Website security basics for small sites

The handful of habits that prevent most website compromises on shared hosting: updates, logins, permissions, HTTPS, backups and fewer moving parts.

ExplainerBeginner2 min readUpdated

Most small sites aren’t targeted personally. They’re found by automated scanners looking for known weaknesses. Remove the weaknesses and the scanners move on.

1. Keep software updated

Out-of-date plugins, themes and applications are the leading cause of compromise. Keeping website software updated

2. Protect every login

Unique passwords, two-factor authentication and limited login attempts. Hosting account security checklist Brute-force login attacks: how to recognise and stop them

3. Reduce what can be attacked

Delete unused plugins, themes, test scripts, old installs and staging copies you’ve finished with. Code that isn’t there can’t be exploited.

4. HTTPS everywhere

How to force HTTPS (redirect HTTP to HTTPS)

5. Correct file permissions

755 folders, 644 files, never 777. File permissions explained (644, 755 and why never 777)

6. Keep secrets out of the web root

No database dumps, backups or config copies in public_html. Storing configuration and secrets outside public_html

7. Validate input in your own code

Prepared statements for SQL, escaping output, checking uploads. Keeping your databases secure

8. Backups you can restore

The safety net for everything else. A simple backup strategy for your website

9. Watch for signs

Unexpected redirects, new admin users, unfamiliar files and warnings from search engines. My website has been hacked: what to do

New to Traxio? Hosting is 30 days free with no card needed, then £0.99 a month. See what’s included

Popular

Tip: press / to search from any pageSee all results