09/09/2026
Seven checks. Under an hour. Dashboard access and a browser, nothing to buy.
We wrote a WordPress security audit you can run yourself, ordered so the checks most likely to find real exposure come first.
The one that surprises people is the first: who has Administrator access. The developer who built the site four years ago. An agency you stopped working with. A staff member who left. A plugin support account created for a one-off issue in 2023. All ordinary, all still able to install software on your site.
The one that matters most is multi-factor authentication on every account that can install a plugin. Ten minutes of work, and it defeats the most common way small business sites are compromised.
And the backup question is not "do you have backups" β everyone says yes to that. It is when anyone last restored one and opened it.
Read the full checklist: https://insights.cloudgeeks.com.au/blog/audit-wordpress-security-under-an-hour-checklist/