Security is a routine: reduce access, update safely, monitor changes and keep recoverable backups.
Steps
- Use unique admin accounts, strong passwords and multi-factor authentication; remove unused users.
- Keep core, active theme and plugins supported and updated. Delete abandoned or unused components.
- Use HTTPS, least-privilege file permissions and trusted plugins only; never install nulled themes.
- Schedule off-server file-and-database backups and test a restore.
- Review Site Health, admin users, security alerts, logs and unexpected file changes regularly.
Verify the result
Run an external malware scan and test backup restoration in staging.
Important: If compromised, preserve logs, change credentials from a clean device, restore known-good code and rotate database/API secrets.