DIY Website Security Audit Checklist (Free)

By Bug Circuit Security Team
DIY Website Security Audit Checklist (Free)

You can check most of your own website's security in under an hour using free tools — this checklist walks you through exactly how. It won't catch everything (more on that below), but it will catch the mistakes that actually get small sites hacked: missing security headers, weak admin logins, outdated plugins, and backups nobody ever tested.

Who this is for: owners of a WordPress site, Shopify store, small SaaS app, or agency client site who want to do a basic pass themselves before (or instead of) paying for a professional audit. What you'll get: a step-by-step checklist you can run today, with exact settings and free tools — no card, no login required for any of it.

1. Check your security headers

Security headers are instructions your server sends to browsers, telling them how to behave (e.g., "never load this site in a frame" or "only connect over HTTPS"). They're free to add and block several common attacks outright, including cross-site scripting and clickjacking.

Run your homepage through our free security headers checker or securityheaders.com and look for these:

  • Strict-Transport-Security: max-age=31536000; includeSubDomains — forces HTTPS for a year
  • X-Content-Type-Options: nosniff — stops browsers guessing file types
  • X-Frame-Options: DENY (or SAMEORIGIN) — blocks clickjacking
  • Content-Security-Policy — restricts what scripts can run on your page
  • Referrer-Policy: strict-origin-when-cross-origin — limits data leaked to other sites via links

The OWASP Secure Headers Project maintains the current reference list and exact syntax if you want to go deeper than this checklist.

If you're on WordPress, a plugin like HTTP Headers or rules in your .htaccess/Nginx config can add these in minutes. On Shopify or other hosted platforms, some headers are already set for you — check rather than assume.

2. Verify SSL/TLS is actually configured correctly

Having the padlock icon isn't the same as having SSL/TLS (the encryption protocol that protects data between your visitor's browser and your server) set up correctly. Run your domain through Qualys SSL Labs' SSL Test — it's free and gives you a letter grade.

Check for:

  • Grade A or A+. Anything below B usually means an outdated protocol or weak cipher is still enabled.
  • TLS 1.2 and 1.3 only. TLS 1.0 and 1.1 are deprecated and should be disabled — most hosts do this by default now, but older servers sometimes don't.
  • No mixed content. If any page loads images, scripts, or CSS over plain http:// instead of https://, browsers will flag it and some resources may silently fail to load.
  • Certificate isn't expiring soon. A lapsed certificate breaks HTTPS for every visitor until you renew it. Let's Encrypt auto-renews free certificates every 90 days if configured correctly — confirm that's actually happening rather than assuming it is.

3. Lock down admin and login access

The login page is the single most-attacked part of most small sites, because automated bots constantly try common username/password combinations (a technique called credential stuffing). Walk through this list for every admin account:

  1. No account uses "admin" as the username. It's the first guess in every automated attack.
  2. Two-factor authentication (2FA) is turned on for every admin account, not just the owner's.
  3. Passwords are unique and long (16+ characters) — reused passwords from other breached sites are a top way in.
  4. Login attempts are rate-limited. On WordPress, a plugin like Limit Login Attempts Reloaded, or a setting at your host, should lock out repeated failed logins.
  5. Unused admin accounts are removed, especially ones left over from a past employee, freelancer, or agency.
  6. The default login path is changed where practical. /wp-admin or /admin being public isn't a vulnerability by itself, but combined with weak rate-limiting it makes automated guessing easier.

CISA's guidance on credential-based attacks consistently ranks weak or reused passwords among the most common ways small organizations get breached — this is the cheapest fix on this entire list.

4. Confirm your backups actually work

A backup you've never restored from isn't a backup — it's a hope. Check:

  • Backups run automatically, not only when you remember to click a button.
  • At least one copy lives off your main server (a different storage provider, not just a folder on the same host) — the "3-2-1 rule" (3 copies, 2 different media, 1 offsite) is the standard reference point here.
  • You've actually restored one, even to a test/staging copy of the site. Most backup failures are discovered only during a real emergency, which is the worst possible time.
  • Backups are retained for at least 30 days. If malware sits dormant for a few weeks before triggering, a 7-day retention window means every backup is already infected by the time you notice.

5. Update plugins, themes, apps, and the platform itself

Outdated plugins are the most common entry point for small-site compromises, because once a vulnerability in a popular plugin is published, attackers scan the entire internet for sites still running the old version.

  • Log into your admin dashboard (wp-admin/plugins.php on WordPress, the Apps section on Shopify) and update everything with a pending update.
  • Delete plugins and themes you're not using — even inactive ones can be exploitable if they're still installed.
  • Spot-check your most important plugins against the National Vulnerability Database (search the plugin name) to see if a known CVE (a catalogued, publicly disclosed vulnerability) affects your installed version.
  • Confirm your CMS core (WordPress, etc.) itself is current — core updates often ship security fixes separately from plugin updates.

Your self-audit checklist at a glance

AreaWhat to checkGood sign
HeadersRun through /tools/security-headersHSTS, CSP, X-Frame-Options, X-Content-Type-Options present
SSL/TLSRun SSL Labs testGrade A/A+, TLS 1.2+, no mixed content
LoginsReview every admin account2FA on, no "admin" username, rate-limiting on
BackupsRestore a test copyAutomatic, offsite, restore actually works
Plugins/appsCheck update screen + NVDNothing outdated, nothing unused left installed

What a self-check can't catch — and why that's not a knock on you

Everything above is pattern-matching: does a setting exist, is a version current, is a header present. That catches real, common problems. What it can't catch is how your specific site's logic behaves when someone pokes at it deliberately.

Two categories a checklist structurally can't cover:

  • Broken access control — can a logged-in customer edit someone else's order by changing a number in the URL? Can a "viewer" account perform an "admin" action by hitting an API endpoint directly instead of using the menu? This is consistently the #1 risk category in the OWASP Top 10, and finding it requires a person actually trying those paths, not a scanner checking for known signatures.
  • Business logic flaws — things that are technically "working as coded" but exploitable anyway: a discount code that stacks infinitely, a password reset flow that leaks whether an email exists, a file upload that accepts a script disguised as an image. None of these trip an automated scan because nothing is technically broken — the logic itself is the bug.

This is the real difference between running a free scanner and getting a manual vs. automated penetration test: automation is fast and good at known patterns; a human tester thinks like an attacker and tries the things a checklist (or a scanner) was never told to look for.

If you want a free gut-check before deciding whether that's worth paying for, our free website security check gives you a no-login, no-card pass over your site plus a straight yes/no on anything critical.

Key takeaways

  • Run the header and SSL checks first — they're free, instant, and catch config mistakes most owners don't know exist.
  • Turn on 2FA and rate-limiting on every admin login; weak credentials remain one of the most common ways small sites get breached.
  • Actually restore a backup once — an untested backup is not a safety net.
  • Delete unused plugins/themes and update the rest; known vulnerabilities in outdated plugins are a leading cause of small-site hacks.
  • A checklist finds configuration problems; it cannot find access-control or business-logic flaws specific to how your site works — that takes a person testing it by hand.

If this checklist turns up issues you're not sure how to fix, or you want someone to actually try to break in rather than just check settings, that's exactly what Circuit is: a real security engineer manually audits your whole site and hands you a plain-English report with exact fixes, for $49, one time. No pressure either way — the checklist above is yours to use regardless.

Curious what a professional engagement actually costs beyond our own pricing? Here's a breakdown of how much a penetration test costs across different levels of depth.

Want certainty, not guesswork?

A real human security engineer audits your whole site by hand and sends a full report — every issue, its severity, and the exact fix. From $49, with a 14-day money-back guarantee.

See pricing

Common questions

Is there a free website security audit checklist for small business?
Yes — the checklist in this guide covers headers, SSL/TLS, admin login hygiene, backups, and plugin updates, and every tool referenced (SSL Labs, a headers checker, NVD) is free with no signup. It's meant as a self-serve first pass, not a replacement for a manual audit, but it will catch the most common misconfigurations on its own.
How do I audit my own website's security?
Start with the five areas in this checklist: security headers, SSL/TLS configuration, admin/login hardening (2FA, unique passwords, rate-limiting), backup testing, and plugin/theme updates. Each has a specific free tool or settings page to check, and together they cover the configuration mistakes that most commonly lead to small-site breaches.
Where can I get a free security audit checklist template?
This article functions as that template — the checklist table above lists each area, what to check, and what a pass looks like, so you can work through it line by line on your own site. You can also run the automated parts instantly with our free security headers tool and SSL Labs' test, both at no cost.
Can a DIY security checklist replace a professional audit?
No — a checklist is good at catching missing settings and outdated software, but it can't test how your specific site behaves when someone tries to break its logic, like editing another user's data or abusing a discount code. Those access-control and business-logic issues are consistently the hardest to find automatically, which is why they typically require a person manually testing the site.
What's the most common security mistake small websites make?
Outdated plugins and weak admin logins are the two most frequent issues on small sites — both are free to fix immediately. Updating everything with a pending update and turning on two-factor authentication for every admin account takes under 15 minutes and closes off the most commonly exploited entry points.

Keep reading

See what attackers see — free

Run the free passive check on your domain. No login, no impact on your site, results in seconds.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →

Published by Bug Circuit. Written with AI assistance and reviewed for accuracy before publishing.