No-code platform security

Is your Wix, Squarespace, or Webflow site actually secure?

Wix, Squarespace, and Webflow secure their own servers — not the forms, staff access, embedded scripts, or staging pages you set up on top. Here's how to tell a real security issue from a phishing email, and what actually needs checking on each platform.

Wix, Squarespace, and Webflow all secure their own servers well — but that’s not the same as your specific site being configured safely. Two very different things get confused under “security audit” for these platforms: a phishing email impersonating the platform, and a real configuration gap you created yourself — leftover staff access, unvalidated forms, exposed staging pages, over-permissioned CMS accounts, or risky third-party embeds. Squarespace’s “Not Secure” warning is usually the second case: a real, fixable SSL/DNS issue, not an attack. Webflow’s SOC 2 and ISO certifications are real, but they cover Webflow’s own hosting infrastructure, not what you configure on top. None of these platforms audits your configuration — that’s what a manual security review checks.

Wix, Squarespace, and Webflow solve a different problem than you think

What the platform actually secures

Wix, Squarespace, and Webflow all run on managed infrastructure the platform controls end to end — the servers, the network, TLS termination, the CDN, DDoS protection, and the underlying application code. That part is genuinely solid. All three companies publish security and compliance documentation and patch their platform code without you doing anything.

That’s also exactly why “my site is on Wix, Squarespace, or Webflow, so it’s secure” is only half true. Infrastructure security and site security are two different layers, and a platform’s marketing and compliance pages are only ever talking about the layer they control.

What’s still on you

Everything above the infrastructure layer is configured by whoever builds and runs the site: who has editor or admin access (and whether a former contractor still does), what a contact form does with submitted data, which third-party scripts are embedded — chat widgets, analytics, ad pixels — and what they can see or touch, whether a staging or password-protected preview page is actually private or just unlisted, how CMS collection permissions are set, and which integrations hold API keys that could leak. None of that shows up on a “the platform is SOC 2 certified” page, because it isn’t the platform’s to certify.

Wix: “Your site failed a security audit” — scam or real?

How the scam email works

A pattern reported repeatedly by Wix site owners: an email arrives claiming to be from a “Wix Security team” or similar, saying the site “failed a security audit” or has “critical vulnerabilities,” with a link to log in and fix it immediately. It borrows Wix’s branding, creates urgency, and the login page is a credentials-harvesting clone. This isn’t unique to Wix — the same playbook targets Shopify, WordPress, and Squarespace owners too.

The tells are consistent: a generic greeting, a sender domain that isn’t actually wix.com once you check it closely, pressure to act within hours, and a login form embedded directly in the email flow.

What a real Wix security notice — or a real third-party audit — looks like

Wix does send genuine account and security notifications, but a legitimate one never asks you to enter your password anywhere except wix.com. If you’re unsure, don’t click through the email — open a new browser tab, log into your Wix account directly, and check notifications there. You can run the email’s sending domain through an email spoofing checker to confirm whether it authenticates as coming from Wix. A real manual security audit never arrives as a surprise email demanding an urgent login — it starts with domain ownership verification and a signed Authorization to Test, and it’s something you request, not something that lands in your inbox unprompted.

Squarespace: fake compliance emails and real “Not Secure” warnings

Is the “Squarespace Compliance” email real?

The same scam pattern shows up under Squarespace’s name, often branded as a “Compliance” or “Trust & Safety” notice claiming your site violates a policy, with a link to “resolve” it by logging in. Treat it the way you’d treat the Wix version: don’t click through, go to squarespace.com directly, and check your account’s actual notifications.

Why Squarespace shows “Not Secure” and how SSL actually works there

This one is usually not a scam — it’s a real, fixable configuration state. Squarespace provisions a free SSL certificate automatically for every site and domain, but it isn’t instant: it typically takes anywhere from about 20 minutes up to 72 hours to issue and activate after you connect or change a domain, and it can stall if your domain’s DNS isn’t fully pointed at Squarespace yet.

The usual fixes are mundane: confirm the domain’s DNS records match what Squarespace’s domain panel asks for, make sure you’re not mixing a custom domain with an old placeholder URL, and give it up to 72 hours. An SSL certificate checker will show you exactly what certificate your domain is currently serving.

Webflow: great hosting security, silent on everything you configure

What Webflow’s SOC 2 and ISO certifications actually cover

Webflow publishes real compliance documentation — SOC 2 Type II, ISO 27001 — and it’s legitimate: it covers Webflow’s own infrastructure, data centers, hosting network, and internal controls as a company. If you’re filling out a vendor security questionnaire and need to confirm your hosting provider’s posture, that documentation answers it. What it doesn’t answer is whether your specific site is configured safely — hosting security and site security are handled by different parties even though they share the same platform.

What’s yours to secure: staging, forms, embeds, and permissions

Webflow-specific gaps show up repeatedly in manual reviews: staging or password-protected pages left reachable because the password is weak or reused, or a page got published to the live domain by accident during a redesign; form submissions with no rate limiting or validation; embedded custom code blocks running with more access than intended; CMS collection permissions left broader than needed; and staff or client accounts never removed after a project ended. Webflow’s hosting helps, but it’s not a free pass — it secures the platform, not your CMS permissions, your forms, or the third-party script you dropped into an embed block eighteen months ago.

What a manual audit checks that none of these platforms do

  • Leftover staff or collaborator access that should have been revoked.
  • Contact and lead-gen forms with no validation or spam controls.
  • Third-party embeds and integrations with more access than the site needs.
  • Staging or preview pages that are technically public.
  • API keys or webhook URLs exposed in front-end code or embedded scripts.
  • DNS/email records (SPF, DKIM, DMARC) that leave the domain open to spoofing — exactly the gap scammers exploit when sending a fake “your site failed a security audit” email.

None of this requires a vulnerability in Wix, Squarespace, or Webflow’s own code — it’s all in the layer the site owner controls. Start with the free passive check. If that turns something up, or you just want a proper human review, Circuit ($49) is a one-time manual audit with a written report, including platform-specific fixes. Signal ($299, currently discounted) adds the team fixing high and critical issues with you, a re-test, and three months of monitoring. Every engagement starts with domain ownership verification and a signed Authorization to Test — the same thing a scam email is trying to get you to skip.

Common questions

Is the "Wix website security audit" email legit, or a scam?
In most reported cases it’s phishing, not a real notice from Wix. The pattern: an email claims your site "failed a security audit" or has "critical vulnerabilities," creates urgency, and pushes you to log in through a link inside the email. Wix does send real account notifications, but never asks for your password anywhere except wix.com. If you get one, don’t click through — log into wix.com directly in a new tab and check your account notifications there instead.
What is the "Wix Security team" email, and is it real?
There’s no dedicated "Wix Security team" that emails site owners out of the blue demanding an urgent login — that framing is one of the most common versions of the scam pattern above. Check the actual sending domain (not just the display name); it’s rarely wix.com once you look closely. You can run it through an email spoofing checker to confirm whether it authenticates as genuinely coming from Wix.
Is the "Squarespace Compliance" email real, or a scam?
The same scam pattern exists under Squarespace’s name, usually branded as a "Compliance" or "Trust & Safety" notice claiming a policy violation with a link to "resolve" it. Treat it the same way: don’t click through, go to squarespace.com directly, and check your account’s actual notifications there.
Why is my Squarespace website showing "Not Secure"?
This is usually not a scam — it’s a real, fixable configuration state, most often because your SSL certificate hasn’t finished issuing yet or your domain’s DNS isn’t fully pointed at Squarespace. It can also happen if an old placeholder URL is still linked somewhere alongside your custom domain. Check the domain panel first; if DNS is confirmed correct and it’s still showing after a few days, that’s worth investigating.
Does Squarespace give you an SSL certificate?
Yes. Squarespace automatically provisions a free SSL certificate for every site and connected custom domain — you don’t buy or install one separately. It only fails to show as active if the certificate hasn’t finished issuing or the domain’s DNS records aren’t correctly pointed at Squarespace.
How long does Squarespace SSL take to activate?
Typically anywhere from about 20 minutes up to 72 hours after you connect or change a domain, depending on DNS propagation. If it’s been longer than 72 hours and your DNS records match what Squarespace’s domain panel asks for, the delay usually isn’t going to resolve on its own.
Does Webflow’s hosting cover my site’s security?
It covers Webflow’s own infrastructure — servers, network, TLS, and the platform’s SOC 2 Type II and ISO 27001 certifications are real and legitimate. It doesn’t cover what you configure on top: your CMS collection permissions, staff and client access, form validation, or the third-party scripts you’ve dropped into embed blocks. Webflow hosting helps, but it’s not a free pass on the rest.
Is Webflow secure enough on its own, or do I still need an audit?
Webflow’s infrastructure is solid, but that’s a different layer from your site’s configuration. Common findings on Webflow sites include staging or password-protected pages accidentally left public, forms with no rate limiting, over-permissioned CMS editor accounts, and risky embedded scripts — none of which Webflow’s own compliance documentation checks, because it isn’t Webflow’s to check.

Keep reading

Find out what’s actually exposed on your site — not the platform’s

Start with the free passive check, or book a $49 Circuit audit that covers the configuration layer Wix, Squarespace, and Webflow don’t.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →