Keep everything updated
Outdated plugins are the most common way in. Update WordPress, plugins and themes on a schedule, and remove anything you no longer use, because inactive plugins can still be exploited.
Protect the logins
- Give every person their own account. No shared admin login.
- Use long, unique passwords stored in a password manager. See how to roll one out.
- Turn on two-factor authentication for administrators.
- Give each person the lowest role that lets them do their job.
- Remove accounts when people leave.
Back up, and test the backup
Keep automatic backups stored away from the web server, and restore one from time to time to prove it works. A backup you have never restored is a hope, not a plan.
Choose plugins carefully
- Install only what you need.
- Prefer plugins that are widely used and recently updated.
- Never install paid plugins from unofficial sources.
Use decent hosting and a firewall
A good host keeps the server software current and isolates your site from others. A security plugin or web application firewall blocks common attacks and alerts you to changes. Make sure the site uses HTTPS everywhere.
Signs something is wrong
- Visitors are redirected to another site.
- Pages or admin users appear that you did not create.
- Search results for your site show unfamiliar text.
- Your host or Google warns you about malware.
- The site is suddenly very slow.
If you see any of these, change passwords, restore from a clean backup if you have one, and get help before making more changes.
Make it routine
Security is the result of regular maintenance, not a one-time setup. Our WordPress maintenance checklist puts these tasks on a schedule.
We host, update, back up and monitor WordPress sites. See website design, hosting and care.
