is my website secure? the five-minute audit that answers better than any scanner
cybersecurity · Apr 2, 2026 · 5 min read
nobody sits down and hacks your small business site. what happens instead: automated scripts crawl the web testing the same five doors on every site, and they compromise the sites where a door was left open by neglect. so “is my website secure” becomes checkable in five minutes, door by door.
the five doors
- door one: the software. outdated cms, plugins, themes — the single biggest cause of small-site compromises. check: when did the site last run its updates? if the answer is “when it launched”, the door is open; the update discipline is the maintenance half of what recurring costs does a website have.
- door two: the logins. shared passwords, no two-factor, the admin account called “admin” with “summer2023”. check: can you log in from a device you do not own? then the credentials are weak or reused. a password manager and 2fa close this door for free.
- door three: the forms. contact forms that email raw input, no rate limiting, no spam protection — the bot-filling problem has its own post: how do i stop bots filling my contact form. beyond spam, forms are the front door for injection attempts; a framework-built form handles this, a hand-rolled one may not.
- door four: the transport. no https, or a certificate that expired months ago — the browser already tells you about this one, in why does my site say not secure. free to fix in minutes.
- door five: the backups that were never tested. a backup that has never been restored is a hope, not a backup. check: does a restore actually work, and how old is the newest copy? ransomware and broken plugins both end at this door.
the honest risk statement
your small site will be scanned daily and attacked opportunistically. that is not paranoia; it is the background radiation of the web — my honeypot project exists precisely because i wanted to watch it: i wrote a honeypot in go documents what shows up on any exposed port within hours. the sites that survive are not the ones nobody attacks; they are the ones whose five doors were closed when the scanner came through.
the boring habits that keep it closed
- updates on a schedule, monthly at minimum, tested after.
- 2fa on every admin login, password manager for the team.
- one page listing who holds which credential — the logins list from what you need before starting a website.
- automatic off-site backups, restored-once to prove they work.
- the uptime monitor that texts you — because knowing the site is down beats a customer knowing first.
FAQ
do i need a security product or an ssl badge?
mostly no. the five doors above are behavior, not products. security suites for small static sites are mostly invoiced peace of mind; the money is better spent on the maintenance that keeps door one shut.
how do i know if i was already hacked?
search console warnings, strange pages in google ( site:yourdomain.com ), new admin users you did not create, outbound email your host reports. and the full playbook for the worst day is in my site was hacked what do i do now.
is wordpress unsafe?
wordpress is attacked most because it is everywhere; the core is defended professionally. the risk lives in the ten abandoned plugins — which is a discipline question, not a platform verdict.
the closing thought
website security is not a product; it is five doors and a habit. close them once, check them monthly, and your site becomes what the scanners skip — not because it is hidden, but because it is closed, and there is always an easier one next door.
if you want the audit done and the habits installed:
- web development in Parma — builds where the doors come closed and stay closed
- what this site actually sends — my own site’s audit, public