Change the default password and default login URL immediately. The default login URL will then automatically disappear from your footer.
Install themes and plugins only from sources you trust.
Regularly update WonderCMS and always create backups.
WonderCMS supports running JavaScript anywhere. Be careful not to paste random JavaScript code.
WonderCMS supports uploading SVG's, which could also contain JavaScript code. Don't get tricked into uploading malicious SVG's. If in doubt, avoid uploading SVG file extensions.