Most small sites aren’t targeted personally. They’re found by automated scanners looking for known weaknesses. Remove the weaknesses and the scanners move on.
1. Keep software updated
Out-of-date plugins, themes and applications are the leading cause of compromise. Keeping website software updated
2. Protect every login
Unique passwords, two-factor authentication and limited login attempts. Hosting account security checklist Brute-force login attacks: how to recognise and stop them
3. Reduce what can be attacked
Delete unused plugins, themes, test scripts, old installs and staging copies you’ve finished with. Code that isn’t there can’t be exploited.
4. HTTPS everywhere
How to force HTTPS (redirect HTTP to HTTPS)
5. Correct file permissions
755 folders, 644 files, never 777. File permissions explained (644, 755 and why never 777)
6. Keep secrets out of the web root
No database dumps, backups or config copies in public_html. Storing configuration and secrets outside public_html
7. Validate input in your own code
Prepared statements for SQL, escaping output, checking uploads. Keeping your databases secure
8. Backups you can restore
The safety net for everything else. A simple backup strategy for your website
9. Watch for signs
Unexpected redirects, new admin users, unfamiliar files and warnings from search engines. My website has been hacked: what to do
New to Traxio? Hosting is 30 days free with no card needed, then £0.99 a month. See what’s included