For marketing purposes, a secure site will always score higher on SEO than an insecure site – which makes the following tips crucial for increasing business as well as reputational integrity and the protection of customer data.

Before building a website, small business owners typically choose between user-friendly website building tools such as Wix, Squarespace, and Weebly versus mature Content Management System platforms such as WordPress or Joomla hosted by a separate hosting provider.  Given that “all-in-one” website development/hosting solutions such as Wix offer a single point of intrusion, in some ways they are more vulnerable.  Choosing the most suitable solution may be easy if your growth plans and need for independence are aligned.   Many business owners will choose an all-in-one provider than elevates ease of use over everything.

What follows is helpful for those small business owners who are interested in building out a website that gives them greater control over how things look and operate – something available when using WordPress and Joomla.

Here are the top five tips for website security if your company has a minimal budget but is looking for the flexibility offered by a CMS platform.  If your budget is larger, you may want to use a more sophisticated product such as Webflow.  WordPress has been extremely popular with small business owners given the CMS platform allows owners to easily upload and modify content – without the need for a developer charging for every edit.  Given that a large portion of the Internet is using WordPress, these tips focus primarily on WordPress security.

  1. Even though WordPress and Joomla are built using an open-source language (PHP) that previously had security flaws, they have achieved significant security maturity. Corporate websites built using WordPress now allow for secure custom shops and can securely mesh with your own separate e-commerce shops built using Shopify.  Even though some security specialists advocate waiting on software updates to be properly tested before implementation, that sort of counsel typically applies with upgrades mapping to an internal network.  Despite the slight risk inherent in immediately applying an upgrade, the first tip remains having WordPress on auto-update to ensure all security updates are in place as soon as possible.
  2. Because templates can reveal security vulnerabilities over time, choose a mature template with many thousands of downloads that has been security tested over a long period and routinely updated. Avoid free templates in favor of ones that are provided for a fee – which better demonstrates long-term commitment and provides financial incentives for a developer’s ongoing maintenance.  Paid templates are relatively cheap with many good ones being under $100 for lifetime usage.  Do a little research before downloading a template and installing it.
  3. Limit the use of Plugins to those essential for WordPress security, including WordFence (or a similar firewall/scanning plugin), WPS Hide Login (or similar plugin that hides the default login URL frequented by hackers, namely “/wp-admin” or “/wp-login.php”), and Disable XML-RPC-API (or similar plugin disables the XML-RPC and trackbacks-pingbacks on your WordPress website that can lead to brute-force and DDOS attacks). If you limit the use of plugins security plugins and those essential to your site, you limit the likelihood of a breach given so many incidents are directly tied to insecure plugins – those that may have not been updated in years yet are still active on your site.  All plugins should also be routinely monitored and auto-updated.  Most security plug-ins will assist you in making these and other necessary changes.
  4. Make sure you install an SSL (Secure Sockets Layer) Certificate allowing for encrypted HTTPS communications between site and browser. Google’s Chrome browser has long warned when a website does not use this HTTPS protocol – a warning that likely causes potential visitors to not even visit the site.  The Really Simple SSL plugin can help ensure that is properly done.  Many hosting companies provide a free SSL certificate so getting the plugin will make this an easy fix if needed.
  5. Practice good security hygiene by using passwords that include upper case letters, numbers, lower case numbers, and symbols that total no less than 10 characters. Keep the password in a safe place if you cannot memorize it and only use it for your website.  As well, deploy two-factor authentication to make it that much more difficult to get in the website using the front door – Authenticator is an excellent app for 2FA purposes but there many to choose from.

By using the right security plugins and these very basic safeguards, you make your site that much less appealing to the thousands of bots scouring the Internet for website vulnerabilities.  While it is incumbent on open-source developers, plugin and theme developers, and hosting companies to harden their own separate defenses, the strongest chain of defense can only be as strong as its weakest link.