← Back to Work With Me
Sample report — illustrative example, not a real client engagement
MA.
Website Security Baseline Review

Website Security Baseline Report

ClientNorthwind Web Co. (example)
Propertywww.example.com.au
Review date27 Jul 2026
ReviewerMyles Agnew
ScopePublic web, DNS, Cloudflare, WordPress
MethodBaseline Checklist v1 (25 checks)

Executive summary

The property is in reasonable shape but carries three high-priority gaps that would turn a routine incident into an outage: DNS records are not backed up off-platform, HSTS is not enforced, and a stale administrator account remains active. None require a large project to fix — all three can be closed within a day.

18
Pass
4
Needs fix
3
Attention
25
Checks run

Findings by area

AreaStatusNotes
A · DNS & domainNeeds fixRegistrar MFA on; auto-renewal on. No off-platform DNS backup. SPF present, DMARC at p=none.
B · CloudflarePassProxy enabled on public records, Always Use HTTPS on, WAF at default managed ruleset. Rate limiting not configured (low risk for this site).
C · Security headersNeeds fixHSTS not set. X-Content-Type-Options and Referrer-Policy present. No CSP (acceptable for now; noted).
D · WordPressAttentionCore and plugins current; 2 unused plugins present. 1 stale admin account (former contractor). Wordfence installed, no critical alerts.
E · RecoveryNeeds fixHost backups exist but restore never tested. Recovery process undocumented. Registrar/host/Cloudflare contacts not recorded.
The one that matters most: DNS is not backed up off-platform and the restore has never been tested. Today, a bad DNS change or a failed host would mean rebuilding from memory. Both fixes below remove that risk for good.

Recommended fixes — in priority order

#FixPriorityEffort
1Export all DNS zones to a versioned off-platform backup; schedule itP1 — do now~1 hr
2Enable HSTS (start with a short max-age, then increase)P1 — do now~15 min
3Remove the stale contractor admin account; review remaining adminsP1 — do now~15 min
4Run and document a test restore of site + databaseP2 — this week~1 hr
5Move DMARC from p=none toward quarantine after monitoringP2 — this monthstaged
6Remove 2 unused plugins; document registrar/host/Cloudflare contactsP3 — housekeeping~30 min

What was checked, fixed, and monitored

This review ran the full 25-point baseline across DNS, Cloudflare, security headers, WordPress, and recovery. Items 1–3 above were remediated during the session; items 4–6 were handed over with instructions. A follow-up re-run of the baseline is recommended in 90 days to confirm the P1 fixes held and to re-test the restore.

This is a sample of the report from a Website Security Baseline Review.

Request a review for your site →