Security report for
yourbakery.example
Grade D · 62/100
At risk — start with the most urgent items
5 issues found + 1 note
1 Critical1 High2 Medium1 Low+ 1 note
Start here
- Fix Critical and High items first — they're what attackers try first.
- Each item stands alone — forward any one to whoever runs your website, email, or domain.
- Re-check free any time on our website.
Your fix-it list at a glance
| Done | # | Severity | Issue |
|---|---|---|---|
| #1 | Critical | Anyone can send email pretending to be you Critical | |
| #2 | High | Your website software is out of date High | |
| #3 | Medium | Missing browser security headers Medium | |
| #4 | Medium | SSL certificate expires in 12 days Medium | |
| #5 | Low | Server version is advertised Low | |
| Note | Note | DKIM can't be verified from outside Note |
Critical 1
#1
Anyone can send email pretending to be you
yourbakery.example has no DMARC policy and a loose SPF record, so scammers can send invoices and order confirmations that look like they came from you.
HOW TO FIX
Add a TXT record at _dmarc.yourbakery.example: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourbakery.example — then make sure your SPF record ends in -all.
High 1
#2
Your website software is out of date
The site runs an old WordPress version with publicly known security flaws.
HOW TO FIX
In WordPress go to Dashboard → Updates, update core, themes and plugins, then turn on automatic updates.
Medium 2
#3
Missing browser security headers
Without Strict-Transport-Security and a Content-Security-Policy, a downgrade attack or one injected script can target your visitors.
HOW TO FIX
In your host's settings add Strict-Transport-Security: max-age=31536000. Then add a Content-Security-Policy-Report-Only header (or at minimum frame-ancestors 'self'; upgrade-insecure-requests) and tighten it once you've confirmed nothing on the site breaks.
#4
SSL certificate expires in 12 days
When it lapses, browsers show visitors a full-page 'Not secure' warning.
HOW TO FIX
Turn on auto-renew in your hosting control panel.
Low 1
#5
Server version is advertised
Your web server announces its exact version, telling attackers which known bugs to try.
HOW TO FIX
Apache: set ServerTokens Prod and ServerSignature Off. Nginx: set server_tokens off.
Notes 1not counted as issues
Note
DKIM can't be verified from outside
DKIM keys live under a private selector name, so an outside scan can't confirm them.
HOW TO FIX
Turn on DKIM signing in your email provider's admin console.
Assessment based on publicly observable data, like a normal visitor. Informational — not a guarantee. Questions: smallbizsecuritycheck@gmail.com
Generated by Small Business Security Check