Guide
WordPress vendor DD checklist for RIAs
Diligence for hosting and web vendors that touch the firm’s public site. Ask these before renewing, migrating, or adding a marketer’s preferred stack.
Business & fit
- Legal name, support hours, and whether the vendor serves financial professionals as a focus — not only as a logo on a homepage.
- Written scope: what is hosting vs. design vs. content vs. compliance review.
- Subprocessors / infrastructure providers disclosed in plain language.
Access & security
- Who can obtain panel, SFTP, and wp-admin access; MFA expectations; shared-login policy.
- Hardening baseline: TLS, WAF/CDN, least-privilege roles, malware / integrity monitoring.
- Update cadence with staging verification — not “auto-update and hope.”
- Backup frequency, retention, offsite copy, and last documented restore drill.
Operations & evidence
- Uptime expectations during market hours and named escalation path.
- Malware clean-and-restore SLA (if claimed) and what “response” means in hours.
- Ability to produce change history / posture docs your CCO can file.
- Incident communication: who notifies whom, and in what channel.
Commercial & exit
- Contract term, price predictability, and what triggers overages.
- Exit in under 30 days with full site files, database, and DNS control — no hostage fees.
- Migration help in and out, documented in writing.
Score your current posture, then compare vendors with eyes open.