Guide

WordPress vendor DD checklist for RIAs

Diligence for hosting and web vendors that touch the firm’s public site. Ask these before renewing, migrating, or adding a marketer’s preferred stack.

Business & fit

  • Legal name, support hours, and whether the vendor serves financial professionals as a focus — not only as a logo on a homepage.
  • Written scope: what is hosting vs. design vs. content vs. compliance review.
  • Subprocessors / infrastructure providers disclosed in plain language.

Access & security

  • Who can obtain panel, SFTP, and wp-admin access; MFA expectations; shared-login policy.
  • Hardening baseline: TLS, WAF/CDN, least-privilege roles, malware / integrity monitoring.
  • Update cadence with staging verification — not “auto-update and hope.”
  • Backup frequency, retention, offsite copy, and last documented restore drill.

Operations & evidence

  • Uptime expectations during market hours and named escalation path.
  • Malware clean-and-restore SLA (if claimed) and what “response” means in hours.
  • Ability to produce change history / posture docs your CCO can file.
  • Incident communication: who notifies whom, and in what channel.

Commercial & exit

  • Contract term, price predictability, and what triggers overages.
  • Exit in under 30 days with full site files, database, and DNS control — no hostage fees.
  • Migration help in and out, documented in writing.

Score your current posture, then compare vendors with eyes open.

Run the ScorecardBook a migration consult

← All resources