What is a good website security checklist?
Here is a practical checklist to keep your Dirham A Day site secure. Work through it once, then review it every few months.
Access & passwords
- Strong, unique passwords everywhere (control panel, email, FTP, database, WordPress).
- Two-factor authentication enabled on the control panel, client area and WordPress.
- Remove old users and access you no longer need.
Software
- WordPress core, plugins and themes fully updated.
- Unused plugins and themes deleted.
- Running a current, supported PHP version.
Encryption
- Free SSL active and HTTPS forced site-wide; no mixed content.
- Email configured with secure SSL/TLS ports.
Hardening
- Correct file permissions (folders 755, files 644, config 600/640).
- Directory browsing disabled; sensitive files protected.
- Login protection / limited login attempts.
Resilience
- DirhamVault off-site backups in place, and you know how to restore.
- SPF, DKIM and DMARC set for your domain.
Our servers add CSF, LFD, ModSecurity, malware scanning and DirhamGuard around your account. For a hand working through this list, contact our team on WhatsApp +971 58 553 6767 or support@dirhamaday.ae or log in at my.dirhamaday.ae.
Still need a hand? Our UAE-based team is here 24/7.