CMS Development Guide 2026
πŸ” Security & Legal

Backups & WordPress security

Backups

  • Set up automatic backups before handing off
  • WordPress: UpdraftPlus (free, reliable)
  • Most managed WordPress hosts include daily backups
  • Tell the client where their backups are and how to restore

WordPress security basics

  • Use a security plugin: Wordfence or Solid Security
  • Change default login URL from `/wp-admin` to something custom
  • Use strong passwords and 2FA
  • Keep WordPress, themes, and plugins updated