Security and access
Is it a bad idea to use the same password for hosting and email?
Yes. If one is leaked, the other falls too, and your email can be used to reset almost everything else. A password manager makes unique passwords effortless, and two-factor authentication adds a second layer.
What is the safest way to give a freelancer access to my site?
Create a separate account for them with only the access they need, not your own login. Use a time-limited account where the hosting allows it, and review or remove it afterwards. Never share your registrar login. Keep a note of who has what.
What should I do first if I think my site is hacked?
Take a backup of the current state for analysis, then restore a clean version if you have one. Update everything, change all passwords, check for unknown admin users, and scan for backdoors. Tell your host; they can often see what happened.
Is it safe to use free public wifi to manage my site?
Encrypted connections protect the content, but a hostile network can still try tricks. Use HTTPS only, enable two-factor authentication, and use a VPN if the network is untrusted. Avoid doing anything sensitive on a stranger's computer.
How do I find out whether my passwords have leaked?
Check your email addresses on a breach notification service and see which sites were affected. A password manager can also warn you about reused or exposed passwords. If something leaked, change it and any site that shared it.
Do I need a separate user for each person who edits the site?
Yes. Individual accounts let you give each person only the permissions they need, see who changed what, and remove one person without affecting others. Sharing a login makes all of that impossible.
What are file permissions and which should I use?
They control who can read, write and run each file. A typical baseline on shared hosting is 755 for folders and 644 for files, with your configuration file tighter. Avoid 777, which lets anyone on the server write.