Securitate• 15 May 2026
•
8 min citire
Website security: 13 mandatory checks in 2026
The most important security tests for any website: SSL, headers, CMS exposure, mixed content. Plus a free tool that runs them all.
In 2026, cyberattacks on small and medium websites have grown by over 300% compared to 2023. The good news: 90% of them are prevented with correct configurations that cost nothing.
## The 13 basic checks
### 1. HTTPS active and HTTP redirect
Without SSL, modern browsers flag the site as unsafe, and Google penalizes SEO. Solution: free Let's Encrypt certificate, configured in 10 minutes.
### 2. HSTS (Strict-Transport-Security)
Forces browsers to use HTTPS only, preventing downgrade attacks. A simple header to add.
### 3. Content Security Policy (CSP)
Direct protection against XSS - the most common type of web attack.
### 4. X-Frame-Options or frame-ancestors
Prevents the site from being displayed in an iframe on another site (clickjacking).
### 5. X-Content-Type-Options nosniff
Prevents browsers from interpreting files as another MIME type.
### 6. Referrer-Policy
Controls how much information is sent with external links.
### 7. Permissions-Policy
Controls access to camera, microphone, geolocation.
### 8. Server header without version
nginx/1.18.0 tells an attacker exactly which vulnerabilities to look for.
### 9. X-Powered-By disabled
PHP/7.4.3 is a gift for attackers. Simple to hide.
### 10. CMS and sensitive files exposure
/wp-admin, /.env, /.git/config - all must be protected.
### 11. Mixed content
HTTP resources loaded in an HTTPS page. Browsers have been blocking them since 2020.
### 12. Cookie security (Secure + HttpOnly)
Fundamental for protecting sessions.
### 13. Updated versions
WordPress, PHP, plugins - old versions are a major risk.
## Our scanning tool
We automated all these checks. Enter any website's URL and in 30 seconds you get a report with a 0-100 score (A/B/C/D/F grade), severity per issue (Critical/High/Medium/Low) and concrete recommendations.
Free, no registration, non-intrusive scan (we check only what is public, following OWASP standards).
## When you need a professional audit
If our scan finds critical vulnerabilities, or if you run a site with online payments, user accounts or sensitive data, we recommend a full audit:
- Manual penetration testing
- Server configuration audit (firewall, SSH, databases)
- Specific WordPress/Laravel hardening
- Incident response plan
- Continuous monitoring
Contact us with the scan report and we will propose a personalized plan.