An online store holds things attackers want: customer names and addresses, order histories, admin access and sometimes a checkout they can tamper with. Small stores get targeted too, usually not by a person picking them out but by automated bots scanning thousands of sites for the same weak spots.
The good news is that most of those weak spots are basic and fixable. This checklist covers fifteen steps a non-developer can work through, grouped by area. You don’t need to do them all in one day, but you should do them all.
Updates and software
1. Keep WordPress, WooCommerce, plugins and themes updated
Outdated plugins and themes are one of the most common ways WordPress sites get compromised. Security fixes are shipped in updates, and once a fix is public, attackers know exactly what to look for on sites that haven’t updated.
A practical routine:
- Check Dashboard → Updates at least weekly.
- Enable automatic updates for minor WordPress releases (the default) and for plugins you trust.
- For major WooCommerce updates, test on a staging copy first if your host offers one, then update the live store.
Core updates also bring security improvements that you get only by updating. WordPress 6.8, released in April 2025, for example, switched password hashing to bcrypt by default.
2. Remove plugins and themes you don’t use
A deactivated plugin still sits on your server and can still contain vulnerable code. Go to Plugins → Installed Plugins and delete anything you’re not using. Do the same for old themes under Appearance → Themes, keeping only your active theme and, if you like, one default WordPress theme as a fallback.
3. Only install plugins and themes from reputable sources
Stick to the official WordPress.org directory, the WooCommerce marketplace or well-known developers. Never install “nulled” (pirated) premium plugins or themes. They are a well-known way of distributing malware.
Before installing, check when the plugin was last updated, whether it’s compatible with your WordPress version and whether the developer responds to support questions.
Logins and user accounts
4. Use strong, unique passwords everywhere
That means your WordPress admin, hosting account, domain registrar, email account and payment gateway dashboard. A password manager makes this practical. Reused passwords are dangerous because a leak from one unrelated site can open your store.
5. Turn on two-factor authentication
Two-factor authentication (2FA) asks for a code from your phone in addition to a password. WordPress doesn’t include 2FA in core, but several well-maintained plugins add it. Enable it at least for every administrator and shop manager account. Also turn it on for your hosting, domain and payment accounts.
6. Limit login attempts
Bots try thousands of password combinations on the login page. A security plugin or your host’s firewall can limit repeated failed attempts from the same source. Some hosts already do this at server level, so check before adding a plugin.
7. Give people the lowest role they need
Review Users → All Users. WooCommerce adds a “Shop manager” role that can manage orders and products without full admin rights, which is often enough for staff. Remove accounts for former employees, freelancers and agencies as soon as their work ends. Avoid using a username like “admin.”
Backups and recovery
8. Take automatic, off-site backups
A backup is the safety net that makes every other problem recoverable. Good backups for a store:
- Run automatically, at least daily. Busy stores may want more frequent database backups, since orders change constantly.
- Include both files and the database.
- Are stored somewhere other than your web server, such as cloud storage or your host’s separate backup system.
- Are kept for a few weeks, so you can go back to before a problem started.
9. Test a restore
A backup you’ve never restored is a guess. Once or twice a year, restore a backup to a staging site and check that the store loads, products appear and orders are there. Many hosts offer one-click staging sites that make this easy.
Hosting and server
10. Choose hosting that takes security seriously
Your host handles a big part of your security. Look for:
- Server-level firewall and malware scanning
- Isolation between accounts, so a hacked site on the same server can’t reach yours
- Automatic backups
- Support for current PHP versions
- Responsive support if something goes wrong
Cheap shared hosting can be fine for a small store, but check what’s included.
11. Use HTTPS everywhere
Your whole site, not just checkout, should load over HTTPS. Most hosts provide free SSL certificates. Check that Settings → General shows your site address starting with https://, and that browsers don’t show mixed content warnings on any page.
12. Keep PHP up to date
Your host lets you choose which PHP version your site runs on. Older PHP versions stop receiving security fixes. Check the current version in Tools → Site Health → Info → Server, and ask your host to help you move to a supported version. Test on staging first, as very old plugins may not be compatible.
Payments and customer data
13. Let your payment provider handle card data
The safest way to accept cards is to never have card numbers touch your server. Well-known gateways such as Stripe, WooPayments, PayPal and Square use hosted fields or redirects so that card details go straight to them. This also reduces your compliance burden under PCI DSS, the card industry’s security standard. Our guide to managing WooCommerce payment gateways covers the options.
Never store card numbers in order notes, spreadsheets or email.
14. Watch for fake orders and card testing
Card testing is when fraudsters use your checkout to check whether stolen card numbers work, usually with many small orders in a short time. Warning signs include a burst of failed payments, lots of low-value orders from different names and a spike in new accounts. Your payment gateway’s fraud tools, a CAPTCHA on checkout or rate limiting from your host can help. Contact your payment provider quickly if you see this, as it can affect your account.
Monitoring
15. Monitor your site and know your recovery plan
Set up:
- Uptime monitoring that emails you if the store goes down
- Malware scanning, from your host or a security plugin
- Activity logging that records admin logins and changes to users, plugins and settings
And write down, in one place, what you’ll do if something goes wrong: who to contact at your host, where your backups are, and how to reach your payment provider.
The checklist at a glance
| # | Step | How often |
|---|---|---|
| 1 | Update core, WooCommerce, plugins, themes | Weekly |
| 2 | Remove unused plugins and themes | Quarterly |
| 3 | Install only from reputable sources | Always |
| 4 | Strong, unique passwords | Once, then on staff changes |
| 5 | Two-factor authentication | Once |
| 6 | Limit login attempts | Once |
| 7 | Review user roles | Quarterly |
| 8 | Automatic off-site backups | Set once, check monthly |
| 9 | Test a restore | Twice a year |
| 10 | Review hosting security | Yearly |
| 11 | HTTPS everywhere | Once, check after changes |
| 12 | Supported PHP version | Twice a year |
| 13 | Gateway handles card data | Once |
| 14 | Watch for card testing | Ongoing |
| 15 | Monitoring and recovery plan | Set once, review yearly |
A 30-minute monthly routine
If you do nothing else, block out half an hour on the first Monday of each month:
- Log in, check for updates and apply them (5 minutes).
- Check that last night’s backup exists (2 minutes).
- Look over Users → All Users for accounts you don’t recognise (3 minutes).
- Review the security plugin or host’s scan results (5 minutes).
- Skim recent orders and failed payments for anything unusual (5 minutes).
- Check Tools → Site Health for critical issues (5 minutes).
- Note anything to fix and schedule it (5 minutes).
What to do if you think you’ve been hacked
Signs include unexpected redirects, new admin users you didn’t create, spam pages in Google results or a warning from your host. If it happens:
- Don’t panic, and don’t start deleting things at random.
- Contact your host. Many will help clean up or restore.
- Change all passwords: WordPress, hosting, database, FTP and email.
- Restore from a clean backup taken before the problem started, if you have one.
- Update everything and remove the plugin or theme that let the attacker in, if you can identify it.
- If customer data may have been exposed, check your legal obligations for notifying customers and authorities where you operate.
Choosing a theme with security in mind
Your theme is code running on every page, so treat it like any plugin: choose one that’s actively maintained, compatible with the latest WordPress and WooCommerce, and from a developer with a track record. Avoid themes that bundle many third-party plugins you can’t update separately. iConvert Themes are built and maintained by Extend Themes, whose WordPress products run on more than 200,000 sites. For more on picking extensions carefully, see our roundup of WooCommerce extensions.
Keep your store boring and safe
Security for a small store isn’t about expensive tools. It’s about habits: update regularly, keep only what you use, protect logins, back up and test, and let your payment provider handle card data. Work through the fifteen steps once, then keep up the monthly routine.
Looking for a well-maintained ecommerce theme to build on? Take a look at iConvert Themes.
Comments are closed