SAMPLE REPORT · fictional business (yourbakery.example) · Your report lists your site's real findings. Get your own free grade →
Small BusinessSecurity Check
SECURITY REPORTSeptember 26, 2026

Security report for

yourbakery.example

Checked September 26, 2026 · Passive, read-only assessment · Small Business Security Check

Grade D · 62/100

At risk — start with the most urgent items

5 issues found + 1 note

1 Critical1 High2 Medium1 Low+ 1 note

Start here

  1. Fix Critical and High items first — they're what attackers try first.
  2. Each item stands alone — forward any one to whoever runs your website, email, or domain.
  3. Re-check free any time on our website.

Your fix-it list at a glance

Done#SeverityIssue
#1CriticalAnyone can send email pretending to be you
Critical
#2HighYour website software is out of date
High
#3MediumMissing browser security headers
Medium
#4MediumSSL certificate expires in 12 days
Medium
#5LowServer version is advertised
Low
NoteNoteDKIM can't be verified from outside
Note

Critical 1

#1

Anyone can send email pretending to be you

yourbakery.example has no DMARC policy and a loose SPF record, so scammers can send invoices and order confirmations that look like they came from you.
HOW TO FIX
Add a TXT record at _dmarc.yourbakery.example: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourbakery.example — then make sure your SPF record ends in -all.

High 1

#2

Your website software is out of date

The site runs an old WordPress version with publicly known security flaws.
HOW TO FIX
In WordPress go to Dashboard → Updates, update core, themes and plugins, then turn on automatic updates.

Medium 2

#3

Missing browser security headers

Without Strict-Transport-Security and a Content-Security-Policy, a downgrade attack or one injected script can target your visitors.
HOW TO FIX
In your host's settings add Strict-Transport-Security: max-age=31536000. Then add a Content-Security-Policy-Report-Only header (or at minimum frame-ancestors 'self'; upgrade-insecure-requests) and tighten it once you've confirmed nothing on the site breaks.

#4

SSL certificate expires in 12 days

When it lapses, browsers show visitors a full-page 'Not secure' warning.
HOW TO FIX
Turn on auto-renew in your hosting control panel.

Low 1

#5

Server version is advertised

Your web server announces its exact version, telling attackers which known bugs to try.
HOW TO FIX
Apache: set ServerTokens Prod and ServerSignature Off. Nginx: set server_tokens off.

Notes 1not counted as issues

Note

DKIM can't be verified from outside

DKIM keys live under a private selector name, so an outside scan can't confirm them.
HOW TO FIX
Turn on DKIM signing in your email provider's admin console.

Assessment based on publicly observable data, like a normal visitor. Informational — not a guarantee. Questions: smallbizsecuritycheck@gmail.com

Generated by Small Business Security Check