Shops are a higher-value target than ordinary websites.
WHY THEY ARE TARGETED
They process payments, hold customer data, and a card skimmer injected into checkout earns continuously until discovered.
THE ESSENTIALS
Two-factor authentication on every administrator account Strong unique passwords, never reused Keep WordPress, WooCommerce, the theme and every extension updated Never install nulled themes or plugins Limit administrator accounts to people who genuinely need them Never store card numbers anywhere on the account Use a hosted gateway so card details are entered on their infrastructure
ADDITIONAL LAYERS
Limit login attempts Change the admin login URL Cloudflare in front of the shop Regular malware scanning with ImunifyAV
WHAT TO WATCH FOR
Administrator accounts you did not create Files modified at times nobody was working Unexpected changes to checkout code Customers reporting card fraud after buying from you, which is the clearest sign of a skimmer
BACKUPS
Daily database backups, stored off the server. For a shop this is not optional.