Get in touch

Have a project in mind? Tell us a bit about it.

Enquiry Form

Most small business website security advice reads like it was written for a bank. Two-factor everything, quarterly penetration tests, a dedicated security team on call. If you run a five-to-twenty page WordPress site for a local business, that advice is not wrong, exactly — it is just aimed at someone else’s problem. The actual risk to a small business site is dull and mechanical: an out-of-date plugin gets exploited by a bot that is scanning millions of sites a day, not a human attacker who has chosen you specifically. That distinction changes what is worth doing.

Here is what we actually check, and fix, when we take over maintenance on a client’s site — in the order it matters, not the order that sounds impressive.

Updates are the whole ballgame, and almost nobody treats them that way

The overwhelming majority of WordPress compromises trace back to a known, already-patched vulnerability in a plugin, theme, or WordPress core itself that simply never got updated. Not a zero-day. Not a sophisticated attacker. A hole that was closed months earlier in an update the site owner clicked “remind me later” on, repeatedly, until a bot found it first.

The fix isn’t glamorous: core, theme, and plugin updates applied on a schedule, not whenever someone remembers. If you can’t commit to checking weekly, a managed host or maintenance service that applies updates for you is worth the cost on this point alone. The one caveat is to update on staging first if you’re running anything with custom code, because updates occasionally break things — but “it might break something” is a reason to test before updating, never a reason to skip updating.

Backups are what make every other mistake survivable

Assume, for a moment, that something gets through anyway — a plugin vulnerability nobody had patched yet, a compromised password, a supply-chain issue in a third-party script. The single factor that determines whether that’s a bad afternoon or a bad month is whether you have a backup from before it happened, stored somewhere the compromise can’t reach.

That last part matters more than people think. A backup plugin that saves copies to the same server as the site isn’t much of a backup; if the server gets wiped or the account gets locked, the backup goes with it. The standard here is off-site, automated, and tested: backups that run daily or on every change, land in a separate location (cloud storage, a different host, wherever), and that someone has actually tried restoring at least once. An untested backup is a hypothesis, not a safety net.

Logins are the door, so treat them like one

A short list, all of it boring, all of it effective:

  • Unique, long passwords for every account with access — not “Website2024!” reused from the email account. A password manager makes this free to do right.
  • No shared logins. If three people touch the site, that’s three accounts, not one login everyone knows, because you can’t tell who did what or revoke one person’s access without changing the password for everyone.
  • Two-factor authentication on the WordPress admin login and the hosting account. This one step blocks the large majority of credential-stuffing attempts, where bots try passwords leaked from other sites’ breaches against your login.
  • Login attempt limiting, so a bot can’t sit there guessing passwords indefinitely. Most security plugins include this, and some hosts enforce it automatically.
  • User roles that match what people actually need. A guest blogger doesn’t need administrator access to publish a post; the “Author” or “Editor” role covers it, and it means a single compromised contributor account can’t take down the whole site.

What a security plugin actually catches, and what it doesn’t

Security plugins are useful and worth running, but it’s worth being specific about what they do. A malware scanner compares your site’s files against known-bad signatures and flags suspicious changes — genuinely helpful for catching an infection early, before it does more damage or gets your site blacklisted by Google. A firewall (often bundled in) blocks a lot of automated attack traffic before it reaches WordPress at all.

What they don’t do is replace updates or backups. A scanner tells you something bad already happened; it doesn’t prevent the vulnerability that let it happen, and it can’t undo the damage the way a clean backup can. Think of a security plugin as a smoke detector, not a fire extinguisher and definitely not fireproofing. All three layers matter, but they’re not interchangeable.

The infrastructure layer: hosting, HTTPS, and DNS

A few things worth confirming once and then mostly forgetting about:

  • HTTPS (the padlock) should be active site-wide, not just on a checkout page, and any lingering http:// links should redirect. Most hosts issue a free SSL certificate automatically now, so if yours doesn’t, that’s worth a conversation with the host.
  • Choose a host that patches its own server software and offers automatic backups as part of the plan, not as a $15/month add-on you have to remember to enable. The cheapest hosting plan is rarely the cheapest option once you count the hours spent cleaning up after it.
  • Lock down access to your domain registrar account with the same seriousness as the WordPress login — whoever controls the domain can redirect your entire site and email, and domain-level compromises are harder to recover from than a hacked WordPress install.

What’s genuinely overkill for a five-page brochure site

Not everything marketed as “security” earns its complexity budget for a small site. A web application firewall with custom rule tuning, a dedicated security operations subscription, IP allowlisting that locks out your own team when they travel — these solve problems that mostly belong to high-traffic e-commerce sites or platforms handling sensitive user data, not a local plumbing company’s website. If a vendor’s pitch is scaled for a target that isn’t you, it’s fine to say so and move on.

The same goes for stacking three overlapping security plugins “to be safe.” Beyond a certain point, more scanners running against each other create conflicts and slow the site down without meaningfully improving the odds. One well-configured plugin, current updates, and real backups outperform four plugins fighting for the same job.

A twenty-minute monthly routine beats a security audit you do once and forget

Security on a small business site isn’t a project with an end date; it’s closer to changing the batteries in a smoke detector. The version that actually works is small and repeatable: confirm updates ran, glance at the security plugin’s log for anything flagged, verify the latest backup exists and is recent, and check that no unfamiliar admin users have appeared. Twenty minutes, once a month, catches almost everything before it becomes a story worth telling. The version that doesn’t work is the one-time lockdown everyone feels good about in January and nobody revisits until something breaks in October.