Website security is essential to the WordPress admin because if we are attacked, we have sensitive information stored in our admin panels that is at risk of being used against us. Hackers can add harmful code and redirect users to unsafe websites which will look bad in our names. We can protect our websites through strong passwords. Passwords should be hard to guess and complex, with multiple letters and combinations of characters. That way, it is way more difficult for people to gain access to our websites. SSL’s also are very helpful because they encrypt connection between the website and visitors. SSL uses HTTPS, which is more secure as well. Security plugins as well also provide great protection, and I am using Wordfence Security, which can be found in WordPress plugins. Wordfence is great because when something needs attention, it can block suspicious visitors and protect the website from common attacks, adding additional protective layers.
Users
I would assign different roles depending on the job that the person needs to execute. Obviously, granting access and full access to everyone is not optimal because the risk of security is quite high, and giving everyone some sort of administration also causes imbalances in power and imbalances in what players can do. Giving administrator to someone would be someone that I would trust with the well-being of my website. An editor would be able to edit and publish different posts, but this role would not be as important as an administrator since they lack certain abilities that administrators have. Authors would be able to write and publish as well, and I would use this for those who contribute regularly to their articles or blog posts. Lastly, subscribers would have the most limited access, as they should not be accessing my website if I do not have any prior knowledge of them or have spoken to them before. Trusting strangers with my website is not safe.