Use HTTPS to protect user data and ensure that your site is not flagged as “not secure” by web browsers. Once secured check that all internal links and references use https.
Practice least privilege
Limit access permissions to your website's CMS to the minimum necessary. Grant only essential privileges to users, especially for administrative roles. This principle helps prevent unauthorized access and misuse.


