Is my website secure? A 15-minute check for business owners
Six things you can check on your own website this afternoon, without touching code, and the five questions to ask whoever looks after it.
You probably did not build your website yourself. Someone set it up a few years ago, it has been running ever since, and as long as the contact form sends emails and the shop takes orders, you have no reason to look under the bonnet.
Most owners only think about security after something goes wrong: a customer mentions a strange redirect, Google shows a warning, or the hosting company suspends the account. By then the fix costs more and the damage is already done.
You can catch a lot of problems earlier without any technical knowledge. Below are six checks that take about fifteen minutes in total. None of them touch your code and none of them can break anything.
1. Look at your site the way Google sees it
Open Google and type site:yourdomain.com, with your own address. You will get a list of every page Google knows on your site.
Scroll through it. You are looking for pages you do not recognise: product names you never sold, text in Japanese or Chinese, links about pharmacy, casinos or loans. Hacked sites often get thousands of such spam pages added quietly, because the attacker wants to borrow your site's reputation in search results. Google even has a guide for one common version of it, called the Japanese keyword hack.
If you have access to Google Search Console, open the Security issues report on the left. Google lists there anything it has flagged on your site. An empty report is good news.
2. Check that the padlock is real
Click the padlock next to your address in the browser and open the certificate details. Look at the expiry date. Certificates renew automatically on most hosting plans, but "most" is doing a lot of work in that sentence. An expired certificate shows your visitors a full-page warning.
Then type your address by hand with http:// instead of https://, and once more with and without www. All four versions should land on the same secure address. If one of them stays on plain http, forms on that version send data unencrypted.
3. Find out when things were last updated
If your site runs on WordPress and you can log in, open Dashboard > Updates. Note three things: the WordPress version, how many plugins wait for an update, and whether the theme has one pending.
A plugin that has not been updated in a year is the most common way into a WordPress site. Patchstack, a company that tracks WordPress vulnerabilities, reports year after year that the large majority of new ones sit in plugins, not in WordPress itself.
While you are there, open the Plugins page. Anything marked as inactive is still sitting on your server. Its files can often be reached directly, whether it is switched on or not. If you do not use a plugin, ask for it to be deleted, not only deactivated.
4. Count the people who can log in
Still in the admin panel, open Users and filter by Administrator. For every name, ask yourself whether that person still works with you.
Former employees, an agency you parted ways with two years ago, a freelancer who fixed one bug: these accounts tend to live forever. Each one is a password that you do not control and that may have leaked somewhere else. Remove the ones you do not need, and make sure the ones that stay use two-factor login.
5. Check who can send email in your name
Go to a free checker such as MXToolbox, choose the DMARC lookup and type your domain. Do the same for SPF.
If DMARC is missing, anyone can send an email that looks like it came from your address. Your customers will not see the difference, and a fake invoice with your logo and your bank details swapped for someone else's is one of the most common scams aimed at small businesses. Since 2024 Gmail and Yahoo also expect DMARC from anyone sending email in bulk, so a missing record hurts your real newsletters too.
A record that says p=none exists but only watches. p=quarantine or p=reject is what actually protects you. Moving to it is a job for whoever manages your domain, and it takes them minutes once SPF and DKIM are in place.
6. Ask where the backups live
This one is a question, not a click. Ask the person who looks after your site where the backups are stored.
If the answer is "in a folder on the same server", that is worth a second conversation. A backup file sitting in the website folder, with a name like backup.zip or site-old.tar.gz, can be downloaded by anyone who guesses the address. It contains your whole site, often including the customer database and the password to it. Bots try these file names on every site they visit.
Good backups live somewhere else, run on a schedule, and someone has tried restoring one at least once.
What these checks do not show you
The six checks above cover the things you can see from your chair. They miss what needs a tool: whether your forms accept input they should reject, old JavaScript libraries with known holes, forgotten test subdomains, open server ports, or configuration files left where anyone can read them.
That is the gap I built ShieldWave for. You type your address, and in about 90 seconds it runs more than 20 of these checks from the outside, the way an attacker would. The report explains each finding in plain language, sorts them into what to fix this week, this month and later, and gives you a ready brief to forward to your developer. The first check is free and needs no account.
Five questions for whoever looks after your site
You do not need to understand the answers in detail. You need to hear that someone has thought about them.
- When were WordPress, the theme and the plugins last updated, and who does it?
- Where are the backups kept, how often do they run, and have you ever restored one?
- Who has administrator access right now?
- Are SPF, DKIM and DMARC set up for our domain, and is DMARC set to quarantine or reject?
- If the site were hacked tomorrow, what would you do first, and how would I find out?
If the answers come back vague, that tells you something too. Security on a small business website is regular maintenance, much like servicing a car. It rarely needs a big budget. It needs someone to look at it on a schedule, and you now know what to ask them to look at.