Secure the accounts behind the site
Turn on multifactor authentication for the domain registrar, hosting account, content management system, email, and payment provider. Use a password manager and unique passwords. Remove accounts belonging to former employees or vendors, and avoid sharing one administrator login.
Keep the software and backups current
Apply supported updates to the site platform, plugins, themes, and dependencies. Remove extensions that are no longer used. Maintain automatic backups outside the live website and periodically test that a backup can actually be restored.
- Use HTTPS and redirect old HTTP links.
- Limit administrator access to people who need it.
- Monitor unexpected file changes and failed logins.
- Keep a written recovery contact list.
Know when to get professional help
Use a qualified security professional when the site handles sensitive personal data, stores payment details, has been compromised, or supports critical business operations. A legitimate assessment requires authorization and a defined scope. Never treat a public automated score as proof that a site is secure.
This guide provides general information. Website requirements vary by platform, audience, location, and business risk.