A repeatable WordPress security checklist
Start with controls you can verify on your own site. Generic breach statistics do not tell you whether an account, plugin or backup is secure. The earlier placeholder data source and unsupported prevalence claims have been removed.
Review access and software
Give each person a separate account with only the permissions needed. Review administrators and protect access with strong authentication. Keep software current, check the update source and remove abandoned or unnecessary plugins and themes.
Check detection and response
Know where access, application and security logs are kept and who reviews alerts. Investigate unexpected administrators, modified files or unfamiliar scheduled tasks. A scanner result needs assessment; a clean scan does not prove that every part of a site is safe.
Verify backups and changes
Choose backup frequency from how much recent work or order data you can afford to lose. Back up files and the database, protect recovery copies and test a restore away from the live site. After updates, check key customer journeys. Keep a documented escalation route and review the checklist whenever the site's responsibilities change.