Most small business sites don't get hacked because someone specifically targeted them — they get hacked because automated scripts are constantly scanning the entire web for outdated plugins, weak passwords, and known vulnerabilities, and eventually land on a site that hasn't been maintained.
WordPress alone powers over 40% of all websites globally, which makes it the single largest target for these scripts, and plugin vulnerabilities accounted for 96% of all WordPress security issues reported in the most recent Wordfence security report — rising 68% year over year, with more than a third still unpatched. Your business isn't too small to be targeted; small businesses are frequently targeted precisely because they're less likely to have basic protections in place. Here are 20 things to check, organized by priority, so you know exactly where to start.
Foundational Hardening
Properly configured SSL, not just present
An SSL certificate is baseline in 2026, but installed isn't the same as configured correctly. Test your certificate at SSL Labs' free SSL test — you should get an A or A+ rating. A lower grade means misconfiguration that can still leave data exposed despite the padlock icon showing.
Every piece of software updated
Outdated software remains the most common entry point for attackers. Your CMS core, every theme, and every plugin needs regular updates — abandoned plugins that no longer receive security patches are a frequent, quiet source of compromise.
Strong, unique passwords everywhere
Weak or reused passwords remain one of the most common causes of a compromised admin account. Use long, unique passwords for every login — admin, hosting, email — managed through a password manager rather than memory.
Multi-factor authentication on admin access
MFA adoption sits around 70% of the workforce overall, but small businesses land on the lower end — usually because nobody set it up, not because anyone decided against it. Turning it on for your CMS admin, hosting account, and email takes about twenty minutes combined and closes off the single most common way accounts actually get compromised.
Access & Infrastructure
| Checklist Item | Why It Matters | Quick Check |
|---|---|---|
| 5. Trusted-source plugins and themes only | Poorly coded or "nulled" (pirated) premium plugins often ship with hidden backdoor access built in | Audit your installed plugins and remove anything from an unofficial or unknown source |
| 6. Correct file permissions | Incorrect permissions are a common vulnerability, especially on shared hosting | Confirm sensitive config files are never set to fully writable; ask your host to verify if you're unsure |
| 7. A web application firewall | A firewall blocks a large share of automated attack traffic before it ever reaches your site's code | Confirm one is active, either through your host or a dedicated security plugin |
| 8. Hardened login access | Brute-force login attempts and exposed remote-access endpoints are a common attack vector | Limit login attempts, and disable or restrict any legacy remote-access features you don't actively use |
| 9. Least-privilege user roles | Every account with admin-level access is another possible entry point | Audit user accounts and confirm each person has only the access level their role actually requires |
| 10. A reputable, security-conscious host | Hosting quality directly affects how much protection exists below the application layer | Confirm your host provides malware scanning, DDoS protection, and regular platform-level updates |
This is the layer where most real compromises happen — a single weak plugin or overly permissive file setting can undo every other item on this list.
Data, Monitoring & Resilience
11. Automated, off-site backups
No security measure is 100%. Without a clean, off-site backup, a hacked site can mean rebuilding from scratch and losing content, customer data, and SEO equity built over years.
12. Regular malware scanning
Automated scanning catches injected malicious code before it spreads or gets flagged by browsers and search engines, which is far less disruptive than discovering an infection after the fact.
13. Security headers configured
Headers like Content-Security-Policy and HSTS determine how much damage an attacker can do even after finding a foothold — they're a meaningfully deeper layer than SSL alone.
14. Input validation on every form
Cross-site scripting and SQL injection remain among the most common attack types blocked across the web. Every form on your site is a potential entry point if input isn't properly validated.
15. Secure cookie configuration
Cookies handling sessions or sensitive data should be flagged Secure and HttpOnly so they can't be intercepted or accessed by injected scripts.
16. Uptime and security monitoring
Ongoing monitoring catches a compromise in hours instead of weeks — the difference between a quick cleanup and a much larger recovery effort.
Pro tip: Unpatched plugins are frequently how an attacker gets an initial foothold — everything in this section is what determines how much damage that foothold can actually do once they're in. Both layers matter; neither one alone is enough.
Signs You're Already Compromised
17. Google flags your site or search results look wrong
A "This site may be hacked" warning in search results, or unfamiliar pages suddenly appearing in Google's index, is a clear signal something has already been injected.
18. Unfamiliar admin accounts or files
An admin account nobody on your team created, or unexplained files in your site's directory, are strong indicators of unauthorized access that needs immediate attention.
19. Nulled or pirated themes and plugins in use
Pirated premium software is a well-documented way attackers distribute backdoor access disguised as a free version of a paid product. If any are in use, assume compromise and investigate.
20. No tested recovery plan
If you can't say with confidence when your last backup was taken and that a restore has actually been tested, you don't have a recovery plan — you have an assumption, and it's usually wrong at the worst possible time.
The Bottom Line
Website security in 2026 isn't a single setting you turn on once — it's layered defense, built up item by item, that makes your site a harder target than the next one an automated script scans. Most of what matters here can be fixed with relatively little effort once you know what to check.
Start with the foundational items if you have gaps there, then work through access control and monitoring. The cost of prevention is a fraction of the cost of recovery. Choose accordingly.