Overview
WordPress runs 41.5 per cent of all websites and roughly 59 per cent of sites with a known content management system as of mid 2026, making it the single largest attack surface on the web, with the overwhelming majority of that risk living outside core. W3Techs, CMS market share July 2026.
The Patchstack State of WordPress Security 2026 counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, up 42 per cent from 7,966 in 2024, with 91 per cent found in plugins and 9 per cent in themes, and only six reported in WordPress core, all low risk. Patchstack, State of WordPress Security 2026.
Most businesses do not know who owns their domain, where their website is hosted, or whether the backups work. This guide walks through the audit in order of what matters most: domain ownership, DNS, hosting, SSL, backups, CMS security, and transactional email.
The highest-risk items are domain ownership (registered to the business, not an ex-agency), DNS (at a dedicated provider, not the web host), and backups (offsite and tested).
Domain Registration
Domain ownership is the highest-risk item on the audit because a domain registered to a former employee or web agency can be held hostage when the relationship breaks down. For .au domains the registrant must match the business ABN or ACN, and the domain should sit in the business own registrar account with MFA and registrar lock enabled. Patchstack, State of WordPress Security 2026.
For .au domains, use an auDA-accredited Australian registrar. Synergy Wholesale, VentraIP, Crazy Domains Business, and Hostopia are established operators with direct auDA accreditation. For gTLDs (.com, .net, .org), Cloudflare Registrar offers at-cost pricing and strong security. Lock the domain and enforce MFA on the registrar account.
- Registered in the business name, not an ex-employee or web agency
- Admin contact is reachable (real email, not a dead inbox)
- Held with an auDA-accredited registrar for .au domains
- Cloudflare Registrar or equivalent at-cost registrar for gTLDs
- Registrar account has MFA enabled (phishing-resistant preferred for admins)
- Registrar lock and transfer lock enabled
- Auto-renewal on for all critical domains
- Register relevant variants (.com, .com.au, .au, common misspellings)
- Transfer AUTH codes stored securely in password manager
- auDA eligibility evidence retained (ABN or ACN matching the registrant)
DNS
Keep DNS at a dedicated provider such as Cloudflare, AWS Route 53 or Azure DNS rather than the web host, because if DNS lives at the host, changing hosts means losing DNS and potentially email. Publish SPF, DKIM and a DMARC record at p=reject or p=quarantine with reporting, and enable DNSSEC and a CAA record to restrict which certificate authorities can issue for the domain. W3Techs, CMS market share July 2026.
- DNS hosted at a professional provider (Cloudflare, Route 53, Azure DNS). Not at your web host.
- DNSSEC enabled where supported
- MX records match your email provider
- SPF record published, covers every sender, ends with -all (see Email Auth Guide)
- DKIM selectors published per service
- DMARC at p=reject or p=quarantine with reporting
- CAA record restricts which CAs can issue SSL for the domain
- No stale records pointing to dead services
See our Email Authentication Guide for SPF, DKIM, and DMARC detail.
Hosting
A web application firewall and CDN in front of the origin matter more than ever, because Patchstack found in 2025 penetration tests that common hosting defenses such as internal WAFs and CDN-level filtering blocked only 26 per cent of vulnerability exploit attempts overall, and just 12 per cent of WordPress-specific attacks. Patchstack, State of WordPress Security 2026.
- Reputable provider (Cloudflare Pages, AWS, Azure, Pantheon, Kinsta, WP Engine, Hostinger Business, SiteGround, VentraIP business tiers)
- Located in Australia or acceptable region for your audience
- Daily backups with 30 or more day retention
- WAF (Web Application Firewall) enabled
- CDN (Cloudflare or similar) in front of the origin
- TLS 1.2 minimum, TLS 1.3 enabled
- Server software (PHP, Node, MySQL) on supported versions
- Admin panel behind MFA
SSL and Security Headers
A valid auto-renewing SSL certificate is the baseline, not the finish line. Enforce HTTPS with a 301 redirect, set HSTS with preload, publish a Content-Security-Policy, and add X-Frame-Options or frame-ancestors and a Referrer-Policy, then test at securityheaders.com and ssllabs.com. W3Techs, CMS market share July 2026.
- Valid SSL certificate, auto-renewing (Let us Encrypt or commercial)
- HTTP forced to HTTPS via 301 redirect
- HSTS header with preload where possible
- Content-Security-Policy header
- X-Frame-Options or frame-ancestors
- Referrer-Policy
- Use securityheaders.com and ssllabs.com to test
Website Backups
A backup that sits only on the hosting provider and is accessible from the admin panel is not a real backup, because a host outage or takeover leaves no restore path. Keep an offsite or immutable copy, store files and database separately, retain for 30 or more days, and test a restore quarterly. Patchstack, State of WordPress Security 2026.
- Daily automated backups of files and database
- Stored offsite from the hosting provider
- Restore tested quarterly
- 30 or more day retention
- Includes both code and files and database
- Backup not accessible from the admin panel alone (immutable option preferred)
WordPress and CMS Security
WordPress still powers a huge portion of Australian SMB websites. It is also the most attacked platform on the web. Most compromises come from unpatched plugins, not core.
Of the 11,334 new WordPress vulnerabilities logged in 2025, 91 per cent were in plugins and 9 per cent in themes, and highly exploitable vulnerabilities rose 113 per cent year on year, so keeping core, theme and every plugin on the latest version and removing anything unused is the single highest-impact control. Patchstack, State of WordPress Security 2026.
Patchstack found that roughly 20 per cent of heavily exploited flaws were attacked within six hours of disclosure, about 45 per cent within 24 hours and 70 per cent within seven days, so a quarterly update cadence is too slow for any site that handles customer data or payments. Patchstack, State of WordPress Security 2026.
Cross-site scripting accounts for 40.6 per cent of plugin disclosures, broken access control 13.2 per cent and cross-site request forgery 12.9 per cent, and nearly half of disclosed vulnerabilities had no patch available at disclosure, which is why removing unused plugins and limiting admin accounts matters as much as patching. Scantitan, WordPress Plugin Vulnerability Statistics 2026.
- WordPress core, theme, and every plugin on the latest version
- Remove unused themes and plugins (every one is an attack surface)
- Admin username is not admin
- MFA on all admin accounts (Wordfence, iThemes Security, Cloudflare Access)
- Limit login attempts, block known-bad IPs
- XML-RPC disabled unless required
- File editing disabled in wp-config.php (define WP_DISALLOW_FILE_EDIT)
- Security plugin installed (Wordfence, Sucuri, or Patchstack)
- Reviewed quarterly, not just when something breaks
Transactional Email / SMTP
Forms, order confirmations, password resets, newsletters. Sent via your SMTP relay, not your M365 mailbox. Otherwise SPF breaks, deliverability tanks, and your domain gets flagged.
Sending transactional email such as form notifications, order confirmations and password resets from a Microsoft 365 or Google Workspace mailbox breaks SPF, tanks deliverability and can get the domain flagged. Use a dedicated transactional provider such as Postmark, SendGrid, Mailgun, Amazon SES or Resend, published in SPF, DKIM signed and DMARC aligned. W3Techs, CMS market share July 2026.
- Use a dedicated transactional provider (SendGrid, Postmark, Mailgun, Amazon SES, Resend)
- Published in SPF, DKIM signed, DMARC aligned
- Monitor bounce and complaint rates
- Separate sending domain for marketing email (mail.example.com.au)
- Never send transactional from your human mailbox
Common Mistakes
Exploited vulnerabilities became the top initial access vector for data breaches for the first time in 19 years, at 31 per cent of breaches, in the 2026 Verizon DBIR, which makes an unpatched WordPress plugin or a stale DNS record a more likely breach path than a stolen password. Verizon 2026 DBIR.
Only 27 per cent of WordPress site owners have a documented breach recovery plan, and common hosting defenses block just 12 per cent of WordPress-specific attacks, so the businesses that recover are the ones with offsite tested backups and a managed update cadence rather than a set-and-forget install. Patchstack, State of WordPress Security 2026.
Domain registered to the old web agency
Relationship breaks down, domain held hostage. Transfer into the business account.
DNS at the web host
Change web host, lose DNS. Keep DNS at a dedicated provider.
WordPress last updated 18 months ago
Every unpatched plugin is an entry point. Managed updates or replace.
No backups independent of the host
Host outage or takeover means no restore. Keep offsite copies.
MX records at the hosting cPanel
Web host death kills your mail. MX points at your mail provider directly.
SSL set to on but mixed content errors
Padlock shows but the page loads HTTP assets. Audit and fix.
Common questions
Who should own our domain name?
Should DNS be at our web host?
What security headers should our website have?
Is WordPress safe for a business website?
How often should we update WordPress plugins?
Do we need a separate provider for transactional email?
Audit Your Website Properly
We run full website and domain audits including hosting review, DNS hardening, SSL, WordPress security, and SMTP authentication.

Remote Support