codexier.

Maintenance & Security

WordPress Security Checklist for Company Sites

By CodexierPublished 5 min read

WordPress runs a large share of Swedish company websites, which makes it the platform automated attacks try first. The good news is that nearly every compromise uses one of a handful of doors: an outdated plugin, a guessable admin login, a forgotten account, or a host with no protection in front of the site. This checklist closes those doors in order of importance, and says when you can stop and when the site needs professional help.

Updates for core, themes and plugins

Vulnerabilities in plugins and themes are published, and attack scripts scan the whole internet for sites still running the old version. The window between a patch and mass exploitation is often days. Turn on automatic updates for minor core releases and for plugins from reputable authors, and set a weekly routine to apply the rest after checking the site still works. If you are afraid to update because something might break, that fear is itself a sign the site needs a staging copy and a maintenance routine.

  • Enable automatic minor updates for core; apply major versions after a test.
  • Update plugins weekly at a fixed time, then check the front page, a form and the checkout if you have one.
  • Replace plugins that have not been updated by their author in over a year.
  • Keep the PHP version current at the host; old PHP is unsupported and slow.

Admin logins and two-factor

The login page is attacked by scripts trying common passwords all day. A unique password from a password manager defeats the guessing; two-factor authentication defeats a stolen one. Give each person their own account with the lowest role that does the job, so an editor cannot install plugins and a compromised editor account cannot take the site down.

ControlWhat it stopsEffort
Unique strong password per userGuessing and reuse from other breachesMinutes
Two-factor authentication for all adminsUse of a stolen passwordMinutes per user
Limit failed login attemptsAutomated guessing at scaleOne plugin or host setting
No user named admin; least-privilege rolesObvious targets, damage from one accountMinutes
Change the default login URLSome automated noise; not a substitute for the aboveOptional

Removing unused plugins and users

Deactivated plugins are still code on the server and can still be exploited. Unused themes are the same. Old accounts from a previous agency or a former colleague are a door with no one watching it. Once a quarter, list every plugin, theme and user and delete what is not in use. The site becomes faster and simpler at the same time, and each update day gets shorter.

Backups stored off the server

A backup on the same server as the site disappears with the site. Store backups somewhere else, such as cloud storage in your own account, keep at least thirty days of them, and include both files and the database. Then test a restore once, on a staging copy, so that the first time you try it is not the day after an incident. Many Swedish hosts include daily backups; check how long they are kept and how you would restore one yourself.

  1. Daily automatic backups of files and database, kept for at least thirty days.
  2. Stored off the server, in an account your company controls.
  3. A restore tested at least once, with the steps written down.
  4. A manual backup taken before every major update or redesign.

Hosting-level protection

The cheapest security is the attack that never reaches WordPress. A web application firewall, either at a managed WordPress host or through a service in front of the site, blocks known attack patterns, rate-limits login attempts and filters bots. Add HTTPS with a valid certificate, which every host now provides, and a malware scan that alerts you rather than waiting for a customer to notice. If your host offers none of this, that is a reason to move.

When you do not need to buy anything: a small brochure site on a good managed host, with automatic updates, two-factor enabled and the host's backups, is already in decent shape; run through this list yourself in an afternoon. Bring in help when the site takes payments or holds customer data, when it has been compromised before, when nobody has updated it in months, or when you cannot say who has admin access. Our performance and security optimisation is a one-time hardening at a fixed 9,990 kr, and the monthly maintenance package at 4,990 kr per month carries the routine for you; a free 15-minute call is enough to say which of the two your site needs, or that neither is necessary yet.

Frequently asked questions

How do I know if my WordPress site has been hacked?

Common signs are unknown admin users, pages or links you did not create, redirects to other sites, a browser or search warning, spam sent from your domain, or the host suspending the account. A malware scanner and a review of the users list catch most cases. If in doubt, take a backup, change all passwords and get the site checked.

Is a security plugin enough?

A good security plugin helps with login limits, scanning and some firewall rules, but it runs inside WordPress and cannot stop what the host lets through. It is one layer. Updates, two-factor, off-server backups and a firewall in front of the site are the others, and none replaces the rest.

How often should a company WordPress site be updated?

Weekly for plugins and themes, immediately for security releases, and after a test for major core versions. If you cannot commit to a weekly routine, a maintenance plan is the honest alternative; a site updated twice a year is the profile of most compromised sites.

Not sure whether your site is exposed?

Tell us what the site does and when it was last updated. In 15 minutes we walk through this checklist with you and say whether a one-time hardening, a maintenance plan or an afternoon of your own time is the right fix.

Book a free 15-minute call