Why a small website is also a target
"Who would want to hack my site?" is a common question among business owners. The uncomfortable answer is that nobody has to choose you: automated attacks sweep the internet looking for known flaws and get in wherever they find an open door, regardless of the company's size.
The consequences, however, are personal: injected spam links that sink your rankings, fraudulent emails sent from your domain, a red "dangerous site" warning in the browser, customer data leaked from a form, or a hijacked website. Recovering costs far more than preventing.
10 common security flaws in business websites
1. Outdated software, plugins and themes
In WordPress and other content management systems, every plugin is a separate program. Old versions have public vulnerabilities that bots test every day. Unused plugins should be deleted, not just deactivated.
2. Downloadable configuration files or backups
Files such as .env, .git folders, server configuration files or .zip and .sql backups inside the public folder can be downloaded just by guessing their name, and they sometimes contain passwords. The server must explicitly deny them and the deployment must exclude them.
3. Passwords and API keys inside the code
Storing credentials in the code or pushing them to a repository is one of the costliest mistakes: even if they're deleted later, they remain in the history. Credentials belong in environment variables or secret managers, and if any were exposed, they're changed immediately.
4. HTTPS not enforced and no HSTS
Having an SSL certificate isn't enough. The whole site must redirect to HTTPS, and the Strict-Transport-Security (HSTS) header tells the browser never to connect without encryption again.
5. Missing or duplicated security headers
HTTP headers tell the browser how to protect your visitors: Content-Security-Policy limits which scripts can run, frame-ancestors or X-Frame-Options prevent your site from being embedded in fraudulent pages, and X-Content-Type-Options, Referrer-Policy and Permissions-Policy close other doors. When the hosting, the CDN and the application each add their own copy, you get duplicated or contradictory headers that scanners penalize.
6. Forms without bot protection
An unverified form receives spam daily and can be used to send emails in your name. It's protected with an anti-bot challenge (such as Cloudflare Turnstile or reCAPTCHA), server-side validation and rate limits.
7. Exposed admin panels
The admin login page at its default address, publicly listable users, weak passwords and no two-step verification are the favorite combination for brute-force attacks. In WordPress it's also worth closing xmlrpc.php if it isn't used and hiding the user list from the public API.
8. Neglected DNS and domain
Your domain is the foundation of everything. It should have a transfer lock, auto-renewal, notification emails someone actually reads and, where the provider allows it, DNSSEC enabled with its DS record at the registrar, so nobody can forge your site's DNS responses. SPF, DKIM and DMARC records also protect your email against spoofing.
9. Backups nobody has tested
A backup stored on the same server is useless if the server fails or is compromised. Backups must be automatic, stored off the server, free of credentials in public places and, above all, tested: a backup that can't be restored isn't a backup.
10. Nobody is watching the site
The most common failure of all is not finding out. A site can spend weeks with an exposed file, a certificate about to expire or injected spam before anyone notices. Security needs automated monitoring with alerts.
How a website's security is verified
- Mozilla HTTP Observatory: analyzes security headers for free and assigns a grade from F to A+.
- Search Console's Security issues report: warns if Google detects hacking or malware.
- OWASP Top 10: the international reference for the most critical web application risks.
- Manual and automated review: checking that sensitive files return an error, that there are no credentials in the code and that headers arrive once, with the right value.
Why it isn't a job for beginners
Web security is a balancing act. A content security policy that's too strict blocks the payment form, analytics or chat; one that's too loose protects nothing. A header that stops other sites from using your resources can break your link previews on WhatsApp if it's also applied to images. And on a modern site, headers can be set in several layers (server, hosting, CDN and application) that have to be coordinated.
Fixing these points requires understanding how they interact, testing each change before publishing it and verifying the result on the real site. Done blindly, a security "fix" can leave the website broken or, worse, give a false sense of protection.
Continuous security: monitoring and maintenance
Security isn't a certificate you get once. Every update, every new plugin and every change of provider can open a door. That's why verification has to be automatic. It's the system I use on my own site and can set up on yours: before publishing, it checks that no configuration file is exposed, and a guardian checks the live site's headers, sensitive files and certificate every day, raising an alert if anything changes.
How Erick Hernández Arias can help
After 18 years building and maintaining websites for companies in the Dominican Republic, Puerto Rico and the United States, I build security in from the design stage: properly configured headers, protected forms, credentials kept out of the code, automatic backups and daily monitoring. If your site already exists, I can review its state and fix what's needed; if you're building a new one, it's born protected. See services and maintenance plans.
Frequently asked questions
Why would anyone attack a small company's website?
Because most attacks are automated: bots that sweep the internet testing known flaws on thousands of sites at once. They don't choose you; they exploit any open door to send spam, inject links or steal data.
Does having SSL mean my website is secure?
No. SSL encrypts the connection, but it doesn't protect against outdated software, exposed files, weak passwords or unprotected forms. It's a minimum requirement, not a guarantee.
What are security headers?
They're instructions the server sends to the browser to protect visitors, such as Content-Security-Policy, Strict-Transport-Security or X-Content-Type-Options. You can check them for free with Mozilla HTTP Observatory.
How often should a website's security be reviewed?
Monitoring should be continuous and automated, with alerts. On top of that, run a full review after every major change and at least once a quarter, and apply security updates as soon as they're released.