Is my WordPress site secure? A simple yes or no checklist

Sometimes I log into a website + immediately wonder if it’s been hacked. Here’s the thing, most WordPress sites aren’t actually hacked… they’re just messy. It’s no wonder so many online business owners ask “is my WordPress site secure” when we have our initial chat.

And this isn’t a judgement. If you watch any videos of our foster dogs playing, you’ll notice the toys everywhere + dog hair tumbleweeds that roll by 6.5 days of the week.

Instead, I want to show you exactly what to look for to see if your site is secure or not. Regardless of how many alerts, warnings, or other banners you see on the backend.

Think of this like those Seventeen magazine quizzes, only you just need to reply with yes or no. And we aren’t thinking about a specific crush the entire time hoping the results are that we are meant to be together.

WordPress Security Self-Assessment Checklist

These 10 questions will help you answer the question is my WordPress site secure. Respond with a yes or no + track how many of each you respond with.

  1. Does your site have a valid wildcard SSL?
    Your SSL should protect both the www + non-www versions of your site, at a minimum. And if it doesn’t autorenew, you need to know when it is set to expire.
  2. Are your backups running automatically?
    Don’t waste your time running manual backups. A full site backup is not a trend, it’s a staple.
  3. Do you have fewer than 5 updates waiting?
    You do not need to run updates every day, in fact, I’d say it’s not the vibe. But letting them pile up is riskier than you think.
  4. Do you have fewer than 15 plugins installed?
    Know the answer + the reason why. There are sites that need a few dozen plugins, but a lot of sites don’t.
  5. Is your WordPress password recent + unique?
    It should be less than a year old + not reused from another account. Or written on a sticky note.
  6. Do you know exactly who has admin access to your site + is the list short?
    All WordPress sites should have at least 2 administrator accounts so that you have a backup; you likely don’t need many more.
  7. Have your other admins changed their passwords this year?
    Changing your password is great until you realize someone with admin access is using 123456 as their login to your entire business.
  8. Is your login URL customized + hidden from bots?
    Your login screen is the door to the contents of your site. Please close it.
  9. Is your site protected from Brute Force Attacks?
    Brute Force protection is the same as locking that proverbial door from item 8. These attacks put your site at risk of being hacked + slow things way down.
  10. Is your site free of default content + settings?
    Uncategorized, Sample Page, admin… none of these things belong in your business.

Your results

Your site sounds secure AF + that is great news for your business, your brand + the folks that land on your site. That doesn’t mean you’re “done” with security. It means you should keep doing the things that you’re doing!

To be honest, you’re probably ahead of most business owners with this score. But in this case, normal isn’t good enough. Try to fill the gaps in your security over the next quarter.

Are you an adrenaline seeker? Because your site is living dangerously! Some of these things are smaller tasks that will make a big impact in protecting your business + your bank account from a bad situation.

Bonus Question: How many of those did you want to skip or ignore? If the answer is 4 or more, consider getting a go-to developer to help you.

You don’t need to host your site with me to benefit. A single 5-hour retainer ($635) can not only get your site locked down like Fort Knox, it usually covers a couple months of maintenance too.

For the DIY queens, grab your free WordPress security guide here + stop asking is my WordPress site secure.