A hacked website rarely announces itself with a dramatic error screen. More often, a customer reports a strange redirect, a search result shows a warning, or an order confirmation email stops arriving. This website security checklist helps business owners, developers, and agencies prevent those expensive surprises by focusing on the controls that matter most.
Security is not one setting or one product. It is a routine that protects your site, customer data, email reputation, search visibility, and ability to keep operating after a problem. The right priorities depend on your platform and hosting environment, but every business website needs a reliable baseline.
Website Security Checklist: Start With Access
Most website compromises begin with stolen, guessed, or reused credentials. That makes account access the first place to tighten security, even before evaluating plugins or server settings.
Use a unique, long password for every critical account: your hosting control panel, domain registrar, CMS administrator account, database, business email, FTP or SFTP accounts, and payment tools. A password manager is the practical way to do this without relying on memory or shared spreadsheets.
Enable multi-factor authentication wherever it is available. A password alone can be exposed through phishing, malware, or an old third-party breach. Multi-factor authentication adds a meaningful barrier, especially for hosting, domain, and administrator accounts.
Access should also match each person’s actual role. Give writers editor-level permissions, developers the access they need for development, and only a small number of trusted people full administrator access. Remove accounts immediately when an employee, contractor, or client relationship ends. For agencies, this is especially important across client sites where old accounts can be overlooked.
Keep the Website and Server Software Current
Outdated software is one of the clearest, most avoidable risks. Attackers regularly scan the internet for known weaknesses in content management systems, themes, plugins, extensions, and server software. They do not need to target your business personally if an automated scan can find an unpatched installation.
Apply core CMS updates promptly, particularly security releases. Keep themes and plugins current as well, but do not treat every update identically. A simple brochure site may safely use automatic minor updates, while a complex eCommerce site or custom application may need testing before changes go live. The trade-off is clear: delaying updates can increase exposure, while untested updates can disrupt checkout flows, custom code, or integrations.
Remove software you no longer use. Deactivated plugins, unused themes, abandoned test applications, and old installation folders create unnecessary attack surface. If a plugin has been abandoned by its developer or has no clear update history, replace it with a maintained alternative.
For VPS and dedicated server users, operating system packages, web server software, PHP versions, database software, and installed services need a patching plan too. Managed hosting can reduce the administrative workload, but site owners still remain responsible for the applications, users, and content running on the account.
Protect Data With Tested Backups
A backup is only useful if it can be restored quickly and completely. Your backup plan should include website files, databases, configuration files, and any media or customer data stored locally. For WordPress and other database-driven sites, backing up files without the database can leave you with an incomplete site.
Schedule backups based on how often your site changes. A static site might need weekly backups, while an online store with new orders, inventory updates, and customer accounts may require daily or more frequent backups. Keep multiple restore points so a backup made after an infection does not become your only option.
Store backups separately from the primary hosting account when possible. If an account is compromised, deleted, or affected by a server-level issue, independent backup copies add resilience. Services such as CodeGuard can automate backup scheduling and make recovery less stressful, but automation should still be checked.
Test a restoration before an emergency forces the issue. Restore a recent backup in a staging environment or temporary location and verify that pages load, forms work, images display, and database content is current. Recovery time is part of security planning, not an afterthought.
Encrypt Every Connection With HTTPS
An SSL certificate protects data traveling between a visitor’s browser and your website. HTTPS is essential for login pages, forms, eCommerce checkouts, customer portals, and any site that collects information. It also supports visitor trust and helps prevent browsers from flagging the site as insecure.
Install a valid SSL certificate, redirect all HTTP traffic to HTTPS, and update internal links and asset references to avoid mixed-content warnings. Check that the certificate renews automatically or has a documented renewal process. An expired certificate can block visitors from reaching the site even when the server itself is functioning normally.
Encryption should extend beyond the public website. Use secure methods such as SFTP or SSH rather than unencrypted FTP. Secure business email settings and protected administrative connections matter just as much, since attackers often use email accounts to reset website passwords or impersonate staff.
Scan for Malware and Monitor for Changes
Malware can inject spam links, steal form submissions, redirect mobile visitors, create hidden administrator accounts, or use your server to distribute malicious activity. Some infections are obvious. Others remain hidden long enough to damage search rankings, customer trust, and email deliverability.
Use scheduled malware scanning and file-change monitoring to identify suspicious code before it becomes a larger incident. A website security service such as SiteLock can be useful for businesses that need ongoing scanning and cleanup support, particularly if they do not have an in-house security team.
Monitoring should include more than malware alerts. Review administrator logins, failed login attempts, new user accounts, server resource spikes, and unexpected changes to DNS records. Sudden outbound email activity can indicate a compromised mailbox or website script. A site that becomes unusually slow may be experiencing a traffic attack, poorly optimized code, or unauthorized server activity. The alert is the starting point, not the diagnosis.
Secure Your Domain, DNS, and Email
Your domain is a critical business asset. If someone gains control of it, they can redirect traffic, intercept email, or prevent your website from resolving. Use a unique password and multi-factor authentication for the domain account, keep recovery details current, and limit who can change DNS records.
Enable domain transfer protection when available. Keep an eye on renewal dates, too. An expired domain can interrupt website and email service at exactly the wrong time.
Business email deserves the same attention as the website. Use strong passwords and multi-factor authentication, remove former users, and apply spam filtering. Configure email authentication records such as SPF, DKIM, and DMARC correctly. These records help receiving mail systems verify messages sent from your domain and reduce the risk of spoofing.
Reduce Risk From Forms, Payments, and Third Parties
Every form is a possible path for spam, fraudulent submissions, and malicious input. Use spam protection on contact forms, limit the data you collect, and make sure form plugins are maintained. Do not ask for sensitive information through a standard contact form when a secure portal or dedicated payment process is more appropriate.
For eCommerce, use a reputable payment gateway and avoid storing card data on your own server unless your business has the compliance controls and technical expertise to do so. Outsourcing payment processing reduces your direct exposure, but it does not remove the need to secure customer accounts, order data, and administrator access.
Review third-party scripts, analytics tags, chat tools, and plugins periodically. Each outside service can affect performance, privacy, and security. Keep only the tools that provide real business value, and verify that they come from known vendors with active support.
Prepare for an Incident Before One Happens
Even well-managed websites can face vulnerabilities, phishing attempts, or compromised credentials. A short incident plan helps your team act quickly instead of making high-pressure decisions without a process.
Document who can contact your hosting provider, domain registrar, developer, payment processor, and email administrator. Keep support contacts outside the website itself. Define who can take the site into maintenance mode, rotate credentials, restore a backup, and communicate with customers if personal data or service availability is affected.
When an incident occurs, preserve evidence before making broad changes. Note the time, visible symptoms, recent updates, suspicious accounts, and alerts. Then isolate the issue, change credentials from a clean device, scan the environment, and restore only from a known-good backup if restoration is required. Charter Hosting support can help customers assess hosting-level concerns, but a fast response is always easier when account ownership and recovery details are current.
Security improves through consistent maintenance, not a one-time cleanup. Put recurring reminders on the calendar for updates, account reviews, backup checks, and scan reports. A site that is fast and available earns attention; a site that is also prepared to withstand a problem earns lasting trust.


