If you take payments, the security expectations are higher and the consequences of a compromise are more serious.
THE FUNDAMENTALS
Use a hosted payment gateway such as Paystack, Flutterwave or Stripe, where the card details are entered on the provider's page or in their secure iframe. Do not build your own card form. Never store card numbers, CVV codes or full track data anywhere on your hosting account. There is no legitimate reason to, and doing so brings compliance obligations you almost certainly do not want. Keep the entire site on HTTPS, not only the checkout. Keep the store software and payment plugin updated. Payment extensions are a high-value target.
ADDITIONAL CONTROLS
Enable two-factor authentication on every store administrator account. Restrict administrator access to the people who genuinely need it. Review order and user lists regularly for anomalies. Keep off-server backups, and test restoring them. Monitor for unexpected changes to checkout pages. Card-skimming scripts injected into checkout code are a common attack and are designed to be invisible.
If you are subject to formal PCI DSS obligations, discuss your requirements with your payment provider and consider whether shared hosting is the right environment. Open a ticket and we will advise.