5 فحوصات أمنية أساسية قبل إطلاق موقع شركتك
5 essential security checks before launching your company website
قائمة قصيرة تغطي أكثر الأخطاء التي نراها في مواقع الشركات.
A short checklist covering the mistakes we see most on company websites.
لا يحتاج كل موقع إلى اختبار اختراق كامل قبل الإطلاق، لكن هناك فحوصات أساسية لا يصح تجاهلها.
1. HTTPS في كل مكان
تأكد أن كل صفحة تعمل عبر HTTPS، وأن الروابط القديمة تُحوَّل تلقائيًا، وفعّل HSTS حتى لا يُفتح الموقع بدون تشفير.
2. رؤوس الأمان
رؤوس مثل Content-Security-Policy وX-Frame-Options وReferrer-Policy تمنع فئات كاملة من الهجمات، مثل حقن الأكواد وتضمين موقعك داخل مواقع أخرى.
3. حماية النماذج
كل نموذج تواصل هدف للرسائل المزعجة والاستغلال. استخدم حقلًا مخفيًا لاصطياد البوتات، وتحقق من المدخلات في الخادم، وحدّد عدد الطلبات المسموح بها.
4. لوحة التحكم
فعّل التحقق بخطوتين لكل من يدخل لوحة التحكم، وامنح كل شخص أقل صلاحية يحتاجها فقط، واحذف الحسابات القديمة.
5. النسخ الاحتياطي والتحديثات
النسخة الاحتياطية التي لم تُجرَّب استعادتها ليست نسخة احتياطية. وحدّث الإضافات والمكتبات بانتظام، فأغلب الاختراقات تستغل ثغرات معروفة لها إصلاح منشور.
خلاصة
هذه الفحوصات الخمسة تستغرق وقتًا قليلًا مقارنة بتكلفة اختراق واحد. نقدّم فحصًا أمنيًا مجانيًا لموقعك الحالي ضمن برنامج العملاء المؤسسين.
Not every website needs a full penetration test before launch, but some basic checks shouldn’t be skipped.
1. HTTPS everywhere
Make sure every page runs over HTTPS, old links redirect automatically, and HSTS is enabled so the site is never opened unencrypted.
2. Security headers
Headers like Content-Security-Policy, X-Frame-Options and Referrer-Policy block whole classes of attacks, such as code injection and embedding your site inside others.
3. Protect your forms
Every contact form is a target for spam and abuse. Use a hidden honeypot field, validate input on the server, and rate-limit submissions.
4. The admin panel
Enable two-factor login for everyone with admin access, give each person the least privilege they need, and remove old accounts.
5. Backups and updates
A backup you’ve never tested restoring isn’t a backup. And keep plugins and libraries updated — most breaches exploit known vulnerabilities that already have a published fix.
Bottom line
These five checks take little time compared with the cost of a single breach. We offer a free security check of your current site as part of our founding clients program.