1. Install a premium or paid theme.
2. Install a “framework” or theme engine.
3. Install premium plug-ins.
4. Install no-longer supported themes or plug-ins. If the last update is over six months on WordPress.org you are asking for it.
5. Install a premium or paid theme.
6. Hire someone to set it up, and don’t ask for documentation on how they changed WordPress.
7. Never go to the Update section in wp-admin. This is the best way to have your site hacked.
8. Leave unused plug-ins active.
9. Put as many Share/Facebook/Twitter/etc widgets as you can on pages. Make sure their Javascript code is on pages that don’t even show them. This is a key to decreasing your Google QS and really dropping in the SERPs.
10. Install a premium or paid theme.