Guide
7-day exposure checklist
A short sprint when the Scorecard (or a stakeholder) flagged elevated web risk. Close the obvious gaps first; book deeper remediation after.
Day 1 — Inventory
- Confirm who hosts the site, who owns DNS, and who has wp-admin / panel logins.
- Export a plugin and user list; note unused admins and abandoned plugins.
Day 2 — Access hygiene
- Remove or demote unused admins; enforce unique logins and 2FA where available.
- Rotate shared passwords; document the living access list for compliance.
Day 3 — Backups & restore
- Verify an offsite backup exists from the last 7 days.
- Ask the host (or run) a restore test to staging — “we think we have backups” is not enough.
Day 4 — Updates
- Patch core, themes, and plugins with known security releases; prefer staging first.
- Delete abandoned plugins and themes you do not need.
Day 5 — Edge & forms
- Confirm HTTPS everywhere; enable or verify WAF/CDN if offered.
- Review contact forms: spam protection, confirmation behavior, and where submissions land.
Day 6 — Content & scripts
- Flag outdated performance claims, testimonials, and third-party scripts for CCO / marketing review.
- Remove or disable tags you cannot explain to a stakeholder.
Day 7 — Decision
- Write a one-page note: remaining gaps, owner, and next 30 days.
- If the host cannot answer restore, update, or exit questions, schedule a migration consult.