Small business website security checklist
Eight checks that cover the basics for a small-business website: what each one protects, how to fix it, and whether our free scan checks it from the outside or you need to look yourself. Then what no outside scan can see, and a 15-minute routine to repeat every quarter.
The checklist at a glance
| Item | Our free scan |
|---|---|
| 1. HTTPS and certificate renewal | Checks it |
| 2. Security headers | Checks it |
| 3. Software updates | Partly |
| 4. Exposed files | Common ones |
| 5. DNS and subdomain takeover | Partly |
| 6. Email authentication | SPF and DMARC |
| 7. MFA on domain, DNS and hosting accounts | You check |
| 8. Backups you've restored | You check |
| Also: malware and hacked content | You check |
1. HTTPS everywhere, with automatic certificate renewal
Every page should load over https://, and plain http:// should redirect there. The certificate behind it expires on a schedule that keeps getting shorter: publicly trusted certificates issued since March 15, 2026 can be valid for at most 200 days, falling to 100 days in March 2027 and 47 days in March 2029 (CA/Browser Forum Baseline Requirements §6.3.2, adopted in Ballot SC-081). Let's Encrypt, which many hosts use, issues 90-day certificates by default and recommends renewing every 60 days (Let's Encrypt FAQ). It also stopped sending expiry reminder emails in June 2025 (Let's Encrypt).
- Turn on automatic renewal in your hosting panel, then confirm once that a renewal actually happened.
- Switch off TLS 1.0 and 1.1. The IETF says neither may be used (RFC 8996).
Our free scan: checks that HTTPS works, that the certificate is trusted and unexpired, warns if it expires within 21 days, and checks that http:// redirects to https://. It doesn't test which older TLS versions your server still accepts, so ask your host to confirm TLS 1.0 and 1.1 are switched off.
2. Security headers
Security headers are instructions your site sends to every visitor's browser. You can usually add them in your host's control panel, your CDN or a security plugin. A reasonable starting set:
Strict-Transport-Security: max-age=31536000; includeSubDomains X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: camera=(), microphone=(), geolocation=()
- Strict-Transport-Security tells browsers to use HTTPS only;
max-age=31536000is one year.includeSubDomainscovers every subdomain, so confirm they all work over HTTPS first. Browsers ignore this header over plain HTTP (MDN). The optionalpreloadflag lets you apply for browsers' built-in HTTPS-only list; getting off that list again takes months (hstspreload.org). - Content-Security-Policy limits which scripts can run: strong protection against injected code, and easy to break a site with. Start with
Content-Security-Policy-Report-Only, which reports violations without enforcing them (MDN). - X-Frame-Options stops other sites from loading yours in a frame to trick visitors into clicks (clickjacking). CSP's
frame-ancestorsdirective offers more options (MDN). - X-Content-Type-Options stops browsers from guessing file types (MDN); Referrer-Policy limits how much of your page addresses leak to other sites (MDN); Permissions-Policy switches off browser features you don't use (MDN).
Our free scan: checks your homepage for all six headers, including Content-Security-Policy.
3. Keep software updated
The FTC's advice to small businesses: set a schedule for updating software and turn on automatic updates (FTC).
- WordPress: since version 5.5 you can turn on automatic updates plugin by plugin and theme by theme (WordPress). Delete plugins and themes you don't use.
- Hosted website builders: the provider usually maintains the platform itself; you're still responsible for any third-party apps, plugins or custom code you add.
- Your server's software: ask your host which PHP version the site runs and compare it with PHP's list of supported versions.
Our free scan, partly: it reads the version details your site announces (server headers, the page's generator tag, the jQuery file) and flags some old versions: PHP older than 7.4, Apache 2.2 and older, jQuery before 3.0, and WordPress 5.x and older. PHP 8.1 and everything before it are past end of life, so compare your version with PHP's supported list yourself. Many sites hide these details and the scan doesn't check plugin versions, so a clean result here isn't proof you're up to date.
4. Remove exposed files
Developer and backup files sometimes land in the public web folder, where anyone can download them: a .git folder (your source code and its history), a .env file (passwords and API keys), a backup such as wp-config.php.bak (database credentials) or a public server-status page. OWASP's testing guide explains why old, backup and unreferenced files are dangerous (OWASP).
- Delete them from the web root and block access to files whose names start with a dot.
- If one was exposed, change every password and key it contained. Assume they're compromised.
Our free scan: requests /.git/HEAD, /.env, /wp-config.php.bak, /.svn/entries and /server-status, and checks what comes back, so a normal "page not found" page isn't mistaken for a leak.
5. Clean up DNS: dangling records and CAA
A subdomain takeover happens when a DNS record, usually a CNAME, still points at a cloud service you've stopped using. Whoever claims that name on the service can then publish content on your subdomain (MDN). MDN's advice: when you shut something down, delete the DNS record first, and keep an inventory of your domains and where they point.
A CAA record lists the certificate authorities allowed to issue certificates for your domain. Without one, any public CA may issue, as long as it validates control of the domain (Let's Encrypt; RFC 8659). If you use Let's Encrypt:
@0 issue "letsencrypt.org"
List every CA you actually use, including your host's or CDN's, or renewals will fail.
Our free scan, partly: checks your nameservers, mail (MX) records and CAA, and whether your domain or common subdomains (www, mail, blog, shop, dev, staging, app) point, by CNAME, at a cloud service name that no longer exists in DNS, such as a deleted Azure app. Platforms that answer for every name, including GitHub Pages, Heroku and Amazon S3, can't be checked this way, so review any records that point at them yourself.
6. Email authentication
Your domain's SPF, DKIM and DMARC records decide whether scammers can send email that looks like it came from you. The FTC tells businesses that use their own domain for email to make sure their provider has all three (FTC). Two guides cover it end to end: what to do if someone is sending email from your domain, including how to check your records, then set up DMARC step by step. Remember that DMARC only protects you once its policy is quarantine or reject.
Our free scan: reads your SPF and DMARC records. The $7 report also lists DKIM as a note, because it can't be reliably found from outside.
7. MFA on the accounts that control your site
Whoever can sign in to your domain registrar, DNS host, web host or email admin console can redirect your website and your mail. In a 2019 emergency directive, CISA described attackers using compromised credentials for accounts that could change DNS records to change records and send traffic to addresses they controlled, and it required federal agencies to put MFA on every account able to change DNS records (CISA ED 19-01).
- Turn on multi-factor authentication for your registrar, DNS host, web host and email admin accounts.
- Prefer security keys or passkeys: CISA calls FIDO/WebAuthn the only widely available phishing-resistant option (CISA).
- Keep each account's recovery email and phone current, and consider giving a second trusted person their own admin login so one lost phone can't lock you out.
Our free scan can't see this. It lives inside your accounts, so check it yourself.
8. Backups you've actually restored
A backup only counts if you can restore it. CISA recommends offline, encrypted backups of critical data, tested regularly (CISA #StopRansomware Guide), and the FTC advises keeping backups disconnected from your network (FTC).
- Find out what your host backs up, how often, and how long it keeps copies.
- Keep your own copy of the site files and database somewhere separate from the host.
- Do a test restore, to a staging copy of the site for example, and note how long it took.
Our free scan can't see backups. Check them yourself.
What an outside scan can't see: malware and hacked content
Malware, injected spam pages and other hacked content live inside your site's files and database, which a passive outside scan like ours can't read. Two places to look:
- Google Search Console's Security issues report lists hacked content, malware and social-engineering pages that Google has found on your site, with sample URLs, and lets you request a review once they're cleaned up (Google). You'll need to verify your site in Search Console first.
- Your host or security plugin: ask your host whether it scans your site files for malware, and where you'd see the results.
Our free scan can't see this. Check the report above and ask your host.
A 15-minute routine for every quarter
- Run the free scan and compare the grade with last quarter's.
- Open Search Console's Security issues report.
- Check the certificate's expiry date (click the padlock in your browser). If it's less than a month away, confirm with your host that automatic renewal is really on.
- Apply updates, or confirm automatic updates ran, and delete plugins and themes you don't use.
- Check that MFA is on, and recovery email and phone are current, for your registrar, DNS host, web host and email admin accounts.
- Read through your DNS records and delete any that point at services you've stopped using.
- Skim your DMARC reports for senders you don't recognize.
- Confirm the latest backup exists, and do a test restore at least once a year.
Common questions
Is a free outside scan enough?
No. An outside scan sees what the public sees: your certificate, headers, exposed files, DNS and email records. It can't see your passwords, MFA settings, backups, most plugin versions, or malware and hacked content inside your site. Use it to catch the public-facing gaps and this checklist for the rest.
How often should I re-check?
After any change to your website, hosting or DNS, and every quarter using the routine above. Certificate lifetimes are shrinking (200 days at most since March 2026, per the CA/Browser Forum), so confirm that automatic renewal is still working.
What should I ask my web developer or host?
Ask four things: do certificates renew automatically, which TLS versions the server still accepts, who applies updates and how often, and where backups are kept and when a restore was last tested. Then send them your scan results so they can see exactly what to fix.
Sources
- CA/Browser Forum — Baseline Requirements for TLS Server Certificates, §6.3.2
- CA/Browser Forum — Ballot SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods
- Let's Encrypt — FAQ
- Let's Encrypt — Ending Support for Expiration Notification Emails
- IETF — RFC 8996: Deprecating TLS 1.0 and TLS 1.1
- MDN — Strict-Transport-Security
- HSTS Preload List Submission (hstspreload.org)
- MDN — Content-Security-Policy-Report-Only
- MDN — X-Frame-Options
- MDN — X-Content-Type-Options
- MDN — Referrer-Policy
- MDN — Permissions-Policy
- FTC — Cybersecurity for Small Business
- WordPress — Plugin and themes auto-updates
- PHP — Supported versions
- OWASP Web Security Testing Guide — Review Old Backup and Unreferenced Files
- MDN — Subdomain takeover
- Let's Encrypt — Certificate Authority Authorization (CAA)
- IETF — RFC 8659: DNS Certification Authority Authorization (CAA) Resource Record
- CISA — ED 19-01: Mitigate DNS Infrastructure Tampering
- CISA — More than a Password (multifactor authentication)
- CISA — #StopRansomware Guide
- Google Search Console Help — Security issues report
Standards and provider settings change. If your provider's current documentation differs from this guide, follow the provider.
Changes to this guide
- : First published.