WordPress security basics for small businesses.

Most WordPress sites that get compromised were not targeted. They were found by automated scans looking for old software and weak passwords. A handful of habits prevents nearly all of it.

Website guide · By Elevated Vibration · Updated October 2026

Keep everything updated

Outdated plugins are the most common way in. Update WordPress, plugins and themes on a schedule, and remove anything you no longer use, because inactive plugins can still be exploited.

Protect the logins

  • Give every person their own account. No shared admin login.
  • Use long, unique passwords stored in a password manager. See how to roll one out.
  • Turn on two-factor authentication for administrators.
  • Give each person the lowest role that lets them do their job.
  • Remove accounts when people leave.

Back up, and test the backup

Keep automatic backups stored away from the web server, and restore one from time to time to prove it works. A backup you have never restored is a hope, not a plan.

Choose plugins carefully

  • Install only what you need.
  • Prefer plugins that are widely used and recently updated.
  • Never install paid plugins from unofficial sources.

Use decent hosting and a firewall

A good host keeps the server software current and isolates your site from others. A security plugin or web application firewall blocks common attacks and alerts you to changes. Make sure the site uses HTTPS everywhere.

Signs something is wrong

  • Visitors are redirected to another site.
  • Pages or admin users appear that you did not create.
  • Search results for your site show unfamiliar text.
  • Your host or Google warns you about malware.
  • The site is suddenly very slow.

If you see any of these, change passwords, restore from a clean backup if you have one, and get help before making more changes.

Make it routine

Security is the result of regular maintenance, not a one-time setup. Our WordPress maintenance checklist puts these tasks on a schedule.

We host, update, back up and monitor WordPress sites. See website design, hosting and care.

Related articles

WordPress Maintenance Checklist

What to check weekly, monthly, quarterly and yearly to keep a WordPress site healthy.

Why It's Smart to Have Someone Manage Your Website

What quietly goes wrong on an unattended website, and what managed care actually covers.

HIPAA and Your Practice Website: Keep Patient Communication in the EHR

Why scheduling, messaging and intake belong in your EHR's patient tools, not in website forms.

Common questions

Straight answers.

Is WordPress secure?

Yes, when it is kept updated, uses reputable plugins and has strong login protection. Most compromises happen on neglected sites.

How do WordPress sites get hacked?

Usually through outdated plugins or themes, weak or reused passwords, or plugins from untrustworthy sources.

Do I need a security plugin for WordPress?

A security plugin or firewall is a sensible layer. It does not replace updates, backups and good login practices.

Worried about your site?

Send us the address. We'll tell you what we'd check first.

Book a free call