Securitate• 15 May 2026 • 8 min citire

Website security: 13 mandatory checks in 2026

The most important security tests for any website: SSL, headers, CMS exposure, mixed content. Plus a free tool that runs them all.

In 2026, cyberattacks on small and medium websites have grown by over 300% compared to 2023. The good news: 90% of them are prevented with correct configurations that cost nothing. ## The 13 basic checks ### 1. HTTPS active and HTTP redirect Without SSL, modern browsers flag the site as unsafe, and Google penalizes SEO. Solution: free Let's Encrypt certificate, configured in 10 minutes. ### 2. HSTS (Strict-Transport-Security) Forces browsers to use HTTPS only, preventing downgrade attacks. A simple header to add. ### 3. Content Security Policy (CSP) Direct protection against XSS - the most common type of web attack. ### 4. X-Frame-Options or frame-ancestors Prevents the site from being displayed in an iframe on another site (clickjacking). ### 5. X-Content-Type-Options nosniff Prevents browsers from interpreting files as another MIME type. ### 6. Referrer-Policy Controls how much information is sent with external links. ### 7. Permissions-Policy Controls access to camera, microphone, geolocation. ### 8. Server header without version nginx/1.18.0 tells an attacker exactly which vulnerabilities to look for. ### 9. X-Powered-By disabled PHP/7.4.3 is a gift for attackers. Simple to hide. ### 10. CMS and sensitive files exposure /wp-admin, /.env, /.git/config - all must be protected. ### 11. Mixed content HTTP resources loaded in an HTTPS page. Browsers have been blocking them since 2020. ### 12. Cookie security (Secure + HttpOnly) Fundamental for protecting sessions. ### 13. Updated versions WordPress, PHP, plugins - old versions are a major risk. ## Our scanning tool We automated all these checks. Enter any website's URL and in 30 seconds you get a report with a 0-100 score (A/B/C/D/F grade), severity per issue (Critical/High/Medium/Low) and concrete recommendations. Free, no registration, non-intrusive scan (we check only what is public, following OWASP standards). ## When you need a professional audit If our scan finds critical vulnerabilities, or if you run a site with online payments, user accounts or sensitive data, we recommend a full audit: - Manual penetration testing - Server configuration audit (firewall, SSH, databases) - Specific WordPress/Laravel hardening - Incident response plan - Continuous monitoring Contact us with the scan report and we will propose a personalized plan.