Is your Wix, Squarespace, or Webflow site actually secure?
Wix, Squarespace, and Webflow secure their own servers — not the forms, staff access, embedded scripts, or staging pages you set up on top. Here's how to tell a real security issue from a phishing email, and what actually needs checking on each platform.
Wix, Squarespace, and Webflow solve a different problem than you think
What the platform actually secures
Wix, Squarespace, and Webflow all run on managed infrastructure the platform controls end to end — the servers, the network, TLS termination, the CDN, DDoS protection, and the underlying application code. That part is genuinely solid. All three companies publish security and compliance documentation and patch their platform code without you doing anything.
That’s also exactly why “my site is on Wix, Squarespace, or Webflow, so it’s secure” is only half true. Infrastructure security and site security are two different layers, and a platform’s marketing and compliance pages are only ever talking about the layer they control.
What’s still on you
Everything above the infrastructure layer is configured by whoever builds and runs the site: who has editor or admin access (and whether a former contractor still does), what a contact form does with submitted data, which third-party scripts are embedded — chat widgets, analytics, ad pixels — and what they can see or touch, whether a staging or password-protected preview page is actually private or just unlisted, how CMS collection permissions are set, and which integrations hold API keys that could leak. None of that shows up on a “the platform is SOC 2 certified” page, because it isn’t the platform’s to certify.
Wix: “Your site failed a security audit” — scam or real?
How the scam email works
A pattern reported repeatedly by Wix site owners: an email arrives claiming to be from a “Wix Security team” or similar, saying the site “failed a security audit” or has “critical vulnerabilities,” with a link to log in and fix it immediately. It borrows Wix’s branding, creates urgency, and the login page is a credentials-harvesting clone. This isn’t unique to Wix — the same playbook targets Shopify, WordPress, and Squarespace owners too.
The tells are consistent: a generic greeting, a sender domain that isn’t actually wix.com once you check it closely, pressure to act within hours, and a login form embedded directly in the email flow.
What a real Wix security notice — or a real third-party audit — looks like
Wix does send genuine account and security notifications, but a legitimate one never asks you to enter your password anywhere except wix.com. If you’re unsure, don’t click through the email — open a new browser tab, log into your Wix account directly, and check notifications there. You can run the email’s sending domain through an email spoofing checker to confirm whether it authenticates as coming from Wix. A real manual security audit never arrives as a surprise email demanding an urgent login — it starts with domain ownership verification and a signed Authorization to Test, and it’s something you request, not something that lands in your inbox unprompted.
Squarespace: fake compliance emails and real “Not Secure” warnings
Is the “Squarespace Compliance” email real?
The same scam pattern shows up under Squarespace’s name, often branded as a “Compliance” or “Trust & Safety” notice claiming your site violates a policy, with a link to “resolve” it by logging in. Treat it the way you’d treat the Wix version: don’t click through, go to squarespace.com directly, and check your account’s actual notifications.
Why Squarespace shows “Not Secure” and how SSL actually works there
This one is usually not a scam — it’s a real, fixable configuration state. Squarespace provisions a free SSL certificate automatically for every site and domain, but it isn’t instant: it typically takes anywhere from about 20 minutes up to 72 hours to issue and activate after you connect or change a domain, and it can stall if your domain’s DNS isn’t fully pointed at Squarespace yet.
The usual fixes are mundane: confirm the domain’s DNS records match what Squarespace’s domain panel asks for, make sure you’re not mixing a custom domain with an old placeholder URL, and give it up to 72 hours. An SSL certificate checker will show you exactly what certificate your domain is currently serving.
Webflow: great hosting security, silent on everything you configure
What Webflow’s SOC 2 and ISO certifications actually cover
Webflow publishes real compliance documentation — SOC 2 Type II, ISO 27001 — and it’s legitimate: it covers Webflow’s own infrastructure, data centers, hosting network, and internal controls as a company. If you’re filling out a vendor security questionnaire and need to confirm your hosting provider’s posture, that documentation answers it. What it doesn’t answer is whether your specific site is configured safely — hosting security and site security are handled by different parties even though they share the same platform.
What’s yours to secure: staging, forms, embeds, and permissions
Webflow-specific gaps show up repeatedly in manual reviews: staging or password-protected pages left reachable because the password is weak or reused, or a page got published to the live domain by accident during a redesign; form submissions with no rate limiting or validation; embedded custom code blocks running with more access than intended; CMS collection permissions left broader than needed; and staff or client accounts never removed after a project ended. Webflow’s hosting helps, but it’s not a free pass — it secures the platform, not your CMS permissions, your forms, or the third-party script you dropped into an embed block eighteen months ago.
What a manual audit checks that none of these platforms do
- Leftover staff or collaborator access that should have been revoked.
- Contact and lead-gen forms with no validation or spam controls.
- Third-party embeds and integrations with more access than the site needs.
- Staging or preview pages that are technically public.
- API keys or webhook URLs exposed in front-end code or embedded scripts.
- DNS/email records (SPF, DKIM, DMARC) that leave the domain open to spoofing — exactly the gap scammers exploit when sending a fake “your site failed a security audit” email.
None of this requires a vulnerability in Wix, Squarespace, or Webflow’s own code — it’s all in the layer the site owner controls. Start with the free passive check. If that turns something up, or you just want a proper human review, Circuit ($49) is a one-time manual audit with a written report, including platform-specific fixes. Signal ($299, currently discounted) adds the team fixing high and critical issues with you, a re-test, and three months of monitoring. Every engagement starts with domain ownership verification and a signed Authorization to Test — the same thing a scam email is trying to get you to skip.
Common questions
Is the "Wix website security audit" email legit, or a scam?
What is the "Wix Security team" email, and is it real?
Is the "Squarespace Compliance" email real, or a scam?
Why is my Squarespace website showing "Not Secure"?
Does Squarespace give you an SSL certificate?
How long does Squarespace SSL take to activate?
Does Webflow’s hosting cover my site’s security?
Is Webflow secure enough on its own, or do I still need an audit?
Keep reading
Find out what’s actually exposed on your site — not the platform’s
Start with the free passive check, or book a $49 Circuit audit that covers the configuration layer Wix, Squarespace, and Webflow don’t.