A practical website security checklist
Use this list with the person responsible for your website. Mark each item checked, needs work or unknown, and record who owns the next action. An unknown answer is useful: it identifies what needs verification.
Access and accounts
- Each administrator has an individual account and an appropriate role.
- Strong authentication protects the website, hosting panel and domain registrar.
- Passwords are unique and stored in an approved password manager.
- Former staff and contractors no longer have unnecessary access.
- Recovery details and an emergency contact are available securely.
Check service accounts and integrations as well as people. An old API key can remain usable after a person's ordinary account is removed.
Updates and software
- WordPress, plugins and themes have a named maintenance owner.
- The normal update schedule and urgent security process are documented.
- Unsupported or unnecessary components have been reviewed.
- Updates are backed up and tested appropriately before release.
- Forms, login and any checkout process are checked afterwards.
Our WordPress update guide explains the sequence. A plugin advisory needs checking against the actual installed version and exposure.
HTTPS and browser protection
- The public hostname loads over HTTPS without certificate errors.
- Important assets and form destinations use protected connections.
- Certificate renewal is automated where suitable and monitored for failure.
- Security headers are reviewed for this application, with changes tested.
- The site does not expose private administration merely because a URL is unlisted.
A missing header is a prompt for assessment, not proof of a breach. Read the TLS and WordPress guide before applying a copied configuration.
Backups and recovery
- Backups cover the database and the files the site needs.
- Copy frequency, retention and storage locations are known.
- A restoration has been tested in a safe environment.
- Someone can initiate recovery if the usual contact is unavailable.
- The potential loss of recent orders or enquiries is understood.
Review the scope of ResaHost backups against your own systems. A website backup does not automatically include external email or business applications.
People and response
- Staff have a clear route for reporting suspicious activity.
- Important provider contacts are available outside the affected system.
- Someone can authorise urgent containment and recovery work.
- Evidence and incident decisions are recorded.
- Personal-data implications are assessed when relevant.
If the website may be compromised, contact the responsible technical team promptly. Preserve useful evidence, assess containment and restore from a verified clean position. Remove the cause before reopening the same exposure. Avoid claiming the site is fixed merely because its homepage looks normal.
ResaHost website security provides the technical service context. For accounts, cloud tools and staff routines beyond the website, use the small-business cybersecurity guide.
Review this checklist after significant releases, staff changes and incidents, as well as on a regular schedule. Keep the evidence of what was checked so the next review starts from facts.