordPress secure enough for a business website?

Yes, when it is maintained. Patchstack counted only six vulnerabilities in WordPress core in 2025. Most risk comes from plugins, themes and weak logins, which the checklist addresses.

What is a WordPress security audit?

A review of users, plugins, themes, versions, hosting settings, backups and logs against a checklist like this one, ending with a prioritized list of fixes.

Related services

Want a second opinion on your website or marketing?

Pick a time for my free callCall 954-539-5678