All articles

5 essential security checks before launching your company website

A short checklist covering the mistakes we see most on company websites.


Not every website needs a full penetration test before launch, but some basic checks shouldn’t be skipped.

1. HTTPS everywhere

Make sure every page runs over HTTPS, old links redirect automatically, and HSTS is enabled so the site is never opened unencrypted.

2. Security headers

Headers like Content-Security-Policy, X-Frame-Options and Referrer-Policy block whole classes of attacks, such as code injection and embedding your site inside others.

3. Protect your forms

Every contact form is a target for spam and abuse. Use a hidden honeypot field, validate input on the server, and rate-limit submissions.

4. The admin panel

Enable two-factor login for everyone with admin access, give each person the least privilege they need, and remove old accounts.

5. Backups and updates

A backup you’ve never tested restoring isn’t a backup. And keep plugins and libraries updated — most breaches exploit known vulnerabilities that already have a published fix.

Bottom line

These five checks take little time compared with the cost of a single breach. We offer a free security check of your current site as part of our founding clients program.

Need help with your project?

Talk to us — the first consultation is free of commitment.