Account Security Best Practices
Portal Security
- Use a strong, unique password — Don't reuse passwords from other services
- Never share your credentials — Our team will never ask for your portal password
- Log out after each session — Especially on shared computers
- Keep your email secure — Your email is the key to password resets
Website Security
- Keep software updated — WordPress core, plugins, and themes should always be on their latest versions
- Remove unused plugins and themes — Each one is a potential attack surface
- Use strong admin passwords — At least 12 characters with mixed case, digits, and symbols
- Limit admin accounts — Only grant administrator access to people who genuinely need it
- Avoid nulled/pirated plugins — These are the most common malware infection vector we encounter
Critical: Nulled (pirated) plugins and themes are the #1 source of malware infections in the cases we handle. Always use legitimate, licensed software.