A repeatable WordPress security checklist

← All articles

Start with controls you can verify on your own site. Generic breach statistics do not tell you whether an account, plugin or backup is secure. The earlier placeholder data source and unsupported prevalence claims have been removed.

Review access and software

Give each person a separate account with only the permissions needed. Review administrators and protect access with strong authentication. Keep software current, check the update source and remove abandoned or unnecessary plugins and themes.

Check detection and response

Know where access, application and security logs are kept and who reviews alerts. Investigate unexpected administrators, modified files or unfamiliar scheduled tasks. A scanner result needs assessment; a clean scan does not prove that every part of a site is safe.

Verify backups and changes

Choose backup frequency from how much recent work or order data you can afford to lose. Back up files and the database, protect recovery copies and test a restore away from the live site. After updates, check key customer journeys. Keep a documented escalation route and review the checklist whenever the site's responsibilities change.

Sources and further reading