Most small-shop compromises come from out-of-date plugins and weak passwords, not from the hosting. This checklist covers the things that matter most.
Encryption
- Every page loads over HTTPS, with no mixed-content warnings. How to fix mixed content warnings
- HTTP redirects to HTTPS. How to force HTTPS (redirect HTTP to HTTPS)
Payments
- Checkout uses your payment provider’s hosted or embedded form.
- Card numbers are never stored, emailed or logged on your hosting.
Logins
- Every admin account has a long, unique password, stored in a password manager. Strong passwords and password managers
- Only the people who need admin access have it.
- Two-factor authentication is on for WordPress admin, using a plugin you trust.
Updates
- WordPress, WooCommerce, the theme and every plugin are up to date. Updating WordPress, themes and plugins safely
- Unused plugins and themes are deleted, not just deactivated.
Backups
- You take regular backups of files and the database, and keep a copy away from your hosting. How to back up WordPress
- You’ve tested restoring one.
If something looks wrong
Unexpected redirects, new admin users or strange files are signs of a compromise. My website has been hacked: what to do
Questions people ask
Do I need PCI compliance?
If you use your payment provider’s hosted or embedded checkout, the provider handles the card data. Your provider will tell you which simple self-assessment applies to you.
Is free SSL good enough for a shop?
Yes. The free certificate provides the same encryption as a paid one.
Starting a small shop? Traxio’s ecommerce hosting runs WooCommerce with free HTTPS, free for your first 30 days, then £0.99 a month.