Small business websites are hacked often, usually by automated bots looking for outdated software and weak passwords. A few basic habits prevent most problems.
1. HTTPS everywhere
An SSL certificate encrypts data and shows the padlock in browsers. Most hosts provide free certificates. Redirect all HTTP pages to HTTPS; our redirect generator helps.
2. Keep everything updated
- WordPress core, themes and plugins.
- Remove plugins and themes you do not use.
- Use plugins from trusted developers only, never “nulled” pirated ones.
3. Strong logins
- Unique, long passwords for hosting, domain, CMS and email.
- Two-factor authentication wherever possible.
- Separate logins for each person, removed when they leave.
4. Regular backups
- Automatic daily or weekly backups.
- Stored outside your hosting account.
- Test restoring a backup occasionally.
5. Security monitoring
Use a security plugin or your host’s scanning, and watch for Search Console security alerts.
6. Own your accounts
Your domain and hosting should be registered in your business’s name and email, not only a developer’s.
If your site is hacked
- Change all passwords.
- Restore from a clean backup or have it cleaned professionally.
- Update everything.
- Request a review in Search Console if Google flagged it.
See our website maintenance service.
Want the full picture? This article is part of Business websites: the complete guide, our in-depth guide with everything in one place.




