Most hacked websites could have been protected with a few simple habits. Use this checklist to keep your site and your account safe.
Passwords and logins
- ☐ Use a different, strong password for cPanel, email, FTP and your website's admin area. A password manager makes this easy.
- ☐ Turn on two-factor authentication in cPanel. See How to turn on two-factor authentication in cPanel.
- ☐ Don't use
adminas your WordPress username. - ☐ Remove FTP accounts and admin users you no longer need, such as a former web designer.
Updates
- ☐ Keep WordPress, themes and plugins up to date. Turn on automatic minor updates in WordPress Manager. See How to manage WordPress with WordPress Manager.
- ☐ Delete plugins and themes you don't use. Even deactivated ones can be a risk.
- ☐ Use a current PHP version, 8.2 or newer. See How to change your PHP version.
- ☐ Only install plugins and themes from trusted sources. Never use "nulled" (pirated) premium plugins.
Your website
- ☐ Make sure your site uses HTTPS. See How to force HTTPS on your website.
- ☐ Keep file permissions at
644for files and755for folders and never use 777. See File and folder permissions explained. - ☐ Remove old test installations and copies of your site, such as
/oldor/test.
Backups
- ☐ Your account is backed up automatically twice a week and you can restore it yourself. See About your backups.
- ☐ Before big changes, such as a redesign or a major update, download your own backup. See How to download a backup of your account.
- ☐ Set up SPF, DKIM and DMARC so nobody can easily fake your address. See How to set up SPF, DKIM and DMARC for your domain.
- ☐ Be careful with emails asking you to "verify your account" or "reset your password". We will never ask you for your password.
Think something is wrong with your site? See How to check your website for malware or contact us via How to contact support.