Guide

7-day exposure checklist

A short sprint when the Scorecard (or a stakeholder) flagged elevated web risk. Close the obvious gaps first; book deeper remediation after.

Day 1 — Inventory

  • Confirm who hosts the site, who owns DNS, and who has wp-admin / panel logins.
  • Export a plugin and user list; note unused admins and abandoned plugins.

Day 2 — Access hygiene

  • Remove or demote unused admins; enforce unique logins and 2FA where available.
  • Rotate shared passwords; document the living access list for compliance.

Day 3 — Backups & restore

  • Verify an offsite backup exists from the last 7 days.
  • Ask the host (or run) a restore test to staging — “we think we have backups” is not enough.

Day 4 — Updates

  • Patch core, themes, and plugins with known security releases; prefer staging first.
  • Delete abandoned plugins and themes you do not need.

Day 5 — Edge & forms

  • Confirm HTTPS everywhere; enable or verify WAF/CDN if offered.
  • Review contact forms: spam protection, confirmation behavior, and where submissions land.

Day 6 — Content & scripts

  • Flag outdated performance claims, testimonials, and third-party scripts for CCO / marketing review.
  • Remove or disable tags you cannot explain to a stakeholder.

Day 7 — Decision

  • Write a one-page note: remaining gaps, owner, and next 30 days.
  • If the host cannot answer restore, update, or exit questions, schedule a migration consult.

Re-score after the sprintBook a web risk call

← All resources