Website security checklist
A website security check should answer a practical question: can attackers, browsers, search crawlers, or casual visitors see something your team did not intend to expose? This scanner covers the public-facing controls that often decide whether a site earns user trust or becomes an easy target.
TLS and SSL
Confirms the site uses HTTPS correctly and looks for certificate or protocol weaknesses that can break browser trust.
- Valid certificate chain
- HTTPS availability
- HTTP-to-HTTPS redirect
- Weak protocol signals
Security headers
Reviews browser-enforced protections that reduce XSS, clickjacking, MIME sniffing, and downgrade risks.
- Content-Security-Policy
- Strict-Transport-Security
- X-Frame-Options
- Permissions-Policy
Exposure checks
Looks for public files and metadata that commonly reveal credentials, source control data, deployment details, or sensitive paths.
- .env and backup files
- Source control paths
- Directory listings
- robots.txt disclosures
Server configuration
Flags unnecessary technology disclosure and server behavior that makes targeting or exploitation easier.
- Server header leakage
- Error-page disclosure
- CORS posture
- Redirect behavior
Common vulnerability signals
Uses non-destructive public checks and framework-specific probes to identify obvious known-risk patterns without modifying the site.
- Open redirect indicators
- Mixed-content risk
- Framework exposure
- Known risky endpoints
Operational best practices
Checks whether the public site has basics that help with responsible disclosure, search crawling, and long-term monitoring.
- security.txt
- Clear remediation guidance
- Repeatable grade history
- Monitoring readiness
What each result means
The A-F grade summarizes the overall public posture, but the individual check status matters more than the letter. Prioritize critical and high-severity failures first, then work through warnings that weaken browser-side protections.
Pass
The control is present or configured in a way that meets the scanner baseline.
Warning
The control exists but is incomplete, weak, overly permissive, or missing context needed for a clean pass.
Fail
The scanner found a missing or risky control that should be fixed before relying on the site for sensitive workflows.
Error
The check could not be completed reliably, usually because the target blocked the request, timed out, or returned an unexpected response.
Common vulnerabilities this catches
Most website security failures are not exotic. They are exposed files, weak browser policy, missing transport guarantees, or configuration defaults that were never revisited after launch.
Missing HSTS
Risk: Browsers may allow downgrade attacks or accidental HTTP access after a user has visited the site.
Next step: Serve all traffic over HTTPS first, then enable a long HSTS max-age with includeSubDomains when subdomains are ready.
Weak or absent Content-Security-Policy
Risk: Injected scripts have more room to execute if an XSS bug appears in the application.
Next step: Start with report-only CSP, remove unsafe inline script usage where practical, then enforce a tight production policy.
Clickjacking exposure
Risk: Attackers may be able to frame sensitive pages and trick users into taking unintended actions.
Next step: Use frame-ancestors in CSP or X-Frame-Options on pages that should never be embedded.
Exposed environment or backup files
Risk: Public configuration files can leak credentials, internal URLs, API keys, or deployment details.
Next step: Remove exposed files, rotate any leaked secrets, and block sensitive extensions and dotfiles at the edge.
Next steps after the check
If this is more than a missing header, the next step is an operator, not another scan. Connect your security tools to the Vigilbase Platform, or talk to us about Managed Cloudflare.
Get started with the Vigilbase Platform
Connect the security tools you already pay for to the cybersecurity operating system, and have the Vigil agent investigate what matters.
Open resourceTalk to us about Managed Cloudflare
If this is more than a missing header, the next step is an operator, not another scan.
Open resourceWebsite security check FAQ
What does the website security check test?
It checks TLS and SSL configuration, common HTTP security headers, HSTS, CSP, mixed-content risk, exposed files, server information leakage, robots.txt disclosures, and several public vulnerability signals.Results cover the public URL and signals observed during the scan. They do not cover every authenticated route, internal service or business-logic risk.HTTP Security Headers CheckerA practical website protection guide
Is the scan safe to run on a production website?
Yes, when you are authorized to test the target. The public check is non-destructive, but the verified vulnerability flow may send framework-specific probe requests, including React and Next.js probes, to confirm exposure. It does not brute force logins or modify the target website.Agree the target, permitted testing and timing with the owner first. Non-destructive probing can still reach production application code and should be considered in your testing plan.Tool access and verification requirementsReact2Shell exposure check
Why do I need to verify my email before scanning?
Verification helps prevent abuse and confirms access to the email address used for the request. It does not prove ownership of the target or permission to test it.Only submit systems you own or are explicitly authorized to test. Do not treat a completed email check as permission from a third-party system owner.Tool access and verification requirementsPrivacy and data handling
What is a good website security grade?
A or A+ means the checks scored well against this tool’s public-facing baseline at the time of the scan. Lower grades highlight findings to review and prioritize; no grade proves that the application is secure.Review the individual findings, confirm whether they apply to your deployment, and verify remediation against important user journeys. A rerun can confirm the tested change without certifying the whole application.A practical website protection guideManaged WAF operations and change control
Can this replace a penetration test?
No. This check is a fast public-facing posture review. It is useful for finding common configuration issues, but deeper application logic, authentication, and business-process risks still need expert testing.A practical website protection guideDiscuss your scope with Vigilbase