{"id":18372,"date":"2026-09-29T21:16:34","date_gmt":"2026-09-29T18:16:34","guid":{"rendered":"https:\/\/www.hyyat.com\/knowledgebase\/protect-website-from-hacking\/"},"modified":"2026-09-29T21:16:34","modified_gmt":"2026-09-29T18:16:34","password":"","slug":"protect-website-from-hacking","status":"publish","type":"docs","link":"https:\/\/www.hyyat.com\/en\/knowledgebase\/protect-website-from-hacking\/","title":{"rendered":"How to Keep Your Website Secure: Practical Tips to Prevent Hacking"},"content":{"rendered":"<div class=\"hy-tldr\" style=\"background:#f6f7fb;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:0 0 20px;line-height:1.8\"><strong>In short:<\/strong> The most important steps to protect your site: long, unique passwords (15+ characters) for every account, SSL on all pages, keeping your CMS, plugins and themes updated, removing unused plugins, regular backups, a trusted security plugin, and two-factor authentication where possible.<\/div>\n<p>Keeping a website secure can be hard. Many factors can lead to a site being hacked, and not all of them are related to the server or the hosting company. Here are the things you can do to reduce the risk as much as possible.<\/p>\n<h2>Use strong passwords<\/h2>\n<p>Use at least 15 characters with a mix of letters, numbers and symbols, and make them random. A password generator or a password manager makes this easy.<\/p>\n<h2>Use unique passwords<\/h2>\n<p>Never reuse a password on another account. If one site&#8217;s database leaks or a password is guessed, your other accounts stay safe.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/01\/password.jpg\" alt=\"Use strong, unique passwords\" \/><\/p>\n<h2>Change passwords when in doubt<\/h2>\n<p>If you think a password may have been exposed, change it right away. Because you do not reuse passwords, you only need to change it in one place.<\/p>\n<h2>Use SSL everywhere<\/h2>\n<p>Without SSL, data sent from pages with logins or sensitive information can be read on the way. SSL encrypts the connection between the visitor and the server. See <a href=\"https:\/\/www.hyyat.com\/en\/knowledgebase\/enable-https-on-your-website\/\">how to enable HTTPS and SSL<\/a>.<\/p>\n<h2>Keep your software updated<\/h2>\n<p>New security problems are found every day. Keep your website software, plugins and themes up to date, following each product&#8217;s documentation. Running old, vulnerable versions is the single biggest reason websites get hacked. Also avoid software with a poor security reputation.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/01\/FirefoxFake.png\" alt=\"Keep your website software updated\" \/><\/p>\n<h2>Use a well-reviewed security plugin<\/h2>\n<p>If your platform supports plugins, install a trusted security plugin, for example a well-known WordPress security plugin, or Admin Tools for Joomla.<\/p>\n<h2>Follow the official hardening guides<\/h2>\n<p>Most platforms publish a security or hardening guide with best practices, for example &#8220;Hardening WordPress&#8221; in the WordPress documentation, and the security guides for Joomla, Magento and WHMCS. Search for your application&#8217;s name plus &#8220;security&#8221;.<\/p>\n<h2>Server security<\/h2>\n<p>If you have a VPS or server, its security is your responsibility; our server management service can apply security hardening for you. On our shared hosting, Hyyat Host manages server security: we keep server software updated, use CloudLinux to isolate customer sites from each other, run a firewall with brute force protection on every server, and make it easy to use Cloudflare to block more attacks. See also <a href=\"https:\/\/www.hyyat.com\/en\/knowledgebase\/brute-force-protection\/\">brute force protection<\/a> and <a href=\"https:\/\/www.hyyat.com\/en\/knowledgebase\/wordpress-vulnerability-scan-wp-toolkit\/\">scanning WordPress for vulnerabilities<\/a>.<\/p>\n<p class=\"hy-svc-link\" style=\"background:#fff5f7;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:20px 0;line-height:1.8\"><strong>Related service:<\/strong> <a href=\"https:\/\/www.hyyat.com\/en\/wordpress-hosting\/\">Secure WordPress hosting from Hyyat Host<\/a> with free SSL, brute force protection and 24\/7 support.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: The most important steps to protect your site: long, unique passwords (15+ characters) for every account, SSL on all pages, keeping your CMS, plugins and themes updated, removing unused plugins, regular backups, a trusted security plugin, and two-factor authentication where possible. Keeping a website secure can be hard. Many factors can lead to [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_eb_attr":"","inline_featured_image":false,"wprm-recipe-roundup-name":"","wprm-recipe-roundup-description":"","_templately_pack_id":"","_templately_imported_at":"","_templately_source":"","_templately_import_session_id":"","footnotes":""},"doc_category":[2219],"doc_tag":[],"class_list":["post-18372","docs","type-docs","status-publish","hentry","doc_category-2219"],"year_month":"2026-10","word_count":409,"total_views":"1","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"ahmed fathy","author_nicename":"ahmed-fathy","author_url":"https:\/\/www.hyyat.com\/en\/author\/ahmed-fathy\/"},"doc_category_info":[{"term_name":"\u062d\u0645\u0627\u064a\u0629 \u0645\u0648\u0627\u0642\u0639 \u0627\u0644\u0627\u0646\u062a\u0631\u0646\u062a","term_url":"https:\/\/www.hyyat.com\/kb\/%d8%ad%d9%85%d8%a7%d9%8a%d8%a9-%d8%a7%d9%84%d9%85%d9%88%d8%a7%d9%82%d8%b9\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/comments?post=18372"}],"version-history":[{"count":0,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18372\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/media?parent=18372"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_category?post=18372"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_tag?post=18372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}