Notus Digital icon
01243 217 878
  • Work
  • Services
    • Web Design
    • WordPress
    • Search Engine Optimisation (SEO)
    • Conversion Rate Optimisation (CRO)
  • Contact
  • Blog
  • About
    • Jargon Buster
    • FAQs
Start a Project
Start a Project

Start a Project

"*" indicates required fields

Marketing consent
Notus Digital white logo
  • Work
  • Services
    • Web Design
    • WordPress
    • Search Engine Optimisation (SEO)
    • Conversion Rate Optimisation (CRO)
  • Contact
  • Blog
  • About
    • Jargon Buster
    • FAQs
Red padlock on a keyboard representing WordPress security for small businesses

WordPress security: a no-nonsense guide for small businesses

AUTHOR

Luke Hopkins

PUBLISHED ON

Apr 23, 2026

Red padlock on a keyboard representing WordPress security for small businesses
Home Blog: Insights, tips and tricks WordPress security: a no-nonsense guide for small businesses
TL;DR The short version

WordPress runs roughly 40% of the web, which makes it a permanent target. The good news is that the vast majority of WordPress sites get hacked because of a few preventable basics, not because attackers are clever. This post is a no-nonsense security checklist for small businesses: what actually matters, what to set up once and forget, and what to monitor going forward.

Why WordPress sites get hacked

Almost every WordPress hack falls into one of four buckets:

  • Outdated WordPress core, themes or plugins
  • Weak or reused passwords
  • Vulnerable or abandoned plugins
  • Poor hosting with no isolation between accounts

If you address all four, you remove around 95% of the realistic risk. Everything else is bonus. You don’t need to be a security expert to do this, you just need to actually do it.

Keep everything updated (the boring one that matters most)

The single most common reason small business sites get hacked is out-of-date software. A vulnerability is found in a plugin, a patch is released, and weeks later half the sites using that plugin still haven’t updated. Bots scan the web looking for unpatched versions and exploit them automatically.

What to do:

  • Turn on automatic updates for WordPress core, themes and plugins
  • Check your site at least monthly for any updates that didn’t apply automatically
  • Remove any plugin or theme you’re not actively using (deactivated isn’t enough: delete it)
  • Avoid plugins that haven’t been updated in over a year

If automatic updates make you nervous because something might break, the answer is staging. A good host gives you a one-click staging environment where updates can be tested before they go live.

Get your passwords and accounts in order

The second most common cause of compromise is weak or reused passwords. The fix is simple but most businesses skip it.

Use a password manager

1Password, Bitwarden, Dashlane, whichever you prefer. Generate strong, unique passwords for every account. This applies to WordPress, your hosting, your domain registrar, your email and your payment provider.

Turn on two-factor authentication

For WordPress, plugins like Wordfence, Solid Security or Two Factor Authentication add 2FA for admin logins. Turn it on for every administrator account. The extra five seconds at login time is worth it.

Audit your user accounts

Most sites accumulate old accounts from former staff, freelancers and agencies. Delete anything you don’t need. Demote anything that doesn’t need admin access. The fewer admin accounts, the smaller the attack surface.

Don’t use “admin” as a username

It’s the first thing every brute-force attack tries. If you do, create a new admin account with a different username and delete the original.

If your WordPress login uses a memorable password, no 2FA, and a username of “admin”, you’re not running a website. You’re running an open audition for hackers.

Choose plugins (and themes) carefully

Every plugin is code running on your site. The more plugins you have, the bigger your attack surface. A few simple rules:

  • Only install plugins you actually need
  • Prefer plugins from well-known developers with frequent updates and a large active install base
  • Avoid “nulled” or pirated premium plugins, these are a common source of malware
  • Check the changelog before installing, a plugin that hasn’t been updated in 18 months is a red flag
  • Audit your plugin list every six months and uninstall anything you don’t use

This is one of the biggest reasons we recommend simple, well-maintained themes for most clients. We touched on theme choice in our piece on effective web design.

Pick decent hosting

Cheap shared hosting is one of the biggest hidden risks. If your hosting provider doesn’t isolate accounts properly, a breach in one site on the same server can spread. If they don’t keep server software up to date, vulnerabilities sit unpatched. If they don’t offer real backups, recovering from an attack becomes a nightmare.

A good host gives you:

  • Automatic daily backups stored off-server
  • Free SSL certificates (Let’s Encrypt or equivalent)
  • A staging environment
  • Account-level isolation
  • Server-level firewall and malware scanning
  • Easy WordPress core updates

We talk about why this matters in our post on why website speed matters.

Add a security plugin (one is enough)

You don’t need three competing security plugins fighting each other. Pick one well-maintained one and configure it properly. Reasonable choices include Wordfence, Solid Security and All In One WP Security.

Whichever you choose, the settings that matter most are:

  • Login attempt limiting
  • Two-factor authentication
  • File integrity monitoring
  • Malware scanning on a schedule
  • A firewall (web application firewall, or WAF)

Backups: the thing you only think about when it’s too late

If your site does get hacked, the difference between a 30-minute restore and a week of disaster is whether you have working, recent, off-site backups.

What “good” looks like:

  • Automatic daily backups
  • Stored somewhere other than your hosting account (cloud storage, another provider, or a backup service like UpdraftPlus)
  • Tested at least once a year: an untested backup is just a hope

HTTPS, SSL and the basics that everyone notices

Every page of your site should be served over HTTPS. Browsers warn visitors about non-secure sites, and Google quietly ranks them lower. Most hosts offer free SSL via Let’s Encrypt; if yours doesn’t, change host. We covered SSL briefly in our post on how to conduct a website audit.

What to do if you do get hacked

Don’t panic. Don’t delete things at random. The right order:

  1. Take a snapshot of the current state for evidence
  2. Restore from a known good backup if you have one
  3. Update WordPress core, all plugins and themes immediately
  4. Change every password (admin, hosting, FTP, database, email)
  5. Run a full malware scan
  6. Identify how the attacker got in and close that hole
  7. If it’s serious or you can’t find the entry point, get professional help

A simple monthly checklist

  • Run all available updates
  • Check your security plugin’s scan log
  • Verify your latest backup actually exists and isn’t empty
  • Skim the user accounts list for anything unexpected
  • Take a quick look at Google Search Console for any security warnings

That’s about ten minutes of work, once a month. It’s the difference between a site that quietly hums along and a site that becomes a lesson in disaster recovery. If you’d rather hand this off entirely, our managed WordPress care plans cover all of it. Get in touch.

Let's talk

Thinking about your own website or SEO?

We help small businesses across West Sussex build websites that bring in enquiries and get found online. Tell us what you are working on and we will give you an honest steer.

Get in touch
Luke Hopkins - Director of Notus Digital

WRITTEN BY

Luke Hopkins

SHARE ON

PREV

SEO for interior designers: a practical playbook

NEXT

Schema markup explained: what it is and why your site needs it

Not Us Digital light logo
01243 217 878
Start Project

Helping you

  • SEO & AI Content Checklist
  • Jargon Buster
  • Blog
  • Contact
  • FAQs

Our expertise

  • Web Design
  • WordPress
  • Search Engine Optimisation (SEO)
  • Conversion Rate Optimisation (CRO)
  • About

Areas we serve

  • Chichester
  • Worthing
  • Littlehampton
  • Arundel
  • Brighton
  • Portsmouth
  • Bognor Regis

Follow us

  • Facebook
  • LinkedIn
  • hello@notusdigital.co.uk
  • 01243 217 878
  • Bognor Regis
    West Sussex
    PO21
  • © 2026 Notus Digital
  • Privacy Policy

Notus Digital is a trading name of Notus Digital Ltd. Registered in England and Wales, company number 15465042. Registered office: c/o Accrue Accounting, Unit E4 Arena Business Centre, Holyrood Close, Poole, BH17 7FP.

Newsletter signup

"*" indicates required fields

Name*
Email*
Privacy*