Area: Website and certificates
Public website
A single visit to your homepage, like a browser: redirect to HTTPS, HSTS, security headers, visible versions, technologies, cookies, forms, legal pages and signs of a hacked site (hidden spam, redirects to another domain).
What it can report
Open each one to see what it means and how to fix it.
Website doesn't use HTTPS
What it means
What could happen
How an attacker would use it
How to fix it
- Get an HTTPS certificate for your domain.Let's Encrypt certificates are free, and most hosts and website builders have a free “HTTPS” or “SSL” option in their dashboard.
- Install it in your hosting plan or on the server.
- Redirect every http:// address to its https:// equivalent.
- Check that the images, scripts and forms of your pages also load over https://, otherwise the browser will complain.
- Open your site in a browser and check that the padlock shows.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No HSTS
What it means
What could happen
How an attacker would use it
How to fix it
- Make sure your whole site, and its subdomains if you use them, works over HTTPS.
- Ask your host or IT person to add the “Strict-Transport-Security” header, first with a short time, for example one day (max-age=86400).Hosting panels often have a toggle called “HSTS” or “Force HTTPS”.
- If everything keeps working, raise it to one year (max-age=31536000).
- Add “includeSubDomains” only if every subdomain also has HTTPS, because otherwise it will stop working.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
HSTS lasts too little
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your host or IT person to raise the HSTS “max-age” to one year (31536000 seconds).
- In a hosting panel, look for the “HSTS” setting and choose the longest duration offered.
- Check that your whole site, including subdomains if you add “includeSubDomains”, works over HTTPS.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
WordPress plugins and themes visible
What it means
What could happen
How to fix it
- In the WordPress admin, open the Plugins page and update everything that has an update.Make a backup first, or ask your host to do it.
- Delete the plugins and themes you don't use, not just deactivate them.
- Turn on automatic updates for the plugins you trust, which the Plugins page offers for each one.
- Ask whoever maintains your site to review the plugins every few months.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Missing security headers
What it means
What could happen
How an attacker would use it
How to fix it
- Ask whoever maintains your website, or your host, to add the missing headers.
- Start with the easy ones: “X-Content-Type-Options: nosniff” and “Referrer-Policy”.Many hosting panels and security plugins have a toggle for them.
- For frame protection, add “X-Frame-Options” or the “frame-ancestors” part of the Content-Security-Policy.
- Leave “Content-Security-Policy” for last, in “report-only” mode first: a wrong one can break your site.
- Test your pages in a browser after each change.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Server announces its software version
What it means
What could happen
How an attacker would use it
How to fix it
- Ask whoever manages the server to stop announcing the version.In nginx it is “server_tokens off”, in Apache “ServerTokens Prod” and in PHP “expose_php = Off”.
- On shared hosting, check the panel for a “hide server version” option, or ask support.
- More important: make sure the software itself is up to date.
- Check the headers again after the change, from your browser's developer tools or via Ward.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Unsupported software on the website
What it means
What could happen
How an attacker would use it
How to fix it
- Make a full backup of the site and database, or ask your host to do it.
- Update your content system (for example WordPress), its theme and its plugins first, so they support the new PHP.
- In your hosting panel, look for the PHP version setting and choose a supported version.Many panels have a “PHP version” option; if yours doesn't, ask support.
- Test the site and fix what breaks. Roll back if needed and ask the plugin developers for updates.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
CMS version visible
What it means
What could happen
How to fix it
- Update wordpress and its plugins to the latest version.That is the real fix.
- Hide the “generator” label from the page code, using your theme's settings or a security plugin.
- Check the page again after hiding it.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Form sends data without encryption
What it means
What could happen
How an attacker would use it
How to fix it
- Find the form in the technical details: the address in “action” starts with http://.
- Change that address to https://, in the page, the theme or the form plugin's settings.
- Check that the new address works over HTTPS, otherwise the form will fail.
- Send a test submission and check that it arrives.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Script loaded without encryption
What it means
What could happen
How an attacker would use it
How to fix it
- Find the script address in the technical details.
- Change it to https:// in the page, the theme or the plugin that adds it.
- If the provider of that script doesn't offer HTTPS, replace the service.
- Reload the page and check in the browser that the padlock has no warning.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Hidden spam on the home page
What it means
What could happen
How an attacker would use it
How to fix it
- Ask whoever maintains your site, or your host, to restore a clean backup from before the infection.
- Update the content system, the theme and all plugins, and delete the ones you don't use.
- Change every password: site admin, hosting, FTP and database. Delete users you don't recognize.
- Look for how they got in, such as an old plugin or a shared password. Otherwise it will happen again.
- Check Google Search Console for security warnings and request a review once the site is clean.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Website redirects to another domain
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your team and your web provider whether the redirect to this address is intentional.
- If it is, mark the finding as an accepted risk, with a note saying why.
- If it isn't, check your hosting and DNS for redirect rules you don't know, and remove them.
- Change every password (hosting, website admin, DNS and registrar) and turn on two-step verification.
- Ask your provider to restore a clean copy if the site was changed, and scan it for hidden code.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Legal pages not found
What it means
What could happen
How an attacker would use it
How to fix it
- Check your site's footer: the pages may exist but with other names, or not be linked from the homepage.
- If they don't exist, have them written for your business.A lawyer or a specialized advisor is best. Generic generators can be a starting point, but they need review.
- Publish them as pages on your site.
- Link them from the footer of every page, and next to any form that collects personal data.
- Make sure the cookie notice matches the cookies your site really sets.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.