Doing it properly.
WHEN TO CHANGE ONE
You suspect it is compromised It was reused elsewhere A service was breached Someone with access has left Your computer was compromised
WHEN NOT TO
Routinely, for no reason.
Forced regular changes produce weaker passwords, because people make predictable small changes.
FROM WHERE
A clean computer.
Changing a password from a compromised machine achieves nothing.
WHAT TO CHANGE TOGETHER
If one account is compromised, anything sharing that password.
And anything that account could reset.
FOR THE DATABASE PASSWORD
Change it in cPanel and update your site configuration.
Both, or the site breaks.
AFTER CHANGING
Verify you can still log in Update any stored copy Check nothing else depended on it
WHAT BREAKS
Applications with the old password stored Email clients on devices Scheduled tasks using credentials
WHAT TO CHECK AFTERWARDS
That everything still works.