It sounds basic, but weak passwords remain one of the single most common ways hosting accounts and websites get compromised — this is worth getting right, not treating as an afterthought.
What Makes a Password Weak
- Short passwords, especially under 12 characters
- Common words, names, or predictable patterns
- Reusing the same password across multiple accounts
- Anything based on publicly guessable information (business name, phone number, birthdate)
What Makes a Password Strong
- Long — aim for at least 16 characters where the system allows it
- A genuinely random mix of letters, numbers, and symbols, not a predictable substitution pattern
- Unique to that one account, never reused elsewhere
Use a Password Manager
Trying to remember unique, complex passwords for every account is unrealistic without help. A password manager generates and stores strong, unique passwords so you don't need to memorise them.
Add Two-Factor Authentication
Even a strong password can be compromised through phishing or a data breach elsewhere. Two-factor authentication adds a critical second layer of protection.
Change Passwords If You Suspect Any Compromise
If you've shared access with someone who no longer needs it, or suspect any account may have been exposed, changing your password immediately is the safest response.
Where This Matters Most
Your hosting control panel, WordPress admin, FTP/database access, and domain registrar account are the highest-value targets — prioritise strong, unique passwords there above all else.