WordPress security for small business, in plain English
Everything you need to understand, test, and harden a WordPress site, without the jargon or the fear-selling. Start with a free scan, then work through the guides below.
Why WordPress security matters for a small business
WordPress runs a huge share of the web, which makes it a constant target for automated attacks. Most break-ins are not personal: bots crawl the internet looking for sites running software with known weaknesses. Small businesses are squarely in the firing line. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR).
The good news: most of that risk comes from a short list of fixable things, and you do not need to be an expert to stay ahead of it.
The inside-and-outside model
A WordPress site has two security surfaces. The outside is what anyone on the internet can see: your DNS, email spoofability, TLS certificate, HTTP headers, and any files you have left exposed. The inside is what is actually installed and configured: your exact plugin, theme, and core versions, your admin accounts, and your settings. Most real risk lives on the inside, where plugins account for roughly 96% of WordPress vulnerabilities (Patchstack). A complete picture needs both, which is exactly what BadgerScan combines into one grade.
The guides
- Your Business Was Just Hacked. Here Is What to Do in the First Hour.The instinct is to fix it fast: reboot the computer, delete the bad email, change every password. Almost all of that makes things worse. The first hour is about stopping the spread and preserving what you will need, not cleaning up. Here is the order that actually helps.
- “Auto-Updates: On” Is Not the Same as PatchedA business called us: their WordPress admin password had been changed, and they hadn’t done it. What we found was a two-week-old compromise, traced to a single security update that a hosting setting had quietly blocked from ever installing. This is what we found, and how it happened.
- SPF Exceeds the 10 DNS-Lookup Limit: What It Means and How to Fix ItThis is one of those findings that sounds obscure and is actually serious. Your SPF record still looks fine in your DNS, but the moment it needs an eleventh DNS lookup, receiving mail servers throw the whole thing out. Your anti-spoofing protection is off, and you would never know from looking at the record.
- Why So Many Small-Business Websites Score a D, and How to Climb OutWe ran the same free scan across every small-business website in whole cities and published the aggregate. The typical independent business scored a D. Not an F, not an A, a D, over and over. This is why that keeps happening, and it is almost never what site owners assume.
- How to Tell If Your WordPress Site Is Hacked: 9 Warning SignsA hacked WordPress site rarely puts up a flashing alert. It leaks small, easy-to-miss clues first. Here are the nine warning signs that matter, what each one actually means, and the calm first steps to take before you touch a single file.
- Wordfence Alternative: What to Use Instead, and When You Still Want the PluginMost "Wordfence alternative" advice skips the honest part. Wordfence runs an active firewall and a malware scanner inside your site. A read-only assessment does not. Here is what actually replaces what, and when you still want Wordfence installed.
- BadgerScan vs Sucuri SiteCheck: Two Honest Tools for Different JobsSucuri SiteCheck answers one question fast: does my public page look infected or blacklisted right now. BadgerScan answers a wider one: how exposed am I, inside and out, and what do I fix first. Here is where each fits, with no spin.
- Free WordPress Security Scanners Compared: How to PickEvery free WordPress security scanner checks something different, and most check only half of what matters. Here is what the main approaches actually see, where each one is blind, and how to choose for a small-business site.
- Abandoned WordPress Plugins: How to Spot Them and What to DoAn unmaintained plugin does not announce itself. It just sits there, working fine, until a vulnerability is found and never patched. Here is how to recognise an abandoned plugin and replace it before it becomes the way in.
- WordPress Site Hacked? What to Do: A Calm Recovery ChecklistIf your WordPress site has been hacked, take a breath: here is a clear, practical plan to contain the damage, clean it up, and stop it from happening again.
- Website Security Terms, in Plain EnglishSecurity reports are full of acronyms that assume you already know them. This glossary defines the terms a small-business owner actually runs into, one short sentence each, plus why it matters and where to check it on your own site.
- Free vs Paid Website Security Scanner: What Each One Actually CatchesFree scanners and paid ones are not better and worse versions of the same thing. They look at your site from different places. Here is what each one sees, where each one goes blind, and how to decide what you need.
- WordPress Security for Small Business: A 2026 Ontario ChecklistA skimmable, no-jargon checklist any Ontario small-business owner can work through to keep a WordPress website safe in 2026.
- HTTP Security Headers Explained, in Plain EnglishSecurity headers are short instructions your site sends to every visitor's browser. Here is what each one does, what a scan report is telling you, and the order to add them without breaking your site.
- A Website Security Scan That Sees Inside and OutsideMost free scanners only check what is visible from the street. The real risks usually sit behind the login, so the best website security scan looks at both and combines what it finds.
- WordPress Two-Factor Authentication Setup: How to Turn It OnA stolen or guessed password is one of the easiest ways into a WordPress site. Two-factor authentication shuts that door. Here is how to turn it on, which method to choose, and how to make sure every admin uses it.
- WordPress Plugin Vulnerabilities: Why 96% of the Risk Lives in Your Add-onsThe WordPress core software is remarkably solid, so the real danger to your small-business website almost always comes from the plugins and themes you bolt on top of it.
- Is My Business Email Spoofable? A Plain-English Guide to SPF, DKIM and DMARCIf your domain is missing three small DNS records, a stranger can send invoices and password requests that look exactly like they came from you, and your customers may never know.
- What Hackers See On My Website: The Outside of Your WordPress SiteLong before anyone touches your login page, your website quietly tells the outside world a great deal about itself, and a little of that knowledge is all an attacker needs to start.
Free checks you can run now
Each of these is part of the one free scan. Run it on your own site to see exactly what an attacker sees.
- Free SPF and DMARC Checker: Can Someone Spoof Your Email?
- Free Security Headers Checker: Test HSTS, CSP, and More
- Free SSL Certificate Checker: Validity, Expiry, Chain, and TLS Version
- Free WordPress Vulnerability Scanner
- Free DNS Checker: See What Your Domain's DNS Reveals
- Exposed Files Checker: Find Publicly Reachable Backups and Config Files
See where your site stands
Run the free BadgerScan scan for one plain-English grade across your whole site, inside and out, then use the guides above to fix what it finds.
Run a free security scanSources
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.