Website security requires several layers of protection. The following recommendations can reduce your risk and make recovery easier if an incident occurs.
Keep Software, Plugins, and Themes Updated
Keep your content management system (CMS), plugins, themes, and other website applications up to date. Older versions may contain known security vulnerabilities.
Install software only from sources you trust. Replace anything that is no longer maintained or supported by its developer.
Before installing a major update, create a backup and confirm your website is compatible with the new version.
See:
Use Strong Passwords and Multifactor Authentication
Use a unique password for every hosting, website, email, database, and file transfer account. A password manager can create and store strong passwords for you.
Enable multifactor authentication wherever it is available, especially for accounts with administrator access.
Avoid sharing account credentials. Give each person an individual account so their access can be managed separately.
See:
- Two-Factor Authentication on Pair Accounts
- Changing or Resetting Your Pair Account Password
- Changing Your WordPress Admin Password in the ACC
- Changing a WordPress Database Password on Shared and VPS
- Changing a WordPress Database Password on Managed WordPress and Podcast Websites
- Changing an FTP Login Password
- Changing Your WP Staging Site Password
- Changing Your Mailbox Password
- Changing Your ACC Database Password
Review Users and Permissions
Regularly review everyone who can access your hosting account, website administration area, databases, and files.
Remove accounts that are no longer needed, including accounts belonging to former employees, contractors, or developers. Temporary accounts should be removed when the work is complete.
Give each user only the permissions required for their work. Administrator access should be limited to people who genuinely need it.
Review SSH keys and file transfer logins as part of this process. Remove keys and logins that are no longer needed.
See:
Remove Unused Software, Files, and Databases
Delete plugins, themes, applications, test sites, files, and databases that you no longer use. Deactivating software does not remove its files. Those files may remain on your account and contain vulnerabilities, so deleting unused software is the better option.
Pay particular attention to abandoned website installations and old development projects. Confirm that an item is no longer needed before permanently removing it.
See:
Maintain Reliable Backups
Create regular backups of your website files and databases. Back up your website more frequently if it changes often.
Keep more than one recent backup, with at least one copy stored separately from your hosting account. This helps protect your backups if the account itself is compromised.
Test the restoration process periodically to confirm that your backups are complete and usable.
Pair offers different backup options based on your hosting package. See:
- Taking Manual File Backups on Shared, VPS, and Dedicated
- WP Hosting Backup Types
- Taking Database Backups in the ACC
- Snapshots and Backups: What is the Difference?
- Customer Accessible File Backups
Use Secure Connections
Use HTTPS to protect information sent between your website and its visitors. Make sure your website has a valid SSL certificate and redirects visitors from HTTP to HTTPS.
Use SFTP or SSH when transferring website files.
See:
Use Pair Malware Security’s Free Detection Tier
Turn on Pair Malware Security’s free Detection tier to scan your domain and detect malware. Check the results periodically and address any issues that are found.
See:
Additional tiers are available if you want more automated protection and security features. Learn more about available protection options here: Pair Malware Security.
Watch for Unusual Activity
Pay attention to security notifications and unexpected changes to your website. Warning signs may include unfamiliar admin accounts, modified files, unwanted redirects, missing content, and other unwanted changes. See Understanding Malware Types and Scan Results for help interpreting Pair Malware Security scan results.
If you suspect a security incident, act promptly. Change affected passwords, review account access, and contact our support team if you have any questions about your account.
Review Your Security Regularly
Website security requires ongoing attention. Review these recommendations periodically and whenever you add users, install new software, or make significant changes to your site.