Online shop security checklist

The short list of things that keep a small online shop, and its customers, safe: HTTPS, updates, logins, payments and backups.

ReferenceBeginner2 min readUpdated

Most small-shop compromises come from out-of-date plugins and weak passwords, not from the hosting. This checklist covers the things that matter most.

Encryption

Payments

  • Checkout uses your payment provider’s hosted or embedded form.
  • Card numbers are never stored, emailed or logged on your hosting.

Logins

  • Every admin account has a long, unique password, stored in a password manager. Strong passwords and password managers
  • Only the people who need admin access have it.
  • Two-factor authentication is on for WordPress admin, using a plugin you trust.

Updates

Backups

  • You take regular backups of files and the database, and keep a copy away from your hosting. How to back up WordPress
  • You’ve tested restoring one.

If something looks wrong

Unexpected redirects, new admin users or strange files are signs of a compromise. My website has been hacked: what to do

Questions people ask

Do I need PCI compliance?

If you use your payment provider’s hosted or embedded checkout, the provider handles the card data. Your provider will tell you which simple self-assessment applies to you.

Is free SSL good enough for a shop?

Yes. The free certificate provides the same encryption as a paid one.

Starting a small shop? Traxio’s ecommerce hosting runs WooCommerce with free HTTPS, free for your first 30 days, then £0.99 a month.

Popular

Tip: press / to search from any pageSee all results