Website Security Checklist: HTTPS, DNS, Server, Backups, MFA & Monitoring

Author Avatar Digital Bhatti
• September 25, 2026 • Web Hosting
Website security checklist for WordPress CMS SSL WAF backups and server hardening

Website security is risk reduction, not a one-click product.

A secure WordPress or CMS deployment depends on several layers working together: HTTPS, updates, strong authentication, a web application firewall, safe file permissions, backups, DNS hygiene and server access controls.

This checklist focuses on the controls that matter most for ordinary websites and small-business infrastructure without pretending that one plugin, VPN or paid SSL certificate can secure the entire stack.

Disclosure: Digital Bhatti may participate in affiliate programs for hosting and security tools. Recommendations on this page are based on the security problem being solved. We do not claim independent testing, auditing or benchmarking unless the article includes the corresponding methodology and evidence.
Security approach used in this guide

Prioritize layered controls: keep software updated, reduce unnecessary exposure, encrypt traffic, protect credentials, filter malicious requests, maintain recoverable backups and monitor the systems that matter.

Last verified: September 15, 2026.


1. The Website Security Checklist

Security Layer Main Risk Reduced Recommended Action Priority
HTTPS / TLS Eavesdropping and traffic tampering Use a valid certificate and enforce HTTPS Critical
Updates Known software vulnerabilities Keep CMS core, plugins, themes and server packages current Critical
Authentication Credential stuffing and brute force Strong unique passwords + MFA/2FA Critical
WAF / edge filtering Malicious application requests Use Cloudflare WAF, ModSecurity or equivalent controls High
Backups Data loss, ransomware, bad updates Automate offsite backups and test restores Critical
Server access Unauthorized administrative access Limit SSH exposure, use keys/MFA where supported, restrict admin access High
DNS and email authentication Spoofing and domain abuse Configure SPF, DKIM and DMARC where applicable High
Monitoring Delayed detection Monitor uptime, logs, login activity and certificate expiry High

2. Enforce HTTPS and Modern TLS

HTTPS encrypts traffic between the browser and the website, reducing the risk of eavesdropping and tampering in transit.

For many ordinary websites, the simplest option is the free certificate already provided by the host or an automated Let's Encrypt deployment.

If you use Cloudflare, configure encryption between both legs of the connection. Cloudflare recommends Full (strict) where possible so the connection from Cloudflare to the origin is also encrypted and the origin certificate is validated.

If your needs go beyond basic automated HTTPS—for example wildcard coverage, several domains, OV/EV business validation or commercial certificate support—compare the options in our Best SSL Certificates guide.


3. Keep WordPress, Plugins and Themes Updated

WordPress' own security documentation emphasizes keeping WordPress itself and installed plugins and themes current.

Practical rules:

  • Install updates from trusted sources.
  • Remove unused plugins and themes instead of leaving them dormant indefinitely.
  • Avoid abandoned or pirated software.
  • Review changelogs before major production updates.
  • Maintain a rollback-capable backup before significant changes.

4. Harden Authentication

Use strong unique passwords and enable MFA or 2FA wherever the platform supports it.

For WordPress and hosting accounts, protect at least:

  • WordPress administrator accounts.
  • Hosting control-panel accounts.
  • Domain registrar accounts.
  • Cloudflare accounts.
  • Email accounts used for password resets.
  • SSH or server-management accounts.

A compromised email or registrar account can be as damaging as a compromised WordPress password.


5. Use a Web Application Firewall

A WAF can filter suspicious web requests before they reach the application.

Common options include:

  • Cloudflare WAF at the edge.
  • ModSecurity rules at the server or hosting layer.
  • Managed host-specific application filtering.

No WAF is a substitute for patching vulnerable software. Treat it as another layer, not the only defense.


6. Protect the Origin Server

If Cloudflare proxies your website, an exposed origin IP can allow direct requests that bypass some edge protections.

Where your architecture supports it, restrict origin access to trusted traffic sources and use properly validated origin HTTPS.

Cloudflare also documents Authenticated Origin Pulls as an additional control that helps verify requests reaching the origin came through Cloudflare.


7. Secure WordPress File Permissions

WordPress recommends limiting write access rather than making files broadly writable.

A common Linux baseline is:

# Directories
find /path/to/wordpress/ -type d -exec chmod 755 {} \;

# Files
find /path/to/wordpress/ -type f -exec chmod 644 {} \;

Actual ownership and permissions depend on your server model, PHP handler and hosting configuration. Do not apply permissions blindly to production systems.


8. Protect wp-config.php and Sensitive Files

wp-config.php contains database credentials and other sensitive configuration.

Restrict access using the mechanisms appropriate for your web server.

On Apache-compatible environments, one possible rule is:

<Files "wp-config.php">
  Require all denied
</Files>

Test configuration changes carefully because server syntax varies.


9. Back Up Offsite and Test Restores

A backup that cannot be restored is not a reliable recovery plan.

For important production sites:

  • Automate backups.
  • Store at least one copy outside the primary hosting account.
  • Retain multiple restore points.
  • Test restores periodically.
  • Document what is covered: files, database, email, DNS and application secrets.

Backup frequency should reflect how much data you can afford to lose.


10. Secure DNS and Email Authentication

Domain security is part of website security.

Protect registrar and DNS accounts with strong authentication, and configure SPF, DKIM and DMARC for domains that send email.

Also review DNS records after migrations so abandoned A, CNAME or MX records do not continue pointing to old infrastructure.


11. Secure Administrative Network Access

Do not treat public networks as inherently trusted.

For remote administrative work:

  • Prefer encrypted protocols such as HTTPS and SSH.
  • Avoid exposing database interfaces publicly when possible.
  • Use a VPN when your network model or organization requires one.
  • Restrict SSH by firewall, keys, MFA or access gateway where supported.

The important control is reducing exposure and protecting credentials—not purchasing a specific VPN brand by default.


12. Monitor Uptime, Logs and Certificate Expiry

Security failures are easier to contain when they are detected quickly.

Monitor:

  • Unexpected administrator logins.
  • Repeated failed authentication attempts.
  • Application and web-server errors.
  • File changes where appropriate.
  • Certificate expiry.
  • Uptime and external availability.

For a self-hosted availability workflow, Digital Bhatti's Uptime Kuma guide can be used to add independent uptime monitoring.


13. Website Security Priority Order

1. Patch core software, plugins and themes
2. Protect admin / registrar / email accounts with MFA
3. Enforce HTTPS end to end
4. Maintain tested offsite backups
5. Add WAF / edge filtering
6. Restrict server and origin exposure
7. Harden file permissions and sensitive configuration
8. Configure DNS and email authentication
9. Monitor uptime, logs and certificate expiry

This order is more useful than buying random security products without first closing basic operational gaps.


Frequently Asked Questions

Do I need a paid SSL certificate for website security?

Usually not. Many ordinary websites are well served by a valid automatically renewed free certificate. Paid certificates are more relevant when wildcard, multi-domain, OV/EV, commercial support or organizational policy requirements apply.

What is the most important WordPress security action?

There is no single control, but keeping WordPress core, plugins and themes updated is foundational. WordPress itself identifies current software as a key security practice.

Should I disable XML-RPC?

Only if your site does not depend on features that use it. Blocking XML-RPC indiscriminately can break integrations, so treat it as an application-specific hardening decision.

Does a WAF replace WordPress updates?

No. A WAF can filter malicious traffic, but vulnerable software should still be patched or removed.

How often should I back up my website?

Match backup frequency to the amount of data you can afford to lose. A frequently updated ecommerce site may need much more frequent database backups than a static brochure site.

Should I use a VPN to manage WordPress?

A VPN can be useful in some network models, but the core requirements are encrypted protocols, strong authentication and restricted administrative exposure. A VPN is one possible layer, not a universal requirement.

Abdul Shakoor, founder of Digital Bhatti
Written by

Abdul Shakoor

Founder of Digital Bhatti, focused on web hosting and infrastructure, WordPress performance, Linux VPS environments, web servers and technical SEO.