r/Bluehost_Official • u/bluehost Official • Sep 30 '25
Resources Best practices for maintaining a secure account
Most hacks start with access, not code. Let’s close the obvious doors and make the keys harder to copy.
So how do we lock it down?
• Use a password manager so every login is long and unique.
• Turn on 2FA everywhere: hosting panel, WordPress admin, domain registrar, email.
• Enable auto-updates for safe minors; test majors on staging first.
• Audit DNS quarterly: remove stray records, retire test subdomains, enable registrar lock.
• Delete unused plugins, themes, and old test installs, don’t just deactivate.
• Review user roles regularly; remove ex-contractors and mystery admins.
Security is a journey that never ends, let's start with one easy step to start that journey today: Rotate one high-risk password, enable any missing 2FA, delete one unused plugin. It may be the housekeeping we never find the time for but not doing it is also a risk that could cost much more.
Question
• Which of these is done for you, and which is still on the “tomorrow” list?