Website Security
Website Security Checklist for Business Websites
A practical website security checklist for business websites: updates, access, backups, a web application firewall, monitoring and what to do if the site is hacked.
· 8 min read
Why a website security checklist matters
Most business websites are not hacked because someone targeted the company. They are hacked because an automated tool found an outdated plugin, a weak password or an exposed admin page, and the site happened to be one of thousands scanned that day. The good news is that the controls that stop these attacks are well understood. The hard part is applying them consistently.
This website security checklist is written for business owners and the people who look after their sites. It works for WordPress, other content management systems and custom-built sites alike.
1. Keep everything updated
- Update the CMS core, themes and plugins as soon as security releases are published.
- Remove plugins and themes you no longer use. Deactivated code can still be exploited.
- Check that the hosting platform runs a supported version of PHP, Node.js or whatever your site depends on.
Outdated software is the most common way business websites are compromised, so this item comes first.
2. Lock down access
- Give every person their own account; never share an admin login.
- Use strong, unique passwords and turn on multi-factor authentication for every administrator.
- Remove accounts for staff and agencies who no longer work on the site.
- Limit admin access to the people who genuinely need it, and give editors only editor rights.
3. Protect the front door
- Serve the whole site over HTTPS with a valid certificate, and redirect HTTP to HTTPS.
- Put the site behind a web application firewall to block common attacks such as SQL injection, cross-site scripting and credential stuffing.
- Rate-limit or protect login pages so password-guessing tools are blocked.
- Use a content delivery network with DDoS protection if the site matters to revenue.
4. Back up, and prove the backup works
- Take automatic daily backups of files and the database, stored away from the web server.
- Keep several days or weeks of history so you can roll back to a point before an infection.
- Test a restore at least every quarter. A backup that has never been restored is an assumption, not a plan.
5. Monitor for problems
- Scan the site for malware and unexpected file changes every day.
- Monitor uptime and get alerts when the site goes down.
- Check whether Google Safe Browsing or security vendors have blacklisted the domain.
- Review admin login activity for logins from unexpected countries or at unusual times.
Continuous website malware monitoring means problems are found by you, not by your customers or by a browser warning.
6. Secure the domain and email
- Turn on registrar lock and multi-factor authentication at your domain registrar.
- Use DNSSEC where your DNS provider supports it.
- Publish SPF, DKIM and DMARC records so attackers cannot easily send email that appears to come from your domain.
7. Reduce what is exposed
- Hide or restrict admin URLs where the platform allows it.
- Turn off directory listing and remove test files, old copies of the site and database dumps from the web server.
- Make sure error messages do not reveal software versions or file paths.
- Review third-party scripts and remove any you no longer need.
8. Know what to do if the site is hacked
Write down, before you need it:
- Who to contact and how to take the site offline or put up a maintenance page.
- Where the clean backups are and who can restore them.
- How to change every password and revoke API keys.
- How to request removal from blacklists once the site is clean.
If the site is compromised, cleaning the visible damage is not enough; the way in has to be found and closed. That is the difference between malware removal that lasts and a reinfection next week.
How often to review this checklist
Run through the update, access and monitoring items monthly, and the full checklist at least twice a year or after any major change to the site. Keep a simple record of what was checked and when; it is useful evidence for clients and insurers.
When to get help
If the site generates leads or sales, its security is part of the business, not a side task for whoever built it. Techx4u website security services cover updates, a web application firewall, daily backups, malware monitoring and clean-up for WordPress and other platforms, so the checklist is done for you and evidenced every month.
Common questions
- What should a website security checklist include?
- At minimum: keeping the CMS, themes and plugins updated; individual accounts with strong passwords and MFA; HTTPS everywhere; a web application firewall; daily off-site backups with tested restores; malware and uptime monitoring; domain and email protection; and a written plan for what to do if the site is hacked.
- How often should I check my website's security?
- Check updates, user accounts and monitoring alerts at least monthly, run the full checklist twice a year, and review it after any major change such as a redesign, a new plugin or a change of hosting provider.
- Is WordPress secure enough for a business website?
- Yes, when it is maintained. Most WordPress compromises come from outdated plugins, unused themes and weak admin passwords rather than WordPress itself. Regular updates, MFA, a web application firewall and monitoring make it a solid platform for business sites.

Let's talk about your environment
Tell us what you are running and what worries you. We will come back with a straight assessment and a costed plan — no obligation.



