WordPress security for a small business site is hygiene. You update what you installed, you lock the door, you keep a copy. Most messy recoveries we see started with an old plugin or an admin password that was also used on email.
Hosting context: WordPress hosting. Cost of staying current: WordPress cost. NP SoftTech is a Hostinger partner. This list is still yours to do.
Update everything, unique passwords, two-factor on admin, delete unused plugins and users, HTTPS on, backups you have restored once. Skip pirated themes.
The checklist
- Update WordPress core when the admin offers it, on a copy if the site is busy.
- Update the theme and every plugin the same week. Delete what you do not use.
- Use unique admin usernames. Do not stay on
adminwith a reused password. - Turn on two-factor for anyone who can install plugins.
- Give writers a lower role than administrator.
- Remove users who left the company.
- Force HTTPS. Fix mixed-content warnings after you switch.
- Keep PHP on a version your host still supports.
- Do not install nulled or “GPL club” copies of paid themes.
- Limit login attempts or use the host’s firewall if it is already there.
- Use a password manager. Do not share the owner account in a WhatsApp group.
- Take backups of files and the database. Restore one on a staging copy so you know it works.
WordPress Updates screen with core, theme and plugins current (no client data). ALT: WordPress dashboard showing updates applied.
What we will not sell you
A guarantee that you will never be scanned. WordPress is public software. You can make the cheap attacks fail. You cannot make the internet polite.
Speed after a cleanup: speed up WordPress. If you would rather not run this stack, WordPress vs custom and WordPress vs Shopify.
Send the URL. We will say update, rebuild or move host. Contact.