Loading...

A Must-Have Website Security Checklist

Maintaining strong website security is essential for protecting your website, your business, and your visitors' data. While Bluehost provides a secure hosting environment, website security also requires ongoing maintenance and proactive protection measures.

For additional information, visit our blog: Website Security - How to Protect your Website from Digital Threats.

Website Security Checklist

Use the following best practices to improve and maintain your website's security.

Remove Unfamiliar or Suspicious Files

Regularly review your website files and directories. Investigate and remove unexpected files or folders, especially those with suspicious names that do not belong to your website or applications.

Keep Scripts and Applications Updated

Outdated software often contains known security vulnerabilities. Always update your website applications to the latest stable versions and subscribe to vendor security announcements when available.

Update Plugins and Extensions

Plugins and extensions must be updated alongside your website platform. Ensure all plugins are compatible with the latest version of your application and remove any that are unused.

Change Passwords and Remove Unused Accounts

If you suspect a security issue, immediately update passwords for:

Also, remove any inactive or unnecessary user accounts.

Delete Unused Databases and Applications

Every installed application or database represents a potential attack surface. Remove software, databases, and tools that are no longer needed.

Correct File Permissions

Recommended permission settings:

  • Files: 644
  • Directories/Folders: 755

Avoid overly permissive settings that allow unauthorized modifications.

Protect Configuration Files

Store configuration files containing sensitive information, such as database credentials, outside the publicly accessible web directory whenever possible.

Secure Your PHP Configuration

Review your php.ini configuration and consider:

  • Setting register_globals to Off
  • Setting display_errors to Off

These settings help reduce exposure of sensitive system information.

Use a Secure Network

When accessing your hosting account or website administration tools, use a trusted and encrypted network connection, such as WPA2 or WPA3-protected Wi-Fi.

Secure Your Computer

Your local computer can become an entry point for attackers. Keep your operating system updated and regularly scan for:

  • Viruses
  • Malware
  • Spyware
  • Keyloggers

Use Encrypted Email Connections

Configure email clients such as Outlook or Apple Mail to connect using SSL/TLS encryption. This helps protect login credentials and email content during transmission.

Install Anti-Virus and Anti-Malware Software

Using reputable security software helps protect your devices and website credentials from compromise.

Linux-based: Avast! Linux Home Edition

Mac: ClamXav

Windows:

What to Do If You Suspect Your Website Has Been Compromised

Discovering that your website may be infected or hacked can be stressful, but there are several options available.

Option 1: Use a Professional Malware Cleaning Service

If you do not have the time or technical expertise to clean an infected website, a professional malware removal service can help identify, remove, and prevent future infections.

For Bluehost customers, Bluehost Malware Protection provides malware cleanup and proactive website security solutions.

Option 2: Restore From a Clean Backup

If you have a backup from before the infection occurred, restoring the site may be the quickest solution.

Important:

  • Restore only from a known clean backup.
  • Avoid restoring backups that may already contain malware.
  • Recreate any website changes made after the backup date.

After restoration, address the vulnerability that allowed the compromise to prevent reinfection.

Tools such as Basic Weekly Backup and Jetpack can help simplify website backup and recovery.

Option 3: Rebuild the Website

If the website cannot be effectively cleaned or restored, rebuilding the site from scratch may be the safest option.

Summary

Website security requires continuous attention and proactive maintenance. Regular updates, strong password practices, secure file permissions, protected devices, and reliable backups all play critical roles in keeping your website safe.

If your website becomes compromised, consider:

  1. Professional malware removal
  2. Restoring from a clean backup
  3. Rebuilding the website if necessary

Following these best practices can significantly reduce the risk of security incidents and help protect your online presence.

If you need further assistance, Bluehost Chat Support is available 24 hours a day, 7days a week while Bluehost Phone Support is available 7 days a week from 7 am-12 midnight EST. 

  • Chat Support -  While on our website, you should see a CHAT bubble in the bottom right-hand corner of the page. Click anywhere on the bubble to begin a chat session.
  • Phone Support -
    • US: 888-401-4678
    • International: +1 801-765-9400

You may also refer to our Knowledge Base articles to help answer common questions and guide you through various setup, configuration, and troubleshooting steps.

Loading...