1. Leaving updates without an owner
Assign someone to review and apply updates. Test important functionality and keep a record of changes rather than assuming every installed component maintains itself.
2. Keeping unused extensions
Review plugins and themes that are no longer needed. Remove unused components after checking dependencies and retaining a recovery option.
3. Reusing passwords
Use unique credentials and appropriate additional authentication. A password shared with another service exposes the website to that service being compromised.
4. Sharing administrator accounts
Give each contributor an individual account with the access required for their work. Remove access when it is no longer needed.
5. Never testing recovery
Backups are useful only when they can restore the files and database you need. Practise recovery away from the live site and document the steps.
6. Using untrusted downloads
Get WordPress and extensions from trustworthy official sources. A free copy of commercial software from an unknown distributor is not a safe shortcut.
7. Ignoring the hosting account
Protect hosting, domain, and email accounts as carefully as the application. Losing any of them can interfere with site access or recovery.
8. Leaving secrets in public files
Keep credentials and backups out of publicly accessible directories and source repositories. Review what can be downloaded without signing in.
9. Treating warnings as background noise
Have an owner for unusual login activity, unexplained file changes, and unexpected redirects. Preserve relevant logs when investigating a problem.
10. Having no incident plan
Document who can restrict access, contact hosting support, restore a clean backup, and verify the site. A written response process helps avoid improvisation under pressure.
Further reading
Key takeaways
- 1. Leaving updates without an owner
- 2. Keeping unused extensions
- 3. Reusing passwords
- 4. Sharing administrator accounts