A Realistic WordPress Security Checklist for Small Business Sites

Most WordPress security advice is written for developers, or for sites big enough to have a dedicated security budget. Most small business sites have neither. This is a checklist built for the second group: what genuinely matters, roughly in order of impact, assuming you’re doing this yourself alongside everything else running a business involves.

1. Keep everything updated – but verify it, don’t just assume it

Outdated plugins are consistently the single most common way small WordPress sites get compromised, ahead of weak passwords or server misconfiguration. Turning on auto-updates helps, but it isn’t the same as knowing your site is current – updates fail silently more often than most owners realise, whether from a licensing hiccup, a corrupted download, or a plugin simply not supporting auto-updates at all. Check actual installed versions periodically, don’t just trust that “updates are on” means “everything’s updated.”

2. Use a password manager, not memory

This sounds basic because it is, and it’s still one of the highest-impact things on this list. A unique, generated password per account, stored in a password manager, removes an entire category of attack (credential stuffing from other sites’ breaches) that no amount of WordPress-specific hardening can fix on its own.

3. Turn on two-factor authentication for every admin account

If a password does leak, two-factor authentication is usually what stands between that leak and an actual compromise. This should be non-negotiable for any account with administrator access, not optional for the ones who “don’t want the hassle.”

4. Get real security headers sending correctly

Headers like X-Content-Type-Options, X-Frame-Options and a sensible Referrer-Policy close off entire categories of browser-based attacks, and they’re often either missing entirely or only partly working – many sites with a caching layer serve most visitors from a static cache that bypasses the PHP code meant to add these headers, so they need to be set at the server level too, not just in code that a cache can skip.

5. Have a real file-integrity check running, not a one-off scan

A single scan tells you the site was clean the day you ran it. An ongoing check that compares your files against official WordPress.org releases – and flags anything that’s changed, been added, or gone missing – is what actually catches a compromise while it’s still small, rather than months later.

6. Know what “recovery” actually means before you need it

Force-logout-everyone, reset-all-passwords, reinstall-core-and-plugins-from-source: these should be one click away, not a scramble to figure out during an actual incident. If your current setup doesn’t have this, that’s the gap to close before anything else on this list.

Oxyshield covers most of this checklist in one plugin: file integrity monitoring, security headers, two-factor authentication, and the recovery tools for when something does go wrong.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get in touch

Give us a call or fill in the form below and we'll contact you. We endeavor to answer all inquiries within 24 hours on business days.