WordPress Security Checklist for Small Business (2026)

WordPress Security Checklist for Small Business (2026)

Small businesses are targeted by hackers more often than most owners assume, not because their site holds particularly valuable data, but because it’s an easy target. Automated bots scan millions of websites daily looking for outdated plugins and weak passwords, and they don’t care how big your business is.

Direct answer: the most important WordPress security steps, in order, are enabling two-factor authentication on all admin accounts, keeping WordPress core, themes and plugins updated weekly, using strong unique passwords, running automated off-site backups, and installing a security plugin to scan for malware. Doing these five well covers most of the risk a small business site actually faces.

Here’s what to do first, and what genuinely matters less.

Why small business sites get targeted

Hackers rarely single out small businesses on purpose. Automated attacks scan the entire internet for known vulnerabilities, and a small business site using an outdated plugin is just as vulnerable as anyone else’s. What hackers usually want isn’t your customer list. It’s often your server’s resources, used to send spam, or your domain’s reputation, used to host a phishing page without your knowledge, sometimes for weeks before you notice.

The checklist: what to fix first

1. Turn on two-factor authentication

This is the single highest-impact step on this list. Two-factor authentication means a stolen or guessed password alone isn’t enough to log in, since a second code from your phone is also required.

How to fix it: install a free two-factor authentication plugin and enable it for every account with admin, editor, or publishing access, not just your own.

2. Update WordPress core, themes and plugins weekly

Most successful attacks on small business sites exploit a known vulnerability in outdated software, not some sophisticated new technique. Set a recurring fifteen minute task, weekly, to check for and apply updates.

How to fix it: log into your dashboard, back up first, apply any pending updates, and quickly check your site still looks and works correctly afterwards.

3. Remove plugins and themes you’re not using

An inactive plugin still sitting on your server is still a potential entry point, even if it’s switched off. Hackers don’t care whether it’s active.

How to fix it: go through your plugin list and genuinely delete, not just deactivate, anything you’re not using.

4. Use strong, unique passwords

Reused or simple passwords remain one of the easiest ways into a website. If your WordPress password is also your email password, one breach anywhere becomes a breach everywhere.

How to fix it: use a password manager to generate and store a long, unique password for your WordPress admin account specifically.

5. Run automated, off-site backups

If something does go wrong, a recent, working backup is what turns a disaster into an afternoon’s inconvenience.

How to fix it: use a backup plugin set to run automatically, storing copies somewhere other than your own server, such as a cloud storage service, so a compromised server can’t also destroy your backup.

6. Install a security plugin for malware scanning

A dedicated security plugin can catch problems you’d never spot by eye, scanning your files for injected malicious code and alerting you early.

How to fix it: install a reputable free security plugin and let it run its scheduled scans. Investigate any alert promptly rather than dismissing it.

Prioritised checklist

Priority Task Time needed
Do first Enable two-factor authentication on all accounts 15 minutes
Do first Set a weekly update routine 15 minutes a week
Do soon Remove unused plugins and themes 20 minutes
Do soon Switch to a password manager and unique passwords 30 minutes
Ongoing Automated off-site backups Set up once, runs automatically
Ongoing Security plugin with scheduled scans Set up once, runs automatically

How do I know if my WordPress site has been hacked?

Common warning signs include unexpected new admin accounts you didn’t create, unfamiliar pages or posts appearing on your site, your site being flagged by Google’s Safe Browsing warning, a sudden and unexplained drop in traffic, or your hosting provider contacting you about unusual server activity. If you notice any of these, act quickly rather than waiting to see if it resolves itself.

What to do if your site is already hacked

Change all your passwords immediately, including hosting and email, since a compromised website often means a compromised admin account too. Restore from your most recent clean backup if you have one, or contact your hosting provider, since many offer malware removal support. Once the site is clean, work through the checklist above properly before considering the incident closed, since whatever let the attacker in the first time is still a risk until it’s fixed.

Security and routine maintenance work together

Security is really one part of a wider maintenance habit. If you haven’t got a broader routine in place yet, our website maintenance checklist for small business covers the full weekly, monthly and quarterly picture, of which security is one important slice, not the whole task.

FAQs

How do I know if my WordPress site has been hacked? Watch for new admin accounts you didn’t create, unfamiliar content appearing on your site, Google flagging it as unsafe, a sudden traffic drop, or your host reporting unusual activity. Any of these warrants immediate investigation.

What is the most common way WordPress sites get hacked? Outdated plugins and themes with known, unpatched vulnerabilities are the most common entry point, followed by weak or reused passwords on admin accounts.

Do I need a security plugin? It’s strongly recommended, since it automates malware scanning you wouldn’t reliably catch by eye. A free, reputable option is a reasonable starting point for most small business sites.

What should I do first if my site is hacked? Change all your passwords immediately, including hosting and email accounts, then restore from a clean backup if you have one, or contact your hosting provider for malware removal support.

progressd Avatar
No comments to show.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

Insert the contact form shortcode with the additional CSS class- "wydegrid-newsletter-section"

By signing up, you agree to the our terms and our Privacy Policy agreement.