WordPress security
WordPress security for a business website: a practical owner’s checklist
Security is a routine shared by the owner, developer and hosting provider. A security plugin can help, but it cannot replace maintained software, sensible permissions or a backup that actually restores.

Know who can get in
Keep an up-to-date list of WordPress administrators, hosting logins, domain accounts and recovery email addresses. Use individual accounts instead of sharing one administrator login. Give an editor the access needed to publish content, rather than full control of plugins and users.
Use strong unique passwords and multi-factor authentication where supported. Remove access after a project or employment ends. Test account recovery while the website is healthy; a forgotten recovery address can turn a minor incident into a long outage.
Make updates a controlled routine
Use supported WordPress, plugin, theme and PHP versions. Obtain extensions from trustworthy sources and remove abandoned or unused components. “Nulled” premium plugins are not a sensible saving for a business website.
Keep a restore point and test changes that affect forms, bookings or payments. Schedule routine maintenance and handle urgent security fixes promptly. Permanently hiding update controls is not a security strategy; define who is allowed to update and how the change is checked.
Protect the important paths
Login protection, sensible rate limits and a web application firewall can reduce abusive traffic. Review file permissions and prevent public access to backups, configuration files and private exports. HTTPS protects traffic in transit but does not make an unsafe plugin trustworthy.
Test the business actions that matter: a customer should not see another customer’s records, an editor should not become an administrator, and an unauthorised request should not change settings. Ask the developer to verify these boundaries on the server.
Treat backups as a recovery service
Back up both the database and the files needed to recreate the website. Keep a copy outside the same hosting account and protect access to it. Choose a frequency based on how much new work the business could afford to lose.
Restore a backup into a separate test environment periodically. Record how long it takes, what credentials are needed and which services must be reconnected. A successful backup notification alone does not establish that recovery will work.
Agree the first response before an incident
If you suspect a compromise, preserve relevant logs and a safe copy of the affected state. Limit harmful activity, identify the entry point, clean or rebuild from a trustworthy baseline, and rotate affected credentials. Simply deleting an unfamiliar file can leave the original weakness open.
After recovery, test forms, payments and email, check for unfamiliar administrator accounts and document what changed. No single plugin or firewall offers a permanent “hack-proof” guarantee. Reliable maintenance reduces the chance and impact of a failure.
Use a weekly maintenance sheet, not a pile of plugins
For each site, record the WordPress version, active theme, essential plugins, PHP version, last successful backup and person responsible. Remove extensions you no longer need after checking dependencies. Buy maintained plugins from their original publisher; an unlicensed copy can cost more than the licence it appears to save.
Use the WordPress hardening guidance (opens in a new tab / नए टैब में) as a baseline. An administrator should assess file permissions and whether dashboard code editing is needed. Do not apply a recursive permission change blindly: ownership differs across hosts.
A useful post-update check for a small business
A successful update message is only the start. Keep a short test list that another person can repeat. For a brochure site, check mobile navigation, the contact form and notification delivery. For a shop, also check stock, a test checkout and the order status; a real customer should not be the first tester.
Avoid overlapping security plugins that compete to block the same request. Choose controls for a known need, record their settings and test legitimate users. If suspicious changes appear, preserve evidence, restrict access and fix the entry point before restoring a clean copy.
Reader conversation
Share your experience
What has worked for you, or what would you like to know about this topic?
1. Verify your email
Choose Send code to receive a verification email. Your email address stays private.
2. Write your comment
Verify your email before submitting a comment.

Reader comments