·

WordPress Security: Hardening Checklist for Small Business Sites

A no-fluff security checklist: updates, backups, MFA, file permissions, and common misconfigurations to fix today.

Most WordPress hacks are preventable. Use this checklist to reduce risk quickly.

Must-do checklist

  • Enable automatic updates (or schedule weekly patching).
  • Use strong admin passwords + MFA.
  • Limit login attempts and add rate-limiting.
  • Disable XML-RPC if not required.
  • Lock file permissions (avoid 777).
  • Take daily backups and test restore monthly.

Server-level improvements

  • WAF (Cloudflare/ModSecurity)
  • Malware scanning
  • Least-privilege database user

Security is not one plugin. It’s a habit: updates, monitoring, and clean access control.

Filed under:

Need help with your website?

Start with a Website Health Check for $49 and get a clear, written report of what your site needs.

Need help with your website? Get a Website Health Check + QA Report for $49 — a clear, written review of your site’s performance, security, and issues.