Free Resource

10-Step Website Security Checklist

A practical checklist for every small business owner. Knock it out in one weekend — and walk away safe from 90% of common attacks.

1

HTTPS / SSL is enabled

Look for the lock icon in the URL bar. Let's Encrypt provides SSL for free.

2

Admin password is strong (16+ characters)

Use a password manager. 'admin123' — never.

3

2FA is ON for admin login

Two minutes to set up with Google Authenticator or a WordPress plugin.

4

WordPress / CMS is on the latest version

Enable auto-updates. Outdated versions are the #1 entry point for attackers.

5

Unused plugins / apps are deleted

Don't just deactivate — delete. The code stays on your site otherwise.

6

Daily automated backups are set up

Use UpdraftPlus (WP) or your host's backup. Store off-site (Drive / Dropbox).

7

Login attempts are rate-limited

Block brute-force bots after 3–5 failed attempts.

8

Cloudflare or a WAF is in front

Cloudflare's free plan gives baseline DDoS and bot protection.

9

Security headers are set

HSTS, X-Frame-Options, Content-Security-Policy at minimum.

10

A monthly security scan is scheduled

Start with a free scan — at least once a month.

Rather not do it yourself?

Our free scan tells you exactly which of these 10 steps are incomplete on your site — and which one to fix first.

Run a Free Scan

FAQs

Any small business website owner — WordPress, Shopify, or a custom site. The steps are universal.

Free · 2 minutes · No signup

Not sure if your website is safe?

Run a free 2-minute check — no credit card needed. We tell you what's broken and exactly how to fix it.

Scan My Site Free
W