All guides
Guide · 7 min read

Is my website secure?

Most small-business websites aren’t attacked by someone who chose them. They’re found by automated scans looking for well-known weaknesses. Here are the ones we see most, and how to close them.

Attackers scan millions of sites at a time for the same handful of mistakes. That’s good news: if you fix those, you’re no longer the easy target the scanners are looking for.

1. Out-of-date software

Content management systems like WordPress, and especially their plugins and themes, are among the most common ways in. When a security fix is released, the problem it fixes becomes public — and sites that haven’t updated are scanned for it within days.

What to do: turn on automatic updates where you can, remove plugins and themes you don’t use, and replace any plugin that’s no longer maintained.

2. Files that should never be public

Backups left in the website folder (backup.zip, site.sql), configuration files like .env that hold passwords, and the .git folder that holds a site’s full code history. If they can be downloaded, an attacker can read your passwords and code without breaking anything.

What to do: keep backups outside the website folder, and have your host block access to .git and .env.

3. Weak logins

Admin pages are tried constantly with common and stolen passwords. A short or reused password is often all it takes.

What to do: a long, unique password for every admin account, two-factor authentication, and only the accounts you actually need.

4. Encryption that isn’t complete

A padlock in the address bar isn’t the whole story. The site should send every visitor to https, turn off old encryption versions, and use HSTS so browsers never fall back to an unencrypted connection.

5. Missing browser protections

A few short settings, sent with every page, tell browsers to refuse common tricks: being framed inside another site (clickjacking), guessing file types, or running scripts from places they shouldn’t. They cost nothing and are often missing.

6. No tested backups

If the worst happens, a recent backup you’ve actually restored once is the difference between an afternoon and starting over. Keep backups off the web server, and test that they work.

Check yours

Our security scan looks for all of these from outside, the way an attacker would — without breaking into anything — and grades what it finds. Or ask for a free report.

See what an attacker would see.

Tell us your website and we’ll send a free report: what’s working, what isn’t, and what to fix first. Or just call — we’re happy to talk it through.

Call 1-236-425-4400