Attackers scan millions of sites at a time for the same handful of mistakes. That’s good news: if you fix those, you’re no longer the easy target the scanners are looking for.
1. Out-of-date software
Content management systems like WordPress, and especially their plugins and themes, are among the most common ways in. When a security fix is released, the problem it fixes becomes public — and sites that haven’t updated are scanned for it within days.
What to do: turn on automatic updates where you can, remove plugins and themes you don’t use, and replace any plugin that’s no longer maintained.
2. Files that should never be public
Backups left in the website folder (backup.zip, site.sql), configuration files like .env that hold passwords, and the .git folder that holds a site’s full code history. If they can be downloaded, an attacker can read your passwords and code without breaking anything.
What to do: keep backups outside the website folder, and have your host block access to .git and .env.
3. Weak logins
Admin pages are tried constantly with common and stolen passwords. A short or reused password is often all it takes.
What to do: a long, unique password for every admin account, two-factor authentication, and only the accounts you actually need.
4. Encryption that isn’t complete
A padlock in the address bar isn’t the whole story. The site should send every visitor to https, turn off old encryption versions, and use HSTS so browsers never fall back to an unencrypted connection.
5. Missing browser protections
A few short settings, sent with every page, tell browsers to refuse common tricks: being framed inside another site (clickjacking), guessing file types, or running scripts from places they shouldn’t. They cost nothing and are often missing.
6. No tested backups
If the worst happens, a recent backup you’ve actually restored once is the difference between an afternoon and starting over. Keep backups off the web server, and test that they work.
Check yours
Our security scan looks for all of these from outside, the way an attacker would — without breaking into anything — and grades what it finds. Or ask for a free report.