WordPress ships with sensible defaults, but a few settings are worth a two-minute check — they affect your security, your search rankings, and how easy your site is to live with. Here are seven I check on every site.

1. Your site title and tagline

Head to Settings → General. Plenty of live sites still say "Just another WordPress site" as their tagline — and Google sometimes shows it. Fix it to something that describes your business.

2. Search engine visibility

Under Settings → Reading, there's a checkbox that asks search engines not to index your site. It's meant for sites in development — but it's shockingly common to launch with it still ticked, making you invisible on Google.

Check this first if you're not showing up in search. It's the number-one reason a new site gets zero Google traffic.

3. Permalink structure

In Settings → Permalinks, choose "Post name" so your URLs are clean and readable (/about-us, not /?p=42). Better for visitors and for SEO.

4. Your admin username

If your login is still "admin", that's half of what an attacker needs. Create a new admin account with a unique name and remove the old one.

5. Automatic updates

Enable automatic updates for minor releases and trusted plugins. Most hacks exploit known holes in outdated software — staying current closes them.

6. Comment settings

If you don't use comments, turn them off under Settings → Discussion. If you do, require approval before they appear to keep spam off your pages.

7. Your timezone and email

Set the correct timezone so scheduled posts publish when you expect, and double-check the admin email — it's where password resets and security alerts go.

Want a full health check?
I'll audit these settings and more, and hand you a tidy, secure, well-configured site. Message me to book one in.