An online store holds things attackers want: customer names and addresses, order histories, admin access and sometimes a checkout they can tamper with. Small stores get targeted too, usually not by a person picking them out but by automated bots scanning thousands of sites for the same weak spots.

The good news is that most of those weak spots are basic and fixable. This checklist covers fifteen steps a non-developer can work through, grouped by area. You don’t need to do them all in one day, but you should do them all.

Updates and software

1. Keep WordPress, WooCommerce, plugins and themes updated

Outdated plugins and themes are one of the most common ways WordPress sites get compromised. Security fixes are shipped in updates, and once a fix is public, attackers know exactly what to look for on sites that haven’t updated.

A practical routine:

  • Check Dashboard → Updates at least weekly.
  • Enable automatic updates for minor WordPress releases (the default) and for plugins you trust.
  • For major WooCommerce updates, test on a staging copy first if your host offers one, then update the live store.

Core updates also bring security improvements that you get only by updating. WordPress 6.8, released in April 2025, for example, switched password hashing to bcrypt by default.

2. Remove plugins and themes you don’t use

A deactivated plugin still sits on your server and can still contain vulnerable code. Go to Plugins → Installed Plugins and delete anything you’re not using. Do the same for old themes under Appearance → Themes, keeping only your active theme and, if you like, one default WordPress theme as a fallback.

3. Only install plugins and themes from reputable sources

Stick to the official WordPress.org directory, the WooCommerce marketplace or well-known developers. Never install “nulled” (pirated) premium plugins or themes. They are a well-known way of distributing malware.

Before installing, check when the plugin was last updated, whether it’s compatible with your WordPress version and whether the developer responds to support questions.

Logins and user accounts

4. Use strong, unique passwords everywhere

That means your WordPress admin, hosting account, domain registrar, email account and payment gateway dashboard. A password manager makes this practical. Reused passwords are dangerous because a leak from one unrelated site can open your store.

5. Turn on two-factor authentication

Two-factor authentication (2FA) asks for a code from your phone in addition to a password. WordPress doesn’t include 2FA in core, but several well-maintained plugins add it. Enable it at least for every administrator and shop manager account. Also turn it on for your hosting, domain and payment accounts.

6. Limit login attempts

Bots try thousands of password combinations on the login page. A security plugin or your host’s firewall can limit repeated failed attempts from the same source. Some hosts already do this at server level, so check before adding a plugin.

7. Give people the lowest role they need

Review Users → All Users. WooCommerce adds a “Shop manager” role that can manage orders and products without full admin rights, which is often enough for staff. Remove accounts for former employees, freelancers and agencies as soon as their work ends. Avoid using a username like “admin.”

Backups and recovery

8. Take automatic, off-site backups

A backup is the safety net that makes every other problem recoverable. Good backups for a store:

  • Run automatically, at least daily. Busy stores may want more frequent database backups, since orders change constantly.
  • Include both files and the database.
  • Are stored somewhere other than your web server, such as cloud storage or your host’s separate backup system.
  • Are kept for a few weeks, so you can go back to before a problem started.

9. Test a restore

A backup you’ve never restored is a guess. Once or twice a year, restore a backup to a staging site and check that the store loads, products appear and orders are there. Many hosts offer one-click staging sites that make this easy.

Hosting and server

10. Choose hosting that takes security seriously

Your host handles a big part of your security. Look for:

  • Server-level firewall and malware scanning
  • Isolation between accounts, so a hacked site on the same server can’t reach yours
  • Automatic backups
  • Support for current PHP versions
  • Responsive support if something goes wrong

Cheap shared hosting can be fine for a small store, but check what’s included.

11. Use HTTPS everywhere

Your whole site, not just checkout, should load over HTTPS. Most hosts provide free SSL certificates. Check that Settings → General shows your site address starting with https://, and that browsers don’t show mixed content warnings on any page.

12. Keep PHP up to date

Your host lets you choose which PHP version your site runs on. Older PHP versions stop receiving security fixes. Check the current version in Tools → Site Health → Info → Server, and ask your host to help you move to a supported version. Test on staging first, as very old plugins may not be compatible.

Payments and customer data

13. Let your payment provider handle card data

The safest way to accept cards is to never have card numbers touch your server. Well-known gateways such as Stripe, WooPayments, PayPal and Square use hosted fields or redirects so that card details go straight to them. This also reduces your compliance burden under PCI DSS, the card industry’s security standard. Our guide to managing WooCommerce payment gateways covers the options.

Never store card numbers in order notes, spreadsheets or email.

14. Watch for fake orders and card testing

Card testing is when fraudsters use your checkout to check whether stolen card numbers work, usually with many small orders in a short time. Warning signs include a burst of failed payments, lots of low-value orders from different names and a spike in new accounts. Your payment gateway’s fraud tools, a CAPTCHA on checkout or rate limiting from your host can help. Contact your payment provider quickly if you see this, as it can affect your account.

Monitoring

15. Monitor your site and know your recovery plan

Set up:

  • Uptime monitoring that emails you if the store goes down
  • Malware scanning, from your host or a security plugin
  • Activity logging that records admin logins and changes to users, plugins and settings

And write down, in one place, what you’ll do if something goes wrong: who to contact at your host, where your backups are, and how to reach your payment provider.

The checklist at a glance

# Step How often
1 Update core, WooCommerce, plugins, themes Weekly
2 Remove unused plugins and themes Quarterly
3 Install only from reputable sources Always
4 Strong, unique passwords Once, then on staff changes
5 Two-factor authentication Once
6 Limit login attempts Once
7 Review user roles Quarterly
8 Automatic off-site backups Set once, check monthly
9 Test a restore Twice a year
10 Review hosting security Yearly
11 HTTPS everywhere Once, check after changes
12 Supported PHP version Twice a year
13 Gateway handles card data Once
14 Watch for card testing Ongoing
15 Monitoring and recovery plan Set once, review yearly

A 30-minute monthly routine

If you do nothing else, block out half an hour on the first Monday of each month:

  1. Log in, check for updates and apply them (5 minutes).
  2. Check that last night’s backup exists (2 minutes).
  3. Look over Users → All Users for accounts you don’t recognise (3 minutes).
  4. Review the security plugin or host’s scan results (5 minutes).
  5. Skim recent orders and failed payments for anything unusual (5 minutes).
  6. Check Tools → Site Health for critical issues (5 minutes).
  7. Note anything to fix and schedule it (5 minutes).

What to do if you think you’ve been hacked

Signs include unexpected redirects, new admin users you didn’t create, spam pages in Google results or a warning from your host. If it happens:

  1. Don’t panic, and don’t start deleting things at random.
  2. Contact your host. Many will help clean up or restore.
  3. Change all passwords: WordPress, hosting, database, FTP and email.
  4. Restore from a clean backup taken before the problem started, if you have one.
  5. Update everything and remove the plugin or theme that let the attacker in, if you can identify it.
  6. If customer data may have been exposed, check your legal obligations for notifying customers and authorities where you operate.

Choosing a theme with security in mind

Your theme is code running on every page, so treat it like any plugin: choose one that’s actively maintained, compatible with the latest WordPress and WooCommerce, and from a developer with a track record. Avoid themes that bundle many third-party plugins you can’t update separately. iConvert Themes are built and maintained by Extend Themes, whose WordPress products run on more than 200,000 sites. For more on picking extensions carefully, see our roundup of WooCommerce extensions.

Keep your store boring and safe

Security for a small store isn’t about expensive tools. It’s about habits: update regularly, keep only what you use, protect logins, back up and test, and let your payment provider handle card data. Work through the fifteen steps once, then keep up the monthly routine.

Looking for a well-maintained ecommerce theme to build on? Take a look at iConvert Themes.

It's easy to create website popups people will love.

Find out how to:
  • grow your lists, leads, and sales;
  • retain abandoning visitors;
  • create unique WordPress popups in minutes;
  • reach the right audience at the right time.

Setting up a WooCommerce online store can be hassle-free.

It's time to find out how to:
  • start your e-commerce business with WooCommerce
  • grow your store using marketing strategies
  • optimize your website using Analytics and A/B testing
Check these out

Comments are closed

Join the newsletter!