A fresh WordPress install gets several important SEO decisions wrong by default, and fixing them takes less than an hour. That is the entire scope of this article: the WordPress SEO basics that genuinely affect whether Google can find, understand and rank your pages, and nothing else. No page speed obsession, no schema plugins, no fourteen-tab settings screens.
The plugin directory is where most owners go wrong. Search for "SEO" and you will find hundreds of plugins, each promising a green light on every post. You need one, at most, and the settings below matter more than any of them.
Permalinks: the one setting you must change first
A permalink is the permanent address of a page, the bit after your domain name. Out of the box, some WordPress setups still produce URLs like ?p=123, which tells Google nothing about the page and looks untrustworthy in search results.
- Open Settings, then Permalinks in the WordPress dashboard.
- Select Post name.
- Save.
Do this before you publish anything, because changing URLs later means setting up redirects, and redirects are exactly the sort of chore that never gets done. If your site is already live with old-style URLs and has pages ranking, leave it alone or ask whoever built the site to handle the redirects properly.
Rule of thumb: a good URL reads like a short description of the page. If you cannot guess what the page is about from the address alone, the address needs work.
Pick one SEO plugin and ignore most of it
You do need a plugin for titles, descriptions and sitemaps, because core WordPress handles these poorly. Yoast SEO, Rank Math and SEOPress all do the job. The differences between them matter far less than the difference between having one and having none, so pick whichever you find least cluttered and install nothing else in the category. Two SEO plugins on one site actively conflict.
Once installed, you will use perhaps a tenth of what it offers. The features that matter are the next three sections. The features you can ignore include the content analysis traffic lights, which measure things like keyword density that Google stopped caring about years ago. A post can score red and rank well, or green and rank nowhere, because ranking is decided by whether the post answers a real question better than the alternatives. If you want the fuller picture of what actually makes a post rank, we have covered it in what is SEO content, and what makes a blog post rank.
Titles and meta descriptions: what searchers actually see
The title tag is the blue headline in Google results. The meta description is the grey text beneath it. Neither appears on the page itself, which is why owners forget them, and both decide whether a searcher clicks you or the result below you.
Your SEO plugin adds a box for each on every page and post. Three habits cover most of it:
- Keep titles under about 60 characters, lead with the words people search for, and make each one unique. "Boiler Servicing in Reading | Smith Heating" beats "Home" or "Services".
- Write descriptions under about 155 characters that say plainly what the page offers. Google sometimes replaces them with its own snippet; write them anyway, because when yours shows, it is your one sentence of advertising.
- Set the site-wide template once. Every plugin lets you define a default pattern such as "Page title | Business name", so pages you never touch still get something sensible.
Sitemaps: tell Google what exists
A sitemap is a machine-readable list of every page on your site. Your SEO plugin generates one automatically, usually at yourdomain.co.uk/sitemap.xml or sitemap_index.xml. You do not maintain it; you just tell Google where it is.
That means connecting the site to Google Search Console, Google's free tool for seeing how your site performs in search, and submitting the sitemap URL there once. The whole job takes ten minutes and we have a full walkthrough in how to set up Google Search Console. While you are in the dashboard, check one more thing: open Settings, then Reading, and make sure "Discourage search engines from indexing this site" is unticked. Web designers tick it during a build and sometimes forget to untick it at launch. A site with that box ticked is invisible to Google, however good everything else is.
Images: two habits, not a plugin
Image SEO on a small business site comes down to two habits, both free.
- Resize before you upload. A photo straight from a phone can be several megabytes. Resize it to roughly the width it will display at, typically 1200 to 1600 pixels for a full-width image, before uploading. Any free tool or even the phone's own editor can do this. Oversized images are the single most common reason small business sites load slowly.
- Fill in alt text. Alt text is a short written description of the image, entered in the media library or when inserting the image. It exists for screen readers first, and it also tells Google what the picture shows. "Replacement fuse board installed in a Victorian terrace" is useful; "IMG_4032" is not. Describe the image plainly and stop; do not stuff keywords into it.
Categories versus tags: keep it boring
Categories and tags both group posts, and both create archive pages on your site, which is where the trouble starts. A site with 20 posts and 60 tags has generated dozens of near-empty pages that dilute the useful ones.
The safe approach: use three to six categories that mirror what you sell or the topics you cover, assign each post to exactly one, and ignore tags entirely. Nobody ever lost rankings by not using tags. If your categories map onto your services, they also become the natural skeleton for a pillar and cluster content plan later, without any restructuring.
Application passwords: the setting for automated publishing
One last setting matters if you ever want software to publish to your site: a scheduling tool, a syndication service, or an automated content service. WordPress supports application passwords, which are separate credentials you issue to a specific tool so it can publish posts without knowing your real login.
- Open Users, then Profile in the dashboard.
- Scroll to Application Passwords, name the connection after the tool, and click Add.
- Copy the generated password immediately; it is shown once.
- Paste it into the tool that needs it.
The security benefit is real: you can revoke one application's access at any time without changing your own password, and the tool never sees your account credentials. If the section is missing from your profile, your host may have disabled it, and a quick support ticket usually resolves that.
The whole checklist: post-name permalinks, one SEO plugin, unique titles and descriptions, sitemap submitted to Search Console, indexing box unticked, images resized with alt text, a handful of categories and no tags. That is WordPress SEO basics done, and most sites never need more configuration than this.
Where Helio SEO fits in
Helio SEO publishes natively to WordPress using exactly the application password mechanism described above, so once your site is configured, a daily article can arrive with titles, descriptions and formatting already handled. The setup in this article is something you can comfortably do yourself in under an hour; where we help is with everything that comes after, which is publishing consistently once the foundations are in place.