Website Security Checklist: Secure Your Domain, Hosting & WordPress Website
Your website is more than a digital business card. It is an important business asset that may store customer information, process inquiries, support sales, and represent your brand around the clock.
A weak password, expired SSL certificate, outdated plugin, compromised hosting account, or failed backup can expose your website to malware, data theft, downtime, and costly repairs.
Use this printable website security checklist to review the protection of your domain name, hosting account, WordPress website, backups, and ongoing maintenance.
Domain Name Security Checklist
Registrar Account Security
- Domain is registered with a reputable domain registrar.
- Registrar account uses a strong, unique password.
- Two-factor authentication is enabled.
- Account recovery email address is current and accessible.
- Account recovery phone number is current.
- Domain expiration date is monitored.
- Automatic domain renewal is enabled.
- Payment information for renewal is current.
- WHOIS privacy protection is enabled when available.
- Registrar login information is stored securely in a password manager.
Domain Locking and Transfer Protection
- Registrar lock or domain transfer lock is enabled.
- Unauthorized transfer protection is enabled when offered.
- Domain authorization codes are stored securely.
- Domain ownership and administrative contact information are correct.
- Unexpected domain transfer or ownership emails are treated as suspicious.
DNS Protection
- DNS records have been reviewed and are accurate.
- Unused and outdated DNS records have been removed.
- Access to DNS settings is limited to authorized users.
- DNS changes are documented.
- DNSSEC is enabled when supported by the registrar and hosting configuration.
- Email authentication records are configured when applicable, including SPF, DKIM, and DMARC.
Hosting Account Security Checklist
Hosting Account Access
- Hosting account uses a strong, unique password.
- Two-factor authentication is enabled for the hosting control panel.
- Only authorized users have access to the hosting account.
- Former employees, contractors, and developers no longer have access.
- Each authorized user has a separate account when the host supports it.
- Hosting account recovery information is current.
- Hosting login and account activity are reviewed periodically.
Server Security
- The server uses a currently supported PHP version.
- Server software receives security updates.
- Automatic security patches are enabled when appropriate.
- A web application firewall is enabled.
- Malware scanning is enabled.
- DDoS protection is available through the host or a content delivery network.
- Server error logs are accessible and reviewed.
- Unused databases, staging sites, and old website installations are removed.
- Development and staging environments are protected from public access.
File Access
- SFTP or SSH is used instead of unencrypted FTP.
- Plain FTP access is disabled when it is not needed.
- Unused SFTP, SSH, and database accounts have been removed.
- File permissions follow least-privilege principles.
- Sensitive configuration and backup files are not publicly accessible.
- Private keys and credentials are not stored in publicly accessible directories.
SSL and HTTPS Checklist
- A valid SSL certificate is installed.
- The website loads securely with HTTPS.
- HTTP traffic automatically redirects to HTTPS.
- No mixed-content warnings appear in the browser.
- All internal website links use HTTPS.
- SSL certificate renewal is automated.
- SSL certificate expiration is monitored.
- Forms, login pages, checkout pages, and account pages load securely.
WordPress Core Security Checklist
- WordPress is updated to the latest stable version.
- Automatic updates are configured appropriately.
- The default “admin” username is not used.
- Administrator access is limited to trusted users.
- Unused WordPress installations have been removed.
- Unused themes have been removed.
- Unused plugins have been removed.
- Only one trusted default theme is retained as a fallback.
- WordPress dashboard file editing is disabled when appropriate.
- Debugging is disabled on the live production website.
- Security keys and salts are properly configured.
- The WordPress database uses a unique table prefix when practical.
Plugin and Theme Security Checklist
- Plugins are obtained only from trusted developers and sources.
- Themes are obtained only from trusted developers and sources.
- Nulled, pirated, or illegally modified plugins and themes are never used.
- All installed plugins are actively maintained.
- All installed themes are actively maintained.
- Plugin and theme updates are installed regularly.
- Changelogs are reviewed before major updates.
- Updates are tested on a staging website when appropriate.
- The website is tested after updates.
- Known vulnerable plugins and themes are replaced or updated immediately.
- Abandoned plugins and themes are replaced with supported alternatives.
- Plugins with overlapping or unnecessary functionality are removed.
User Account and Login Security Checklist
- Every user has an individual account.
- User accounts are never shared between multiple people.
- Passwords are unique and at least 14 to 16 characters long.
- A reputable password manager is used.
- Two-factor authentication is enabled for administrators.
- Two-factor authentication is enabled for editors and other privileged users when possible.
- User roles follow the principle of least privilege.
- Users receive only the permissions needed for their responsibilities.
- Inactive and unnecessary accounts are removed.
- Former employee and contractor accounts are removed promptly.
- Login attempt limiting or rate limiting is enabled.
- Suspicious login alerts are enabled.
- Password reset emails are monitored for unauthorized activity.
Backup and Recovery Checklist
- Automatic website backups are enabled.
- Backups are performed at least daily for frequently updated websites.
- Backups include both website files and the database.
- Backups are stored outside the website’s hosting account.
- Multiple backup versions are retained.
- Backup storage is encrypted or otherwise protected.
- Backup completion notifications are monitored.
- Failed backup notifications are investigated promptly.
- A full website restoration test has been completed recently.
- Website recovery instructions are documented.
- Authorized personnel know where backups are stored.
Malware and Security Monitoring Checklist
- Malware scanning is enabled.
- Security scans are performed regularly.
- File integrity monitoring is enabled.
- Unexpected file changes are investigated.
- Suspicious login attempts are monitored.
- Administrative account changes are monitored.
- Website uptime monitoring is configured.
- SSL certificate monitoring is configured.
- Domain expiration monitoring is configured.
- Security notifications are sent to an actively monitored email address.
- Google Search Console is monitored for security warnings and indexing problems.
- Unexpected redirects, pop-ups, and spam pages are investigated immediately.
Forms, Spam, and Data Protection Checklist
- Contact forms use spam protection.
- CAPTCHA or another bot-protection method is enabled when appropriate.
- Form submissions are validated and sanitized.
- Sensitive personal information is not collected unless necessary.
- Form notification emails are sent securely.
- Uploaded files are restricted by file type and size.
- Uploaded files are scanned or otherwise handled securely.
- Customer and user data are retained only as long as necessary.
- Privacy policies accurately describe data collection and storage practices.
E-Commerce Website Security Checklist
- Payment information is processed by a reputable payment provider.
- Full credit card details are not stored directly on the website.
- WooCommerce or other e-commerce software is updated regularly.
- Checkout, account, and payment pages use HTTPS.
- Administrator and shop manager accounts use two-factor authentication.
- Fraud-prevention features are configured where appropriate.
- Order and payment notifications are monitored for suspicious activity.
- Unused payment gateways are disabled.
Website Security Header Checklist
- HTTP Strict Transport Security is considered and configured appropriately.
- X-Content-Type-Options is configured.
- Frame protection is configured with X-Frame-Options or Content Security Policy.
- Referrer-Policy is configured.
- Permissions-Policy is configured where appropriate.
- A Content Security Policy is evaluated and implemented when practical.
- Server software version information is not unnecessarily exposed.
Performance and Security Checklist
- A reputable content delivery network is enabled when appropriate.
- Website caching is configured correctly.
- Images are optimized.
- Unused scripts, stylesheets, and assets have been removed.
- Unnecessary third-party scripts are removed.
- Third-party integrations are reviewed periodically.
- Performance problems that may indicate malware are investigated.
- Website speed and server resource usage are monitored.
Business Continuity Checklist
- Domain registrar access is documented securely.
- Hosting account access is documented securely.
- WordPress administrator access is documented securely.
- Backup locations and recovery procedures are documented.
- Emergency technical contacts are documented.
- A malware incident response plan exists.
- A website restoration procedure exists.
- A plan exists for notifying affected customers when legally required.
- Ownership of the domain, hosting, website files, and accounts is clearly documented.
- The business owner retains access to critical website accounts.
Recommended Website Maintenance Schedule
| Security Task | Recommended Frequency |
|---|---|
| WordPress core updates | Weekly or as security updates become available |
| Plugin and theme updates | Weekly |
| Website functionality testing | After every update |
| Malware scan review | Weekly |
| Backup verification | Weekly |
| Uptime and security alert review | Weekly |
| SSL certificate check | Monthly |
| User account and permission audit | Monthly |
| Domain and DNS review | Quarterly |
| Full backup restoration test | Quarterly |
| Full website security audit | Quarterly |
Why Weekly Website Maintenance Matters
Website security is not a one-time project. New software vulnerabilities are discovered regularly, plugins and themes require updates, backups can fail silently, SSL certificates can expire, and suspicious login activity may go unnoticed.
For these reasons, working with a web developer who performs weekly website maintenance is strongly recommended.
A professional web developer can:
- Apply WordPress core, plugin, and theme updates safely.
- Review known software vulnerabilities.
- Run malware scans and review security logs.
- Verify that backups are completing successfully.
- Test forms, menus, checkout pages, and other functionality after updates.
- Monitor uptime, SSL status, website performance, and suspicious activity.
- Respond quickly when a website problem or security warning appears.
Regular maintenance can help identify small problems before they become expensive emergencies involving website downtime, data loss, malware removal, or complete site restoration.
Quick Website Security Score
Give yourself one point for every completed item below.
- Two-factor authentication is enabled on the domain registrar account.
- Two-factor authentication is enabled on the hosting account.
- SSL and HTTPS are working correctly.
- WordPress core is fully updated.
- Plugins and themes are fully updated.
- Automatic daily backups are enabled.
- Backups are stored off-site.
- Malware scanning is enabled.
- Login protection is enabled.
- Professional weekly maintenance is being performed.
- 9–10 points: Excellent protection. Continue monitoring and maintaining your website.
- 7–8 points: Good protection, but review and address the missing items.
- 5–6 points: Moderate risk. Important security improvements are needed.
- 0–4 points: High risk. Address the most serious security gaps as soon as possible.
Print or Download This Checklist
Print this checklist or save it as a PDF, and review it at least once every month. A short security review can help prevent downtime, data loss, malware infections, domain theft, and emergency repair costs.
Keep a completed copy with your website documentation and record the date of each review.
Need Help Keeping Your WordPress Website Secure?
If you do not have time to monitor updates, backups, security alerts, malware scans, and website functionality yourself, consider working with a web developer who provides ongoing weekly maintenance.
Eliyahna Creative provides WordPress maintenance, security reviews, updates, backups, troubleshooting, and ongoing technical support to help keep your domain, hosting account, and website protected.
Contact Eliyahna.com