Security Signals Check

WordPress Security Check for South African Websites

If something about your website's behaviour is bothering you, a good first step is a calm look at what the public site already reveals. We review visible security signals — certificates, insecure content, exposed errors, odd redirects and clues about unmaintained components — and explain what they do and do not mean.

This is an observational review, not penetration testing, and it cannot certify that a website is secure.

Check My WordPress Security SignalsFree to submit. No obligation.
  • Human-reviewed
  • Plain-English feedback
  • South African businesses

What this check is, and what it is not

This is a public-facing review of the security signals your website already shows to anyone who visits it. It is intended to help you decide whether you need to escalate to a proper, access-based investigation.

It is not penetration testing, vulnerability exploitation, malware removal or a certification that a site is secure. We do not attempt to access anything we have not been given permission to access, and we do not publish or exploit weaknesses.

We also try hard not to alarm you unnecessarily. Most of what we find on ordinary business websites is routine housekeeping rather than evidence of a problem, and the report is written to reflect that.

If we see something that genuinely warrants urgent attention, we say so clearly and recommend engaging your host or a security professional with proper access — not a longer report.

Reasons people ask for a security check

  • The browser shows a warning when visiting the site
  • Something about the site's behaviour has changed and nobody knows why
  • Your host or a customer mentioned a possible problem
  • The site was compromised before and you want reassurance
  • Plugins and themes have not been updated in a long time
  • A previous developer had access that was never removed
  • You handle customer information through forms and want the basics checked
  • You simply want to know where the obvious gaps are

Visible signals we review

HTTPS and certificate behaviour

Whether the certificate is valid and correctly configured, and whether visitors are consistently served over a secure connection.

Mixed content

Images, scripts or stylesheets still loading insecurely on otherwise secure pages — common on older WordPress builds.

Browser and search warnings

Whether browsers or search results show any warning about the site, which usually needs immediate attention.

Exposed errors and debug output

PHP notices, database errors, directory listings or debug information visible publicly, which reveals more than it should.

Unexpected redirects and injected content

Pages that redirect somewhere unrelated, unfamiliar scripts, or content that does not belong to your business.

Unmaintained component clues

Public signals suggesting a theme or plugin is an older or abandoned version — a risk factor rather than a verdict.

Hosting and platform signals

Observable indications about the server environment and whether basic protective layers appear to be in place.

Administrative exposure

Whether login and administrative areas are unusually exposed, noted as context rather than presented as the main defence.

Backups, update history, file integrity, user accounts and server hardening cannot be verified publicly. If those matter for your decision — and for anything beyond a first look, they do — they need an access-based review.

How WordPress security problems usually begin

A component that stopped being maintained

The most common route in is not a clever targeted attack. It is an automated script finding a known problem in a plugin or theme that has not received an update in years.

This is why the boring advice — update regularly, remove what you no longer use — is also the advice that works.

Credentials that were never tightened

Shared administrator accounts, passwords reused elsewhere, no two-factor authentication, and old accounts belonging to developers or staff who moved on years ago.

None of this is dramatic until it matters, and then it matters a great deal. It is also among the cheapest things on any security list to fix.

Too many people with too much access

WordPress has permission levels for a reason. Contributors who only publish content rarely need administrator rights, and every extra administrator is another route in.

Reviewing who has access, and at what level, costs nothing.

No tested backup

Many sites have backups running that nobody has ever restored. A backup you have not tested is a hope rather than a plan.

It is also the difference between a bad afternoon and a genuinely serious business problem.

Cleaning the symptom, not the cause

After a compromise it is tempting to remove the visible damage and move on. If the entry point is still open, the same problem tends to return within weeks.

Proper remediation means identifying how it happened, closing that route, rotating credentials, and confirming afterwards that browser and search warnings have cleared.

Submit Your Website for a Security Signals Review

Tell us the website address and what has prompted the concern. If a browser, customer or host has flagged something specific, include the exact wording if you have it.

Free to submit. No obligation. Human-reviewed feedback in plain English.

  • Free to submit
  • Human-reviewed
  • Plain-English feedback
  • South African support

What happens after you submit your website

  1. 1

    You tell us the website address and what has concerned you.

  2. 2

    We review the public site for visible security signals and warning signs.

  3. 3

    You get a plain-English summary: what we saw, what it may indicate, and what it definitely does not prove.

  4. 4

    Where the evidence warrants it, we recommend a proper access-based investigation with your host or a security professional.

If you think something is already wrong

If the site is redirecting visitors, showing content you did not publish, or triggering browser warnings, treat it as an active problem rather than waiting for a report.

At a high level: contact your hosting provider, preserve existing backups rather than overwriting them, change administrative and hosting passwords from a device you trust, and involve someone who can investigate with proper access. Then deal with the underlying cause before restoring anything.

Our malware warning-signs page covers this situation in more detail, including what to expect from a proper clean-up.

We will never ask you to send us passwords or hosting credentials to receive this review. It is done entirely from the public website.

WordPress Security Questions

Get a Calm, Honest Read on Your Website's Security Signals

Submit your website and find out which signals are worth acting on, which are routine housekeeping, and when a proper access-based investigation is the right next step.

Check My WordPress Security SignalsFree to submit. No obligation.