Most website compromises we investigate start with a weak or reused password on an admin account. Bots try common passwords against login pages continuously, at a rate no human could match. Getting this right removes the single largest risk you control.
What makes a password strong
Length matters far more than complexity. A long passphrase of four or five unrelated words is stronger and easier to remember than a short string full of symbols. Aim for at least sixteen characters.
- Unique to that one account. Never reused anywhere else, ever.
- Not based on your company name, domain, brand, birth year or phone number.
- Not a dictionary word with predictable substitutions. Attackers test those first.
- Not a keyboard pattern.
Use a password manager
You cannot remember dozens of unique long passwords, and you should not try. Use a reputable password manager, let it generate random passwords, and remember exactly one strong master password. This is the single most effective change most businesses can make.
Usernames matter too
Do not use admin, administrator, or your domain name as a username. Half the attack traffic against a WordPress site targets those names specifically. Use something unrelated to your brand.
When to change a password
- Immediately if a staff member with access leaves.
- Immediately if you suspect a device was infected or a phishing link was clicked.
- If the password was ever shared over email, chat or a phone call.
- If it appears in a known breach. Password managers flag this automatically.
Routine forced rotation every ninety days is no longer recommended. It pushes people toward predictable variations. Long unique passwords plus two factor authentication is the better model.
Do not send passwords to us in plain text
If you need to give us access, create a separate account for us rather than sharing yours, and send credentials through a secure sharing method as described in our safe file sharing article.
If you would like us to review the accounts on your site, reply to your email thread or contact [email protected].