WordPress ships with sensible defaults, but a few settings are worth a two-minute check — they affect your security, your search rankings, and how easy your site is to live with. Here are seven I check on every site.
1. Your site title and tagline
Head to Settings → General. Plenty of live sites still say "Just another WordPress site" as their tagline — and Google sometimes shows it. Fix it to something that describes your business.
2. Search engine visibility
Under Settings → Reading, there's a checkbox that asks search engines not to index your site. It's meant for sites in development — but it's shockingly common to launch with it still ticked, making you invisible on Google.
3. Permalink structure
In Settings → Permalinks, choose "Post name" so your URLs are clean and readable (/about-us, not /?p=42). Better for visitors and for SEO.
4. Your admin username
If your login is still "admin", that's half of what an attacker needs. Create a new admin account with a unique name and remove the old one.
5. Automatic updates
Enable automatic updates for minor releases and trusted plugins. Most hacks exploit known holes in outdated software — staying current closes them.
6. Comment settings
If you don't use comments, turn them off under Settings → Discussion. If you do, require approval before they appear to keep spam off your pages.
7. Your timezone and email
Set the correct timezone so scheduled posts publish when you expect, and double-check the admin email — it's where password resets and security alerts go.
I'll audit these settings and more, and hand you a tidy, secure, well-configured site. Message me to book one in.