An emergency WordPress malware cleanup recently took over part of my weekend. The infection was worse than I expected, and it was a reminder of something every small business owner should know:
WordPress needs ongoing maintenance and security.
Your website might look fine while important updates, expired plugin licenses, and old accounts pile up behind the scenes. Eventually, those overlooked details can become expensive problems.
You don’t need to become a cybersecurity expert to improve your WordPress security. Start with these practical steps—and make sure someone is responsible for keeping them done.
1. Update WordPress, plugins, and themes
WordPress updates aren’t just about new features. They can also fix security weaknesses.
Keep all three parts of your website updated: WordPress itself, your plugins, and your themes. You can check available updates under Dashboard → Updates.
Before updating, confirm you have a recent backup. Afterward, check your important pages and test anything customers rely on, such as booking, checkout, and contact forms. WordPress’s own update guidance recommends backing up before making changes.
Updates can occasionally cause compatibility problems. For a business-critical website, have your provider test significant changes on a private copy first. Avoiding updates indefinitely leaves the underlying security problem unresolved.
2. Remove plugins and themes you don’t need
Every plugin you keep is another piece of software to maintain.
Review what’s installed. Remove plugins you no longer use, and replace tools that are no longer maintained. Download software from the official WordPress directory or the developer’s legitimate website—not a site offering “free” copies of paid products.
Remove unnecessary themes, too, but keep any parent theme your active theme depends on. If you keep a default theme as a fallback, update it.
Not sure what a plugin does? Check before deleting it. Something that looks unused may power your forms, backups, or page layouts. These steps fit WordPress’s broader security hardening guidance.
3. Use unique passwords and turn on two-factor authentication
Use a long, unique password for every important account. A password manager makes that much easier.
Then enable two-factor authentication, or 2FA. It adds another verification step when you sign in, so a stolen password alone is less useful to an attacker. WordPress recommends both strong passwords and 2FA in its password security guidance.
Protect more than your WordPress login. Enable 2FA wherever available for your hosting account, domain registrar, and the email account used for password resets. Store recovery codes somewhere safe.
Avoiding the username “admin” is a reasonable extra precaution, but don’t treat your username as a secret. Strong authentication matters much more.
4. Set up automatic backups—and make sure they work
This is one of the biggest things missing from many website maintenance plans.
A complete WordPress backup needs both your website files and your database. Keep multiple versions, including a copy stored separately from your website’s hosting environment. WordPress explains these requirements in its backup guidance.
Choose a backup frequency based on how much work you could afford to lose. Daily backups are a practical starting point for many businesses; a busy online store may need more frequent protection.
Ask your provider to test a restore. “Backups are enabled” and “we can successfully recover your website” are different promises.
Backups don’t prevent hacking, but they can make recovery much less painful.
5. Review who has access to your website
Does a former employee still have a login? What about the contractor who finished a project two years ago?
Remove access people no longer need. Before deleting a WordPress user, make sure their posts or pages are reassigned appropriately.
Give each person their own account and only the permissions their work requires. Someone writing blog posts may need an Author or Editor account, rather than full Administrator access. WordPress provides different user roles for exactly this reason.
6. Keep contact forms maintained and protected
A contact form can be an important source of new business. You don’t need to remove it simply because visitors can type into it.
The security concern is whether the software safely handles those submissions. WordPress’s developer security guidance explains that incoming data needs appropriate checking and handling.
For a small business owner, the practical steps are straightforward:
- Use an actively maintained form plugin or service.
- Install its security updates promptly.
- Enable its spam protection.
- Disable file uploads unless you actually need them.
- Test that legitimate customer inquiries still reach you.
CAPTCHA can help reduce automated abuse, but it doesn’t repair vulnerable software.
If you don’t use a form at all, removing the unnecessary plugin is sensible. If it brings in customers, maintain it as part of your website. For more detail, read our guide to preventing website form spam.
7. Add protection against repeated login attempts
Automated tools can repeatedly try passwords against website login pages. Rate limiting restricts how quickly those attempts can happen.
Ask your host or website provider whether login protection is already included. WordPress outlines several defenses in its brute-force protection guidance.
A web application firewall can add another layer by filtering potentially malicious requests. Services such as Cloudflare offer these tools, but the protections depend on the features and configuration you use. Cloudflare’s firewall explanation describes how that filtering works.
Changing your login address may reduce some automated noise. Treat it as an optional extra after the basics are covered.
8. Confirm what your hosting provider actually handles
Paying for hosting doesn’t necessarily mean someone is maintaining your entire website.
Ask your provider:
- Who updates WordPress, plugins, and themes?
- Are backups included, and how do restores work?
- Is malware monitoring included?
- Who responds if the website is compromised?
Also confirm your site uses HTTPS. It encrypts information traveling between visitors and your website, but it doesn’t prevent every kind of attack or remove malware. Hosting, encrypted connections, and monitoring are all part of WordPress’s recommended security approach.
9. Give website maintenance an owner
Security tasks are easy to postpone when everyone assumes someone else is handling them.
Assign responsibility to yourself, an employee, or a website maintenance provider. Schedule regular reviews of updates, backups, user accounts, and important website functions.
Make sure security alerts go to an inbox someone actually checks. A routine review is useful, but urgent security updates shouldn’t wait for next month’s appointment.
Would a static website be a better fit?
For some small businesses, I recommend considering a static website—especially when the main job is to explain services, show previous work, and help customers get in touch.
A static site serves prebuilt pages. A simple setup can avoid a publicly accessible WordPress dashboard and a database generating pages for each visit. That removes several common attack routes and can make hosting simpler. Cloudflare explains the underlying approach here.
But static doesn’t mean unhackable. Hosting and publishing accounts still need protection, and added forms, booking tools, or other services bring their own security responsibilities.
WordPress can still be a good choice when its editing tools and features suit your business. The right decision depends on what your website needs to do—and who will maintain it. Our guide to dynamic vs. static websites explains the tradeoffs.
Confirm your backups, enable 2FA, and check for outstanding security updates. Those are useful first steps toward keeping your business website dependable.
If maintaining WordPress has become a chore, explore our WordPress-to-static rebuild service. We’ll help you work out whether a simpler website fits your business.