Blog/Security Audit

Website Security Checklist: 40 Checks Every Site Needs

A practical, category-by-category checklist of the passive security checks every public website should pass. Run the free scanner to see where yours stands — in seconds, no login.

May 6, 20269 min read

40+

security checks

7

categories

0

false exploits

Security Headers

7 checks
✓Strict-Transport-Security (HSTS) present with adequate max-age
✓Content-Security-Policy configured (even if report-only initially)
✓X-Frame-Options set to DENY or SAMEORIGIN
✓X-Content-Type-Options: nosniff
✓Referrer-Policy set to strict-origin-when-cross-origin or stricter
✓Permissions-Policy configured to disable unused browser features
✓Cache-Control set appropriately (no-store for sensitive pages)

SSL / TLS

7 checks
✓Valid SSL/TLS certificate installed
✓Certificate not expiring within 30 days
✓All HTTP traffic redirects to HTTPS (301)
✓TLS 1.0 and 1.1 disabled (TLS 1.2+ only)
✓No weak cipher suites (RC4, DES, 3DES)
✓No mixed content (HTTP resources on HTTPS pages)
✓Subdomain coverage via wildcard or SAN certificate

Cookie Security

5 checks
✓Session cookies have HttpOnly flag
✓Session cookies have Secure flag
✓Session cookies have SameSite=Strict or Lax attribute
✓No sensitive data stored in non-HttpOnly cookies
✓Cookie expiry is reasonable (not years)

Information Exposure

8 checks
✓No .env file publicly accessible (/.env)
✓No .git/config exposed (/.git/config)
✓No wp-config.php or similar config files exposed
✓No phpinfo.php page accessible
✓No directory listing enabled on server
✓Error pages don't leak stack traces or server version
✓No sensitive comments in HTML source
✓Server header doesn't expose version info

CORS & APIs

4 checks
✓No wildcard Access-Control-Allow-Origin (*) on sensitive endpoints
✓CORS credentials (withCredentials) not combined with wildcard origin
✓Reflected-origin CORS not in use (mirror arbitrary Origins)
✓API endpoints require authentication where needed

Client-Side Risks

7 checks
✓Inline scripts use nonce or hash in CSP
✓CDN assets use Subresource Integrity (SRI) hashes
✓No eval() usage in JavaScript
✓No dangerouslySetInnerHTML without sanitisation (React)
✓Form inputs sanitised and validated
✓No sensitive data (keys, tokens) in client-side JS bundles
✓localStorage not used for sensitive authentication tokens

Authentication & Sessions

4 checks
✓Password reset tokens expire after use
✓Login rate limiting in place (brute-force protection)
✓Session IDs regenerated after authentication
✓Logout invalidates server-side session

Run the 40-check scan on your site

Passive scanning only. Instant results. No signup required. Zero false exploits.

Free Security Scan →

Frequently asked questions

How do I check if my website is secure?

Run Flux8Shield's free passive scanner — it checks 40+ security factors including headers, SSL/TLS configuration, cookie flags, information exposure, and CORS misconfigurations. No installation, no signup, results in seconds.

What is the OWASP Top 10?

The OWASP Top 10 is a standard awareness document for web application security, listing the 10 most critical security risks. It includes injection attacks, broken authentication, XSS, insecure direct object references, and more. Updated every few years — the 2021 version is the current reference.

Is a passive scan safe?

Yes. Flux8Shield performs entirely passive scanning — it only reads publicly accessible information your server already sends to any browser. It never attempts to exploit vulnerabilities, inject payloads, or access restricted areas.

How often should I run a security scan?

At minimum: after every major deployment, after adding third-party integrations, and quarterly as a baseline audit. For production sites, weekly automated scans catch regressions introduced by updates or new dependencies.

Does website security affect SEO?

Yes. Google factors HTTPS (and implicitly TLS configuration) into rankings. Sites with browser security warnings see near-100% bounce rates. Google Safe Browsing flags compromised sites and can cause dramatic traffic drops if your site is blacklisted.