Website Security Checklist for Consultants and Small Businesses: 12 Steps That Keep You Safe

Padlock on a keyboard illustrating a website security checklist

A website security checklist sounds like something only banks and hospitals need, until the morning a client emails you to ask why your site is redirecting them to a pharmacy in another country. I have had that call from consultants more than once, and every time the site looked fine the night before.

Disclosure: Some links in this article are referral links. If you sign up through them, Design Fly 24 may earn a small commission at no extra cost to you. We only recommend hosting we use for our own clients.

Here is the thing most small business owners do not realize. Your site was probably not targeted by a person who cares about you. It was found by a bot that scans thousands of sites a day looking for an old plugin, a weak password or a forgotten admin account. Small consultant sites without a website security checklist are easy picks, because they are set up once and then left alone.

So this is the practical website security checklist we use at Design Fly 24 when we build or take over a site. It covers WordPress in detail, because that is where most of our clients live, but almost every step applies to Squarespace, Wix, Webflow and Shopify too. None of it requires you to be technical.

Key takeaways

  • Most attacks on small sites are automated, so the basics (strong logins, updates, backups) stop the majority of them.
  • Two factor authentication on every admin account is the highest value item on any website security checklist.
  • Backups only count if they are stored off site and you have tested a restore at least once.
  • Your hosting choice decides how much of the website security checklist is handled for you.
  • Have a written plan for what to do if you get hacked before you ever need it.

Why a website security checklist matters for consultants

For a consultant, your website is a trust document. A school district buyer, a law firm vetting an expert witness, an HR director comparing three trainers: they all look at your site before they call. If it throws a browser warning or shows spam links, you lose the deal and never hear about it.

There is a second problem. If you sell security, risk or compliance advice, a hacked website is more than embarrassing. It quietly tells prospects you do not follow your own advice. Our clients who need a strong security consultant website feel this pressure more than anyone, and a website security checklist is part of every one of those builds.

A website security checklist turns vague worry into a short list of habits. You do them once, set reminders for the rest, and stop wondering whether your site is quietly broken.

1. Lock down logins with strong passwords and two factor authentication

The login page is the front door, and bots knock on it all day. On WordPress, the default login lives at a predictable address, so automated tools keep guessing until one works. That is why logins open our website security checklist.

Start here:

  • Use a password manager and give every account a long, random password that is not used anywhere else.
  • Turn on two factor authentication (an app code or a security key) for every admin and editor account. On WordPress, a reputable security plugin or your host can add this.
  • Never use “admin” as a username. If yours is still “admin”, create a new administrator, log in with it, and delete the old one.
  • Limit login attempts so a bot gets locked out after a few failures.

If you only do one item on this website security checklist this week, make it two factor authentication. A stolen or guessed password becomes almost useless when the attacker also needs the code on your phone.

The same applies to your hosting account, your domain registrar and the email account those services send reset links to. Whoever controls that inbox can reset everything else.

2. Give every user the right role, and remove the ones who left

Most consultant sites collect users over time: a designer from three years ago, a virtual assistant who posted blogs for six months, an agency that set up tracking and moved on. Every one of those accounts is a door that still opens.

WordPress has clear user roles: Administrator, Editor, Author, Contributor and Subscriber. Squarespace, Wix and Webflow have their own versions of contributor permissions. The rule is simple: give each person the lowest role that lets them do their job.

  • Only you (and your developer, if you have one) should be an Administrator.
  • Someone who writes and publishes posts needs Editor or Author, not Administrator.
  • Delete accounts for anyone who no longer works with you. Reassign their content to yourself first.
  • Add a quarterly user review to your website security checklist. It takes two minutes.

This part of the website security checklist is boring, and that is exactly why it gets skipped.

Padlock on a keyboard illustrating a website security checklist
A website security checklist works best as a habit you repeat, not a one time project.

3. Keep core, plugins and themes updated

Outdated software is how most WordPress sites get broken into. When a plugin developer fixes a security hole, they publish the fix in an update. That same update tells attackers exactly what the hole was, and bots start scanning for sites that have not updated yet.

So updates are not optional maintenance. They are the core of any website security checklist. Here is how we handle them:

  • Apply minor WordPress core updates automatically. Review major ones first.
  • Update plugins and themes at least weekly, ideally on a staging copy first if the site is complex.
  • Delete plugins and themes you are not using.
  • Avoid plugins that have not been updated in a year or more, and never install “nulled” (pirated) premium plugins. They often ship with malware already inside.

The official Hardening WordPress guide on WordPress.org covers this and more and is worth bookmarking. If you want a full routine around updates, our WordPress maintenance checklist breaks it into weekly, monthly and quarterly tasks.

4. Store backups off site, and test a restore

A backup is your undo button. When everything else on a website security checklist fails, a clean backup is what gets you back online in an hour instead of a week.

But a backup is only useful if three things are true:

  1. It is stored off site. If your backups live on the same server as your site, a hacked or failed server takes them out too. Send copies to cloud storage such as Google Drive or Amazon S3.
  2. It runs on a schedule. Daily for sites that change often (blogs, events, bookings), weekly is the bare minimum for a brochure site.
  3. You have restored from it at least once. I have seen backups that ran for two years and turned out to be empty.

Keep several versions. Malware sometimes sits quietly for weeks, so a good website security checklist says you keep at least a month of backups.

5. Put a firewall in front of your site

A web application firewall (WAF) filters traffic before it reaches your site. It blocks known attack patterns, bad bots and repeated login attempts, so many threats never touch WordPress at all.

You have three common options:

  • Hosting level firewall. Many good hosts include one. It is the easiest option because you do not have to configure anything.
  • DNS level firewall. Services like Cloudflare sit between visitors and your server. They also help with speed.
  • Plugin firewall. Security plugins add a firewall inside WordPress. Useful, but it runs on your own server, so it uses your resources.

For most consultant sites, a hosting or DNS firewall plus a lightweight security plugin for login protection and scanning is plenty. Do not stack three security plugins on top of each other. They conflict and slow the site down.

Small business owner checking website backups and updates on a laptop
Firewalls and off site backups quietly do most of the heavy lifting.

6. Use SSL everywhere, and check it keeps renewing

SSL is the padlock in the browser bar and the “https” in your address. It encrypts the connection between your visitor and your site, which matters any time someone fills in a form or logs in. Browsers flag sites without it as “Not secure”, a terrible first impression.

Most hosts now offer free SSL certificates that renew automatically. Your job is to confirm three things:

  • Every page loads on https, and the http version redirects to it.
  • There are no “mixed content” warnings from images or scripts still loading over http.
  • The certificate is set to renew automatically, and someone gets an alert if it fails.

SSL does not make a site secure on its own. It protects data in transit, not the site itself. It is still a basic line on every website security checklist we write, because the alternative is a warning screen.

7. Protect your forms and stop spam

Contact forms are where your leads come in, and they are a favorite target. Spam bots flood them with junk, and badly built forms can be abused to send email through your server. Forms belong on your website security checklist for that reason.

  • Add spam protection: a honeypot field, a tool like Cloudflare Turnstile, or Google reCAPTCHA.
  • Do not allow file uploads on a public form unless you truly need them, and if you do, restrict the file types.
  • Send form notifications through a proper SMTP service so they land in your inbox, not in spam.
  • Test every form once a month by filling it in yourself.

Would you rather not do all of this yourself?Our WordPress care plans cover updates, off site backups, monitoring and cleanup if something goes wrong.

See maintenance plans

8. Choose hosting that does part of the website security checklist for you

Cheap hosting is often where security problems start: old server software, poor isolation between accounts, no firewall and support that says malware is “your responsibility”. Good hosting quietly handles a big part of this website security checklist on your behalf.

When you compare hosts, use this short website security checklist for hosting:

  • Free SSL with automatic renewal.
  • A web application firewall and malware scanning included.
  • Automatic daily backups you can restore yourself.
  • Current PHP versions and the ability to switch easily.

For most of our small business clients we use Hostinger. It runs on LiteSpeed servers, includes free SSL and a web application firewall, and has daily backups on Business plans and up. It is not the only good choice, and we cover the others in our guide to the best WordPress hosting and our wider look at web hosting for small business.

9. Monitor uptime, file changes and logins

You cannot fix what you do not know about. Monitoring is the part of a website security checklist that turns a hack that sits unnoticed for a month into one you catch the same day.

  • Uptime monitoring. A free or low effort service checks your site every few minutes and emails you if it goes down.
  • Malware and file change scanning. Your security plugin or host should alert you when core files change unexpectedly.
  • Login alerts. Get notified when an administrator logs in, especially from a new location.
  • Google Search Console. Google will warn you there if it detects malware or hacked content on your site. Make sure you are verified and the alerts go to an inbox you read.

10. A website security checklist for Squarespace, Wix, Webflow and Shopify

If your site runs on a hosted platform, the platform handles server security, SSL and most software updates for you. That is a real advantage. But your website security checklist does not disappear, it just gets shorter.

  • Two factor authentication on your platform account is still the top priority. Your account is now the only door.
  • Review contributors and collaborators, and remove anyone who left.
  • Be careful with third party apps, embeds and code snippets. Each one runs on your site with your trust.
  • Export your content regularly where the platform allows it, so you are not starting from zero if an account gets locked.
  • Protect your domain registrar account separately, with its own strong password and 2FA.

We work on all of these platforms, and the conversation is the same every time: the platform protects the building, you protect the keys.

Your website security checklist at a glance

Here is the whole website security checklist in one place. Print it or hand it to whoever manages your site.

TaskHow oftenWho usually does it
Two factor authentication on all admin, hosting, domain and email accountsOnce, then check quarterlyYou
Review user accounts and rolesQuarterlyYou or your developer
Update core, plugins and themesWeeklyDeveloper or care plan
Confirm off site backups ranWeeklyDeveloper or host
Test a full restoreTwice a yearDeveloper
Firewall and malware scanning activeOngoing, check monthlyHost or security plugin
SSL valid and renewingMonthlyHost
Test contact formsMonthlyYou
Uptime and Search Console alerts workingMonthlyYou or developer

If a row on this website security checklist has nobody’s name next to it, that is the one most likely to fail.

Security is not a product you buy once. It is a handful of small habits that someone actually owns.

11. What to do if your site gets hacked

Even a careful website security checklist reduces risk, it does not remove it. If you see strange redirects, spam pages in Google or unknown admin users, do not start deleting things at random. Work through it in order:

  1. Take a snapshot. Back up the hacked site as it is. You may need it to work out what happened.
  2. Change every password. WordPress admins, hosting, FTP or SFTP, database, domain registrar and the email account tied to them. Turn on 2FA if it was off.
  3. Contact your host. Good hosts will help you find infected files.
  4. Restore a clean backup or clean the site. If you have a backup from before the infection, restore it and then update everything right away. If not, a professional cleanup is safer than guessing.
  5. Find the way in. An outdated plugin, a leaked password, a pirated theme. If you do not close the hole, it happens again next week.
  6. Check Google. In Search Console, look for security issues and request a review once the site is clean.
  7. Tell people if needed. If form submissions or customer data may have been exposed, get proper advice on your obligations.

For broader guidance on incidents and small business cyber hygiene, the Cybersecurity and Infrastructure Security Agency (CISA) publishes free, plain language resources.

12. Write it down and give it an owner

The last step is the one that makes the other eleven stick. Put your website security checklist in a shared document with three columns: the task, how often it happens, and whose job it is. Store your logins in a password manager a trusted person can access if you are away.

Then put a recurring reminder on your calendar. Fifteen minutes on the first Monday of each month covers almost everything that is yours to do. If your website security checklist feels like too much, hand the technical rows to a developer and keep the rest yourself.

Quick tip: Save a one page “if we get hacked” note with your host’s support link, your developer’s contact and where the backups live.

Frequently asked questions

What should a basic website security checklist include?

At minimum: strong unique passwords, two factor authentication, the right user roles, regular updates, off site backups you have tested, a firewall, valid SSL, protected forms, uptime monitoring and a plan for what to do if you get hacked. That website security checklist covers most of the risk for a small business site.

How often should I go through my website security checklist?

Updates and backup checks should happen weekly. Forms, SSL and monitoring are monthly. User reviews and restore tests can be quarterly or twice a year. A short monthly review keeps the whole website security checklist from drifting.

Is WordPress less secure than Squarespace or Wix?

Not by itself. WordPress gives you more control, which means more responsibility for updates and plugins. A well maintained WordPress site that follows a website security checklist is very secure. A neglected one is an easy target.

Do I need a security plugin if my host has a firewall?

Usually one lightweight security plugin is still worth it for login protection, 2FA and file change alerts. Avoid running several at once, since they conflict.

Can Design Fly 24 handle my website security checklist for me?

Yes. Our maintenance plans cover updates, off site backups, monitoring and cleanup, for WordPress and other platforms. Scope depends on your site, so the easiest next step is a short call.

Keep your site safe and get back to client work

You do not need to become a security expert to protect your website. You need the basics done well, done regularly and owned by someone. Work through this website security checklist once, set your reminders, and you will be ahead of most small business sites.

If you would rather hand it off, that is what we do every day for consultants, speakers and small firms across the US. Take a look at our work, read more about Design Fly 24, or book a free call and we will look at your site together and tell you honestly where it stands.

Imtiaz Ahmed
Written by

Imtiaz Ahmed

Imtiaz is the founder of Design Fly 24, a New York web design agency. He has designed and launched 30+ websites for security consultants, expert witnesses, speakers, coaches and professional firms, and helps them turn their sites into steady lead sources through SEO and strong personal branding.

About ImtiazLinkedIn

Keep reading

All articles →

Ready for a website that works as hard as you do?

Design Fly 24 builds fast, search ready websites for consultants and experts across the US. No templates, no fluff. Just a site that earns trust and books calls.