Small Business Website Security Checklist 20 Things to Check in 2026

The green padlock doesn't mean secure. Here's what actually protects a small business website from the automated scripts scanning the web right now.

By Denmaq 11 min read

Most small business sites don't get hacked because someone specifically targeted them — they get hacked because automated scripts are constantly scanning the entire web for outdated plugins, weak passwords, and known vulnerabilities, and eventually land on a site that hasn't been maintained.

WordPress alone powers over 40% of all websites globally, which makes it the single largest target for these scripts, and plugin vulnerabilities accounted for 96% of all WordPress security issues reported in the most recent Wordfence security report — rising 68% year over year, with more than a third still unpatched. Your business isn't too small to be targeted; small businesses are frequently targeted precisely because they're less likely to have basic protections in place. Here are 20 things to check, organized by priority, so you know exactly where to start.

Foundational Hardening

1 /

Properly configured SSL, not just present

An SSL certificate is baseline in 2026, but installed isn't the same as configured correctly. Test your certificate at SSL Labs' free SSL test — you should get an A or A+ rating. A lower grade means misconfiguration that can still leave data exposed despite the padlock icon showing.

2 /

Every piece of software updated

Outdated software remains the most common entry point for attackers. Your CMS core, every theme, and every plugin needs regular updates — abandoned plugins that no longer receive security patches are a frequent, quiet source of compromise.

3 /

Strong, unique passwords everywhere

Weak or reused passwords remain one of the most common causes of a compromised admin account. Use long, unique passwords for every login — admin, hosting, email — managed through a password manager rather than memory.

4 /

Multi-factor authentication on admin access

MFA adoption sits around 70% of the workforce overall, but small businesses land on the lower end — usually because nobody set it up, not because anyone decided against it. Turning it on for your CMS admin, hosting account, and email takes about twenty minutes combined and closes off the single most common way accounts actually get compromised.

Digital security and website protection concept
Closing the most common entry points first

Access & Infrastructure

Checklist Item Why It Matters Quick Check
5. Trusted-source plugins and themes only Poorly coded or "nulled" (pirated) premium plugins often ship with hidden backdoor access built in Audit your installed plugins and remove anything from an unofficial or unknown source
6. Correct file permissions Incorrect permissions are a common vulnerability, especially on shared hosting Confirm sensitive config files are never set to fully writable; ask your host to verify if you're unsure
7. A web application firewall A firewall blocks a large share of automated attack traffic before it ever reaches your site's code Confirm one is active, either through your host or a dedicated security plugin
8. Hardened login access Brute-force login attempts and exposed remote-access endpoints are a common attack vector Limit login attempts, and disable or restrict any legacy remote-access features you don't actively use
9. Least-privilege user roles Every account with admin-level access is another possible entry point Audit user accounts and confirm each person has only the access level their role actually requires
10. A reputable, security-conscious host Hosting quality directly affects how much protection exists below the application layer Confirm your host provides malware scanning, DDoS protection, and regular platform-level updates

This is the layer where most real compromises happen — a single weak plugin or overly permissive file setting can undo every other item on this list.

Data, Monitoring & Resilience

11. Automated, off-site backups

No security measure is 100%. Without a clean, off-site backup, a hacked site can mean rebuilding from scratch and losing content, customer data, and SEO equity built over years.

12. Regular malware scanning

Automated scanning catches injected malicious code before it spreads or gets flagged by browsers and search engines, which is far less disruptive than discovering an infection after the fact.

13. Security headers configured

Headers like Content-Security-Policy and HSTS determine how much damage an attacker can do even after finding a foothold — they're a meaningfully deeper layer than SSL alone.

14. Input validation on every form

Cross-site scripting and SQL injection remain among the most common attack types blocked across the web. Every form on your site is a potential entry point if input isn't properly validated.

15. Secure cookie configuration

Cookies handling sessions or sensitive data should be flagged Secure and HttpOnly so they can't be intercepted or accessed by injected scripts.

16. Uptime and security monitoring

Ongoing monitoring catches a compromise in hours instead of weeks — the difference between a quick cleanup and a much larger recovery effort.

Pro tip: Unpatched plugins are frequently how an attacker gets an initial foothold — everything in this section is what determines how much damage that foothold can actually do once they're in. Both layers matter; neither one alone is enough.

Signs You're Already Compromised

17. Google flags your site or search results look wrong

A "This site may be hacked" warning in search results, or unfamiliar pages suddenly appearing in Google's index, is a clear signal something has already been injected.

18. Unfamiliar admin accounts or files

An admin account nobody on your team created, or unexplained files in your site's directory, are strong indicators of unauthorized access that needs immediate attention.

19. Nulled or pirated themes and plugins in use

Pirated premium software is a well-documented way attackers distribute backdoor access disguised as a free version of a paid product. If any are in use, assume compromise and investigate.

20. No tested recovery plan

If you can't say with confidence when your last backup was taken and that a restore has actually been tested, you don't have a recovery plan — you have an assumption, and it's usually wrong at the worst possible time.

The Bottom Line

Website security in 2026 isn't a single setting you turn on once — it's layered defense, built up item by item, that makes your site a harder target than the next one an automated script scans. Most of what matters here can be fixed with relatively little effort once you know what to check.

Start with the foundational items if you have gaps there, then work through access control and monitoring. The cost of prevention is a fraction of the cost of recovery. Choose accordingly.

Security monitoring dashboard on a computer screen
Layered defense, checked item by item

Next step

Not sure where your site stands?

We can help you run through this checklist, close the gaps, and set up ongoing monitoring so you're not doing this alone.