Safety is extremely necessary for all web sites, however arguably much more so for ecommerce shops. In spite of everything, you’re accumulating buyer data like names, addresses, and fee information.
And whereas safety measures are constructed into WordPress and WooCommerce, there are just a few basic items retailer house owners ought to do to maintain their prospects, crew, and knowledge secure within the occasion of worst-case situations.
On this information to WooCommerce safety, we’ll deal with the steps you need to take to guard your retailer and your prospects, in no explicit order. We’ll additionally have a look at among the finest WooCommerce safety plugins to maintain many of the laborious work. Let’s dive in!
Why you need to safe your WooCommerce retailer
It’s in all probability no shock that you need to shield your WooCommerce retailer.
However let’s check out just a few causes that safety must be a high precedence:
1. Defend your laborious work
You’ve put a variety of work into your website’s design, performance, and content material. The very last thing you need is to lose that work to a safety breach. In case your WooCommerce web site isn’t correctly protected and backed up, you can be taking a look at a variety of misplaced time, cash, and peace of thoughts to get well after a hack.
2. Hold buyer data secure
While you run an ecommerce enterprise, you’re capturing buyer knowledge like addresses, names, telephone numbers, and bank card numbers. Your patrons are counting on you to safeguard that data and hold it from falling into the flawed palms.
3. Keep away from authorized and monetary issues
In case your prospects’ data is compromised, you can probably face actual authorized and monetary issues that, on the very least, may very well be annoying and time-consuming to resolve.
4. Keep your model popularity
In case your web site goes down or is in any other case compromised, it might breach the belief you’ve constructed with prospects and followers.
5. Defend search engine rankings
Your web site can take a fall within the rankings after a hack, particularly in case you’re not capable of get well shortly. In spite of everything, engines like google don’t need to ship customers to a compromised website!
In abstract, WooCommerce safety is necessary to guard each you and your prospects. This isn’t the place for shortcuts!
Learn how to safe your WooCommerce retailer
Now that we’ve mentioned why safety is so necessary, let’s check out some WooCommerce safety suggestions you could implement as we speak.
1. Select a safe internet hosting supplier
Your host shops your web site content material, WordPress core recordsdata, and database, which permits them to be seen by individuals everywhere in the world. It’s primarily the inspiration of website safety — your host ought to have measures in place to guard your recordsdata and database from hackers and malware.
Ideally, you need to discover a host that understands WordPress and WooCommerce safety nicely and clearly states what they do to prioritize your retailer’s security.
Search for options like:
- SSL certificates, which shield buyer knowledge akin to addresses and telephone numbers
- Backups, in order that if something does go flawed, you possibly can restore your website in full
- Assault monitoring and prevention, so that you just’ll know immediately if malware is present in your recordsdata or database
- A server firewall, which prevents hackers from accessing your recordsdata
- 24/7 entry to help, simply in case you want it
- Up-to-date server software program, like PHP and MYSQL
- The flexibility to isolate malicious recordsdata, so {that a} virus or malware can’t transfer to different websites or folders on the identical server

The hosts you consider ought to have a web page about safety on their website, so you need to be capable to affirm whether or not or not your host gives these options. If it’s important to dig deeper or ship emails to get solutions, it is perhaps an indication to steer clear.
You must also take the time to learn opinions from current prospects. Search for suggestions particular to safety points — good or dangerous. That is usually among the finest indications of a high quality host.
Need extra data? This listing of internet hosting suppliers for WooCommerce is a superb place to begin.
2. Require robust passwords for person accounts
Whereas security may begin along with your host, it’s as much as you to observe via. So, make sure to select safe passwords for any and all accounts related along with your WooCommerce retailer — together with accounts in your WordPress website, internet hosting device, and area title supplier.

This implies:
- Utilizing distinctive passwords for every of your accounts, particularly WordPress admin accounts.
- Making a password with a mix of capital letters, lowercase letters, numbers, and symbols.
- Avoiding phrases, anniversaries, birthdays, or different phrases that may very well be simply guessed.
- Prioritizing size — the longer and extra advanced the password, the tougher it’s to crack.
Frightened about whether or not or not your passwords are actually safe?
Worry not: WordPress has a built-in safe password generator that makes it straightforward to create advanced, hard-to-guess combos.
However remembering tough passwords could also be difficult. One nice resolution is a password supervisor like 1Password. These instruments safely retailer your passwords and auto-fill them securely in your favourite websites.
Additionally, just remember to lengthen your password necessities to any and all customers which have entry to your WordPress web site, particularly for directors. You need to use a plugin like Password Coverage Supervisor to set password guidelines, like requiring safe passwords and having customers reset theirs once in a while.
3. Allow two-factor authentication (2FA)
If somebody good points entry to your e-mail or one other account, they may be capable to collect sufficient data to reset your password and log in.
Two-factor authentication, mostly abbreviated as 2FA, is a incredible approach to safeguard your on-line accounts in opposition to undesirable intruders. 2FA depends on a second step — usually your smartphone — to validate logins and confirm that you’re the proprietor.
You must ideally allow 2FA for every admin account. Underneath regular circumstances, a person who efficiently good points entry to your e-mail account might probably discover the login data on your WooCommerce retailer and different accounts.
However with 2FA, they received’t have the power to bodily validate the logins by way of your cell machine.
It’s true that including this second step additionally provides somewhat extra time to your login course of. But it surely’s completely definitely worth the peace of thoughts realizing that your delicate knowledge is secure.

You’ll be able to implement two-factor authentication at no cost with Jetpack, and even select to make it a requirement for all customers in your web site.
4. Block brute pressure assaults
Brute pressure assaults happen when hackers use bots to guess 1000’s of username/password combos till they lastly give you the correct one. Not solely can this permit hackers to entry your website, it might probably additionally negatively influence your load time because of the enhance in retailer site visitors. Stopping brute pressure assaults firstly may be extremely efficient for sustaining your website’s safety.

Jetpack’s free brute pressure assault safety function is an effective way to cease them of their tracks. It robotically blocks malicious IP addresses earlier than they even attain your website, so that you don’t have to fret about them.
You can too view the entire malicious assaults that the device has blocked — a median of 5,193 per website!
You can too use a WordPress plugin to restrict login makes an attempt in your website. Since most respectable customers received’t want various tries to log in, this may be one other efficient safety in opposition to brute pressure assaults. For instance, you may determine to dam somebody who tries and fails to login 3 times inside a sure time interval.
5. Recurrently scan for malware
Malware is software program developed with a malicious goal, and it’s one of the vital widespread types of hacking. It could actually accomplish a wide range of duties, together with redirecting website guests to suspicious web sites and skimming prospects’ bank card data.
If a hacker does handle to realize entry to your website or server and inject malware, you’ll need to know instantly. Caring for this as shortly as attainable reduces the probability of you or your prospects struggling hurt, and helps you get again up and operating shortly.

However you possibly can’t manually monitor your website for malware always! That’s the place a malware scanning resolution like Jetpack Scan is available in. It’s like having somebody guard your website 24/7, recurrently trying to find malware and vulnerabilities.
It sends you an instantaneous alert if malware is discovered in your website so you possibly can troubleshoot and repair nearly all of recognized threats with one click on.
6. Forestall remark and speak to kind spam
Spam can seem in a wide range of methods in your WordPress website, from weblog put up feedback to product opinions and even contact kind submissions.
And it’s extra than simply an annoyance for guests — dangerous actors can use spam to ship prospects to malicious web sites, use your web site to control their search engine rankings (whereas tanking yours), and use your contact types to trick your website guests.
Your first step to stopping spam is in your WordPress settings. In your WordPress dashboard, go to Settings → Dialogue.
Right here, you can also make adjustments like:
- Requiring authors to log in earlier than submitting a remark
- Enabling a notification by way of e-mail every time somebody leaves a remark
- Setting guide approval for each remark left in your website
- Robotically marking feedback as spam based mostly on sure standards, like variety of hyperlinks and sure phrases

You can too edit your settings for product opinions by going to WooCommerce → Settings → Merchandise in your WordPress dashboard. For instance, you possibly can solely permit verified product house owners to go away opinions.

However your greatest protection in opposition to spam is with a plugin like Akismet. It prevents you from having to manually evaluate each remark and kind submission you might have in your website by robotically eliminating spam.
Akismet’s spam filter is 99.9% correct, and doesn’t use annoying and difficult options like CAPTCHAs, preserving website guests completely happy and engaged.
7. Use an exercise log
With a WordPress exercise log like Jetpack, you possibly can control every thing that occurs in your website — from up to date pages and new merchandise to person logins — together with who carried out every motion and when.

How can this enable you to?
It means that you can determine something suspicious which may have occurred, like a safety device being deleted, a printed web page that you just had nothing to do with, or a person login that you just weren’t conscious of. It additionally allows you to maintain different website customers accountable for the actions they take in your WooCommerce web site.
8. Replace your website software program
The method of updating WordPress, WooCommerce, and your plugins or extensions is completely crucial. Updates are launched for a motive, and so they usually make your website safer. By ignoring them, you can be placing your self — and your prospects — in danger.
In reality, 52% of all WordPress vulnerabilities are attributable to out-of-date plugins. And this drawback may be very straightforward to unravel!

The easiest way to method this? Put aside an everyday time to evaluate your updates, make a backup, and deploy these updates to your website. For those who don’t need to fear about it, you too can activate the auto-update function inside WordPress.
9. Use an online utility firewall
An internet utility firewall (WAF) acts like a 24/7 guard on the door of your web site. It opinions every customer behind the scenes, and decides to permit or disallow them based mostly on sure guidelines.
Jetpack Firewall is one useful gizmo that you need to use. Whereas it begins with a database filled with recognized threats, it additionally adapts in actual time based mostly on what’s taking place in your website. It robotically adjusts guidelines when it senses a risk, so your website is all the time protected.

You can too manually block IP addresses if of a particular risk, and allowlist sure ones in order that directors are by no means locked out.
10. Test and regulate your FTP settings
FTP (file switch protocol) is used to switch recordsdata between two gadgets. By your internet hosting supplier, you possibly can create FTP accounts, which let you join out of your laptop to your web site server.
You need to use these to make adjustments to your web site recordsdata, or share entry to your website with a contractor or crew member with out giving them your internet hosting login data.
But when a malicious actor accesses these accounts, they’d be capable to make any variety of adjustments to your website.
Limiting the permissions on these accounts can scale back and even fully get rid of the potential for harm.
Be sure that solely your FTP account can entry the next folders:
- The basis listing
- wp-admin
- wp-includes
- wp-content
For extra particulars on locking down your FTP, take a look at this part of the WordPress Codex. Your host must also have the opportunity that can assist you take these precautions.
11. Recurrently again up your WooCommerce retailer
In case your website is ever hacked, a backup is the quickest and greatest approach to get a clear model up and operating once more. However not simply any backup plugin will do the job.
You need one which saves your website often (ideally in actual time), shops a number of copies, and retains these copies fully separate out of your server, in case that’s compromised too.
And, after all, you’ll additionally want a approach to restore a backup shortly, even when your website is inaccessible.

Jetpack VaultPress Backup is a superb resolution that checks all of these bins. Listed here are some causes it’s the most effective WooCommerce backup plugin:
- It takes real-time backups, which happen each time an motion (bought product, up to date web page, and so on.) happens in your website.
- You by no means have to fret about dropping order data. Whether or not you restore a backup from 5 minutes in the past or 5 days in the past, your whole order data is saved as much as the minute.
- You’ll be able to restore with only one click on. Don’t fear a few time-consuming, tough restore course of. Merely discover the date and time you need to restore to and click on a button, even when your web site is totally down.
- It allows you to use an exercise log to revive a backup. Filter via your website exercise for a particular motion that occurred, and restore to some extent instantly earlier than it came about.
- It saves redundant copies of your web site on the identical, safe servers that WordPress.com makes use of.
- You’ll be able to restore your web site from practically wherever with the Jetpack Cell app.
12. Get an SSL certificates
A safe socket layer (SSL) certificates encrypts the data transmitted by prospects in your ecommerce web site, akin to contact kind submissions and bank card data. Not solely is it completely obligatory for the safety of your ecommerce retailer, it’s additionally an necessary issue for search engine optimization.
There are a number of methods to get an SSL certificates, however most hosts embody them with their plans. If, for some motive, yours doesn’t, you possibly can all the time use the free, open-certificate supplier, Let’s Encrypt, to get one for free of charge.

Be taught extra about SSL certificates.
13. Overview your person permissions
Whereas requiring robust passwords and two-factor authentication are glorious methods to safe person accounts, there’s another step you need to take: reviewing person permissions. By default, each WordPress and WooCommerce embody a variety of person roles that every include set permissions.
For instance, the Admin position is probably the most highly effective, and contains full entry to each component of your web site. A Store Supervisor, nonetheless, simply has the capabilities wanted to handle your on-line retailer, with out the power to edit recordsdata and code. You’ll be able to evaluate the entire person roles right here.

Take the time to undergo every person and ensure they’ve the minimal permissions essential to do their job. For those who don’t work with somebody anymore, contemplate eradicating their account totally.
Be aware: When deleting a person account, you’ll get the choice to take away their content material or attribute it to a different person. Make sure that to attribute it to a different account, or it is going to be completely deleted out of your website!
What’s the most effective WooCommerce safety plugin?
A high-quality WooCommerce safety plugin is the very best approach to get began with securing your website. And Jetpack Safety — which additionally has an official WooCommerce extension — is a superb resolution for shops of any measurement. It was constructed particularly for WordPress, by the crew behind WordPress.com.
Whereas we’ve talked about a few of its performance, right here’s a listing of the safety features that make it one of many WooCommerce safety plugins:
- Actual-time backups: Your website is saved in actual time, so that you just all the time have the most recent model of your recordsdata, orders, and extra. You’ll be able to restore a backup even when your web site is totally down from a desktop or the cell app.
- Malware scanning: Profit from automated scanning for malware and vulnerabilities that put your website in danger. You can too use this device to repair nearly all of recognized threats with only one click on.
- Downtime monitoring: Know instantly in case your website goes down — a typical indication of a hack — so you will get it again up and operating shortly.
- Anti-spam instruments: Implement spam safety for remark and speak to types.
- An exercise log: Hold observe of each motion taken in your website, and study who carried out each and when it came about.
- An internet site firewall: Defend your web site from dangerous actors and unsavory site visitors.
- Brute pressure assault safety: Forestall brute pressure assaults that may compromise your web site and buyer data.
- Two-factor authentication: Add an additional layer of safety in your login web page by requiring a one-time code along with a password.

You’ll additionally profit from world-class help from true WordPress specialists. Be taught extra about Jetpack Safety.
Need simply a few of these safety features? You’ll be able to set up lots of them as particular person plugins, and a few, like brute pressure assault safety, are fully free. See bundle choices.
FAQs about WooCommerce safety
Nonetheless have questions? Let’s reply some widespread ones.
Can a WooCommerce web site be hacked?
Identical to any web site, it’s attainable for WooCommerce shops to be compromised. Nonetheless, WordPress and WooCommerce builders always work on bettering the software program and preserving WooCommerce safe.
For those who use trusted instruments (like hosts, themes, and plugins) and implement the most effective WooCommerce safety suggestions mentioned on this article, your website must be in glorious form.
Which SSL certificates is the most effective for WooCommerce web sites?
There are a number of various kinds of SSL certificates, together with:
Area-validated (DV)
This merely requires that you just show possession of your area title for validation. DV certificates are probably the most inexpensive and commonest forms of SSL certificates.
Group-validated (OV)
OV certificates ask you to offer additional details about your group. This makes it a costlier however extra credible choice.
Prolonged-validated (EV)
This requires even additional data and documentation to show your id. It’s the most costly and credible sort of certificates.
Wildcard certificates
These let you shield a limiteless variety of subdomains below a single area.
The most effective one on your on-line enterprise actually depends upon your particular wants. A DV certificates is a superb place to begin and will probably be ample for almost all of shops. Nonetheless, as you develop, chances are you’ll need to improve to an OV or EV certificates to additional shield your knowledge and bolster your popularity as a model.
What ought to I do if my WooCommerce website is hacked?
In case your on-line retailer has been hacked, take a deep breath and take the next steps:
1. Decide what occurred.
If in any respect attainable, strive to determine how the hack occurred. For those who’re utilizing an exercise log, this could make the method a lot simpler. Your host or developer may additionally be capable to present steerage and data.
2. Scan and restore your website.
Use a WordPress safety plugin like Jetpack Scan to test your web site for malware. If attainable, use the one-click fixes obtainable with Jetpack to take away and restore the issue. You can too manually take away malware or rent a developer to assist.
3. Restore a backup.
For those who’re not capable of take away the malware or just aren’t positive in case your web site is totally clear, restore a backup. For those who’re utilizing Jetpack VaultPress Backup, you possibly can get well your whole order and buyer data, even in case you’re restoring a backup from just a few days in the past. And you are able to do so in case your website is inaccessible.
4. Reset all passwords.
As soon as your web site is clear, reset your whole passwords. This contains your WordPress person accounts, cpanel, internet hosting supplier, FTP, database, and some other accounts related along with your website. If there are any suspicious customers, take away them instantly.
5. Resubmit your website to Google.
In case your WooCommerce website was blocklisted by Google, resubmit your web site when you’re sure that it’s clear. Be taught extra about Google blocklisting.
6. Implement extra safety measures.
Now, observe the WooCommerce safety suggestions on this article to safe your website even additional and stop future hacks.
For those who’re not comfy dealing with this your self, you possibly can rent a trusted WooExpert to wash and restore your on-line retailer in full.
Need extra data? Learn to acknowledge a hack and methods to repair it in this text from Jetpack.
Make WooCommerce safety a precedence
It’s straightforward to lose sight of safety in all of the hustle and bustle of launching or managing your retailer, nevertheless it’s not one thing you need to take evenly. Maintaining your prospects’ knowledge secure must be a high precedence from the very starting.
By following these easy steps, you’ll create the groundwork for a secure, reliable on-line enterprise that’s well-protected within the uncommon occasion of an assault.