MA.
Website Security Baseline Review
Website Security Baseline Report
Executive summary
The property is in reasonable shape but carries three high-priority gaps that would turn a routine incident into an outage: DNS records are not backed up off-platform, HSTS is not enforced, and a stale administrator account remains active. None require a large project to fix — all three can be closed within a day.
18
Pass
4
Needs fix
3
Attention
25
Checks run
Findings by area
| Area | Status | Notes |
|---|---|---|
| A · DNS & domain | Needs fix | Registrar MFA on; auto-renewal on. No off-platform DNS backup. SPF present, DMARC at p=none. |
| B · Cloudflare | Pass | Proxy enabled on public records, Always Use HTTPS on, WAF at default managed ruleset. Rate limiting not configured (low risk for this site). |
| C · Security headers | Needs fix | HSTS not set. X-Content-Type-Options and Referrer-Policy present. No CSP (acceptable for now; noted). |
| D · WordPress | Attention | Core and plugins current; 2 unused plugins present. 1 stale admin account (former contractor). Wordfence installed, no critical alerts. |
| E · Recovery | Needs fix | Host backups exist but restore never tested. Recovery process undocumented. Registrar/host/Cloudflare contacts not recorded. |
The one that matters most: DNS is not backed up off-platform and the restore has never been tested. Today, a bad DNS change or a failed host would mean rebuilding from memory. Both fixes below remove that risk for good.
Recommended fixes — in priority order
| # | Fix | Priority | Effort |
|---|---|---|---|
| 1 | Export all DNS zones to a versioned off-platform backup; schedule it | P1 — do now | ~1 hr |
| 2 | Enable HSTS (start with a short max-age, then increase) | P1 — do now | ~15 min |
| 3 | Remove the stale contractor admin account; review remaining admins | P1 — do now | ~15 min |
| 4 | Run and document a test restore of site + database | P2 — this week | ~1 hr |
| 5 | Move DMARC from p=none toward quarantine after monitoring | P2 — this month | staged |
| 6 | Remove 2 unused plugins; document registrar/host/Cloudflare contacts | P3 — housekeeping | ~30 min |
What was checked, fixed, and monitored
This review ran the full 25-point baseline across DNS, Cloudflare, security headers, WordPress, and recovery. Items 1–3 above were remediated during the session; items 4–6 were handed over with instructions. A follow-up re-run of the baseline is recommended in 90 days to confirm the P1 fixes held and to re-test the restore.
This is a sample of the report from a Website Security Baseline Review.
Request a review for your site →