Site AI Auditот Internet Solutions

Website Security Audit Checklist: What to Check and in What Order

27 сентября 2026 г.Время чтения: 7 минБезопасность и SSL
Website Security Audit Checklist: What to Check and in What Order

Short answer: A practical website security audit checks, in order of impact: HTTPS and the SSL certificate (validity, expiry, redirect, TLS versions); software currency and exposure (CMS, plugins, PHP, visible versions, leftover files); access (admin accounts, two-factor authentication, hosting and registrar security); resilience (backups and restore tests); browser protections (security headers and cookie flags); and the domain (DNS, registrar lock, e-mail authentication). Start with the external checks that take minutes, fix what can cause outages or break-ins first, and repeat the audit after every major change.

“Is our website secure?” is a question every business owner, marketer and agency eventually hears. Answering it does not require a penetration test on day one. A structured audit of the basics, done in the right order, finds the issues behind most real incidents and gives you a clear to-do list. This checklist is designed for small and medium business sites – company websites, blogs, shops and portals – and explains what to check, how, and what a good result looks like.

Before you start: access, scope and a record

A little preparation makes the audit faster and its results more useful. First, define the scope: the main domain and www, every subdomain that serves customers or staff, and any separate shop, booking or portal systems. Second, gather read access to the places you will need to look – the CMS admin area, the hosting control panel, the domain registrar and DNS provider, and the e-mail service – or arrange for the people who hold that access to be available. Third, decide where you will record the results: a simple table with the check, the finding, its priority, the owner and the date is enough.

Finally, run the external checks first. They need no access at all, take only minutes, and often reveal the most urgent problems – an expiring certificate, a missing redirect, an exposed backup file – before you spend time on anything else. Their results also give you a baseline to compare against after fixes, which is the simplest way to show that the work made a measurable difference.

1. HTTPS and the SSL certificate

Problems here are visible to every visitor and often cause outright outages.

2. Software currency and exposure

For each outdated component, note whether the available update is a security release. That single detail usually decides whether it belongs in today’s work or next week’s routine.

3. Access and accounts

4. Backups and recovery

5. Browser protections

Check these headers on several page types – the home page, a content page, the login page, a static file and an error page – because server rules and CDN settings often apply them unevenly. A header present on the home page but missing on the checkout or login page protects less than it seems. Note also where each header is set, so the next person who changes the server or CDN configuration does not remove it by accident.

6. Domain, DNS and e-mail

Many of the items in sections 3, 4 and 6 cannot be seen from outside, which is why an external scan alone never gives the complete picture. Plan a short conversation with whoever manages hosting, the domain and e-mail – often three different people or companies – and walk through those items together. Write down the answers, including “we don’t know”, because unknowns are findings too.

How to prioritise the findings

PriorityExamplesTimeframe
CriticalCertificate expiring or invalid, exposed .env or backups, known exploited vulnerability, unknown admin userToday
HighOutdated plugins with security fixes, no 2FA on admin or registrar, no off-site backups, domain near expiryThis week
MediumMissing basic security headers, exposed versions, directory listing, old TLS versions, no DMARCThis month
ImprovementFull CSP, DNSSEC, CAA, registry lock, restore drillsPlanned

Critical findings can put visitors at risk or take the site offline; high findings are the usual causes of compromises; medium ones reduce exposure; improvements raise the baseline further.

How often to audit

Run the full checklist when you take over a site, after major changes such as a redesign, migration, new hosting or new CDN, and at least once or twice a year otherwise. The external items – certificate, redirect, headers, exposed versions, e-mail records – should be monitored continuously, because they change without anyone intending it: a renewal fails, a server rebuild loses a header, a DNS change breaks e-mail. Keep each audit report so you can compare results over time and show progress to management or clients. For deeper assurance on custom applications, add vulnerability scans and periodic penetration tests; guidance such as the OWASP Top 10 describes the application-level risks those deeper tests look for.

How Site AI Audit helps

Site AI Audit automates the external parts of this checklist in one run: SSL certificate and expiry, HTTP to HTTPS redirect, security headers, exposed software versions, and e-mail authentication (SPF, DKIM, DMARC, MX), alongside SEO and speed. Every finding is explained in plain words and ranked by impact, with how to fix it. The free check shows where you stand; paid plans add the full report with affected pages, unlimited re-checks, monitoring with alerts and PDF reports – with your own logo on the Agency plan. Start with a free check.

Related reading

The bottom line

A website security audit does not need to be complicated to be valuable. Work through HTTPS, software, access, backups, browser protections and the domain in that order, fix critical and high findings first, and keep the external checks under continuous monitoring. Repeated regularly, this checklist catches the problems behind most real-world incidents long before they turn into one.

FAQ

How long does a website security audit take?

The external checks take minutes with an automated tool. A complete audit including accounts, backups and DNS typically takes a few hours for a small business site, longer for complex platforms.

Can I audit my website’s security myself?

Yes, for most of this checklist. External tools cover HTTPS, headers and exposed versions, and the account, backup and domain checks mainly require access and attention rather than specialist skills.

What is the most common problem found in audits?

Outdated software and missing security headers are among the most frequent findings, while expired or soon-to-expire certificates are the most common cause of visible outages.

How often should a website be audited?

Fully at least once or twice a year and after major changes, with continuous monitoring of certificates, HTTPS, headers and e-mail records in between.

Is a security audit the same as a penetration test?

No. An audit checks configuration and hygiene against a checklist, while a penetration test has specialists actively try to break into the application. Most small businesses should start with audits and add penetration tests for custom or sensitive applications.

#Security headers#Website audit#Website security
Проверьте свой сайт — бесплатно.Что исправить на сайте — и с чего начать.
Начать бесплатно

Ещё из блога

Все статьи →
Internet Solutions

Другие продукты нашей команды

Сделано Internet Solutions. Попробуйте и другие наши продукты — каждый экономит время по-своему.

internet-solutions.net ↗
01Автопостинг в соцсети
PostRSS

Новые записи из вашего RSS-фида автоматически публикуются в Facebook, X, LinkedIn, Telegram и ещё 60+ сетях.

Бесплатный тариф · с 2014Перейти →
02AI-чат для сайтов
Talkmio

Ваш сайт отвечает посетителям 24/7 на основе вашего контента и на их языке.

Бесплатный тариф · без картыПерейти →
03AI-ассистент
Ask Mio

Чат, код, дизайн, тексты и исследования. Mio подбирает лучшую модель для каждой задачи.

Бесплатный тарифПерейти →
04AI-автопилот для блога и соцсетей
AI Blog Autopilot

AI пишет SEO-статьи на 2000–3000 слов и публикует каждую в 58+ соцсетях.

Первые 3 статьи бесплатноПерейти →
05Глубокий SEO-аудит
Site SEO AI Audit

Полное SEO-сканирование по 7 направлениям, включая видимость в AI-поиске, с исправлениями по степени влияния.

Первый аудит бесплатноПерейти →
06RSS и товарные фиды
RSS Feed Creator

Создавайте RSS из любой веб-страницы, а также товарные фиды для Google и Meta, которые обновляются сами.

Бесплатный тарифПерейти →
07Разработка сайтов и SEO
Internet Solutions

Сайты, интернет-магазины и индивидуальные системы — проектирует, создаёт и сопровождает наша команда.

С 2011Перейти →
Site AI Audit
Обзор конфиденциальности

Этот сайт использует cookie, чтобы мы могли обеспечить вам наилучший пользовательский опыт. Информация cookie хранится в вашем браузере и выполняет такие функции, как узнавание вас при повторном посещении сайта, а также помогает нашей команде понять, какие разделы сайта вам наиболее интересны и полезны.