Web Development Checklist
Website Security Checklist
A website security checklist for reducing risk from outdated software, weak access control, malware, spam, missing backups, and preventable downtime.
Interactive Checklist
Track Your Progress
Check items off as you complete them. Your progress is saved in this browser so you can return to the checklist later.
Access Control
Limit powerful access to people who need it.
Use unique credentials and multifactor authentication where supported. Review staff, agency and vendor accounts against current responsibilities, with secure recovery ownership. Avoid sharing administrator accounts when individual access can provide clearer accountability and revocation.
Updates and Hardening
Reduce avoidable exposure while preserving required functionality.
Maintain an inventory of software and supported versions. Review updates and vulnerability notices, test compatibility and retain a recoverable backup. Apply hardening settings appropriate to the installation rather than copying rules that may break the editor, uploads or legitimate integrations.
SSL and Hosting
Check transport security and hosting responsibilities.
Verify that HTTPS works on public URLs and that certificate renewal is monitored. Review hosting, DNS and file-permission responsibilities with the provider. Record uptime alerts and escalation contacts so a failure can be investigated without guessing who controls the affected service.
Backups and Recovery
Prepare a recovery process before an incident.
Keep backups separate from the live environment where practical and test a restore in a safe location. Document recovery access, contacts and the order of essential steps. Protect backup data as carefully as production data because it can contain the same sensitive information.
Spam and Malware
Investigate abuse without making the site unusable.
Review suspicious redirects, unfamiliar files, unexpected search listings and form patterns together. Use reputable detection tools and escalate confirmed compromise appropriately. Test spam protections with a legitimate enquiry so controls do not silently prevent customers from contacting the business.
Ongoing Monitoring
Monitor meaningful changes and keep response ownership clear.
Review security alerts, access changes and third-party scripts on a regular schedule. Record what was investigated and the resulting action. Keep logs and incident information in appropriately restricted storage, and revisit the process after software or hosting changes.
Official References
Use the current documentation for platform-specific settings and requirements.
Need Help Completing This Checklist?
Need help completing this web development checklist? Request a practical audit and prioritized action plan.
Request an Audit