Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Website and certificates

Public website

A single visit to your homepage, like a browser: redirect to HTTPS, HSTS, security headers, visible versions, technologies, cookies, forms, legal pages and signs of a hacked site (hidden spam, redirects to another domain).

What it can report

Open each one to see what it means and how to fix it.

Website doesn't use HTTPS

What it means

When someone opens example.com, the connection isn't encrypted (it uses http:// instead of https://). Encryption is what shows the padlock in the browser and keeps what visitors send private.

What could happen

Anything visitors type, such as contact forms, logins or orders, can be read by others on the same network. Browsers label the site “Not secure”, which scares customers away and can lower your ranking in Google.

How an attacker would use it

A customer connects from public Wi-Fi at an airport and fills in your contact or order form. Without encryption, someone on the same network can read the name, email and phone number they typed, and even alter the page before it reaches them.

How to fix it

  1. Get an HTTPS certificate for your domain.Let's Encrypt certificates are free, and most hosts and website builders have a free “HTTPS” or “SSL” option in their dashboard.
  2. Install it in your hosting plan or on the server.
  3. Redirect every http:// address to its https:// equivalent.
  4. Check that the images, scripts and forms of your pages also load over https://, otherwise the browser will complain.
  5. Open your site in a browser and check that the padlock shows.

How to check it's fixed

Ward opens your homepage again and checks that it ends on https://. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

No HSTS

What it means

HSTS is an instruction that example.com sends to browsers: “from now on, always use the encrypted version of this site”. Your site works over HTTPS but doesn't send that instruction.

What could happen

A visitor who types your address without “https” starts on the unencrypted version for a moment, and that is the moment someone on the same network can interfere. It is a medium issue and a one-line change, once HTTPS works everywhere.

How an attacker would use it

A customer on a café's Wi-Fi types your address without “https”. Someone on that network answers the first, unencrypted request and sends the customer to a copy of your site that never switches to HTTPS, so the customer enters their details on a fake.

How to fix it

  1. Make sure your whole site, and its subdomains if you use them, works over HTTPS.
  2. Ask your host or IT person to add the “Strict-Transport-Security” header, first with a short time, for example one day (max-age=86400).Hosting panels often have a toggle called “HSTS” or “Force HTTPS”.
  3. If everything keeps working, raise it to one year (max-age=31536000).
  4. Add “includeSubDomains” only if every subdomain also has HTTPS, because otherwise it will stop working.

How to check it's fixed

Ward reads the header from your homepage. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

HSTS lasts too little

What it means

HSTS tells browsers to always use the encrypted version of example.com, but only for a set time, which is shorter than the six months we look for.

What could happen

Once that time passes without a visit, the browser forgets the instruction, and the first visit after that starts unencrypted again. It's a low-severity gap: the protection exists, but it's weaker than it could be.

How an attacker would use it

A customer who only visits a few times a year comes back after the instruction expired and types your address without “https” on public Wi-Fi. Someone on that network can interfere with that first request, and the customer lands on a copy of your site.

How to fix it

  1. Ask your host or IT person to raise the HSTS “max-age” to one year (31536000 seconds).
  2. In a hosting panel, look for the “HSTS” setting and choose the longest duration offered.
  3. Check that your whole site, including subdomains if you add “includeSubDomains”, works over HTTPS.

How to check it's fixed

Ward reads the header from your homepage. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

WordPress plugins and themes visible

What it means

Your homepage shows WordPress plugins and themes. Plugins are add-ons that give a site extra features, and their names appear in the page's public code.

What could happen

This is informational: there's nothing wrong with using plugins. What matters is that anyone can see which ones you have, so an outdated plugin is easier to spot. Most hacked WordPress sites get in through a plugin that wasn't updated.

How to fix it

  1. In the WordPress admin, open the Plugins page and update everything that has an update.Make a backup first, or ask your host to do it.
  2. Delete the plugins and themes you don't use, not just deactivate them.
  3. Turn on automatic updates for the plugins you trust, which the Plugins page offers for each one.
  4. Ask whoever maintains your site to review the plugins every few months.

How to check it's fixed

This finding is informational and may stay in the list. Keeping plugins updated is what protects you, and Ward flags known outdated components separately.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Missing security headers

What it means

Your website doesn't send some “security headers”: short instructions that tell the browser how to protect visitors from common tricks, like running injected code or showing your page inside someone else's site.

What could happen

These headers are an extra layer, not a basic need. Without them, a flaw elsewhere on the site is easier to abuse, and your pages can be embedded in other sites. The severity is low or informational: there is no rush.

How an attacker would use it

Someone loads your page inside an invisible frame on their own site and gets your visitors to click on a button of yours without knowing it. A frame-protection header would make the browser refuse to show it.

How to fix it

  1. Ask whoever maintains your website, or your host, to add the missing headers.
  2. Start with the easy ones: “X-Content-Type-Options: nosniff” and “Referrer-Policy”.Many hosting panels and security plugins have a toggle for them.
  3. For frame protection, add “X-Frame-Options” or the “frame-ancestors” part of the Content-Security-Policy.
  4. Leave “Content-Security-Policy” for last, in “report-only” mode first: a wrong one can break your site.
  5. Test your pages in a browser after each change.

How to check it's fixed

Ward reads the headers from your homepage. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Server announces its software version

What it means

Your server announces which software and version it runs. It does so in every reply, so anyone can read it without any special access.

What could happen

Knowing the exact version, an attacker can tell at once whether yours has known flaws, without searching. It doesn't create a flaw by itself and the severity is low, but it saves them work. Updating the software matters more than hiding the label.

How an attacker would use it

Someone sweeping many websites reads that yours runs an old version of a popular server. They put yours on the list of targets for that version's known weaknesses, long before anyone tries to log in.

How to fix it

  1. Ask whoever manages the server to stop announcing the version.In nginx it is “server_tokens off”, in Apache “ServerTokens Prod” and in PHP “expose_php = Off”.
  2. On shared hosting, check the panel for a “hide server version” option, or ask support.
  3. More important: make sure the software itself is up to date.
  4. Check the headers again after the change, from your browser's developer tools or via Ward.

How to check it's fixed

Ward reads the headers from your homepage. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Unsupported software on the website

What it means

PHP 7.4.33 is used by your website, and that version no longer receives security fixes from its makers. PHP is the programming language many websites, WordPress and online stores run on.

What could happen

Flaws found from now on stay open, and the old ones are public. Outdated software is one of the most common ways small-business websites get taken over, which can mean defaced pages, stolen customer data or a warning from Google. Fixing it is the priority here.

How an attacker would use it

Automated programs scan the web looking for sites running old versions with published flaws. Yours turns up, and the site is taken over without anybody targeting your company: it gets spam pages, redirects or stolen customer data.

How to fix it

  1. Make a full backup of the site and database, or ask your host to do it.
  2. Update your content system (for example WordPress), its theme and its plugins first, so they support the new PHP.
  3. In your hosting panel, look for the PHP version setting and choose a supported version.Many panels have a “PHP version” option; if yours doesn't, ask support.
  4. Test the site and fix what breaks. Roll back if needed and ask the plugin developers for updates.

How to check it's fixed

Ward reads the PHP version again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

CMS version visible

What it means

Your website announces that it uses wordpress, in a label of its code that visitors don't see but anyone can read. wordpress is the system your site's content is managed with.

What could happen

Showing the version doesn't create a flaw. It only helps someone who is looking for sites with a known problem find yours quickly. It's informational: what protects you is keeping the system and its plugins updated.

How to fix it

  1. Update wordpress and its plugins to the latest version.That is the real fix.
  2. Hide the “generator” label from the page code, using your theme's settings or a security plugin.
  3. Check the page again after hiding it.

How to check it's fixed

This finding is informational and may stay in the list. Hiding the label is optional; keeping the system updated is what counts.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Session cookies without protection

What it means

Your website sets cookies without some protection flags. Cookies are small files the site leaves in the browser, and some of them keep visitors logged in.

What could happen

A session cookie that travels unprotected or can be read by code on the page is what keeps a person logged in. If someone gets hold of it, they can act as that person without a password. The risk depends on the rest of the site, hence medium.

How an attacker would use it

A customer logged into your portal uses public Wi-Fi. Because the session cookie isn't marked as secure, it travels where someone on that network can pick it up, and they enter the customer's account as if they were them.

How to fix it

  1. Ask whoever maintains your website to mark the cookies with “Secure”, “HttpOnly” and “SameSite=Lax”.“Secure” keeps them off unencrypted connections, “HttpOnly” hides them from page code, and “SameSite” limits cross-site use.
  2. In WordPress and similar systems, a security plugin or the theme/server settings usually offers these options.
  3. Leave “HttpOnly” off only for cookies your site's own scripts must read.
  4. Check the cookies again in your browser after the change.

How to check it's fixed

Ward reads the cookies from your homepage again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Form sends data without encryption

What it means

Your page uses HTTPS, but a form on it sends what the visitor types to an unencrypted address (http://). The page looks safe, while the data takes the unprotected route.

What could happen

Names, emails, phone numbers or whatever else the form collects can be read on the way, and the browser may warn the visitor before sending. For a contact or order form, that is a real leak of customer data, so it should be fixed soon.

How an attacker would use it

A customer on public Wi-Fi fills in your quote form, which shows the padlock. When they press send, the data goes out unencrypted, and someone on that network reads their name, phone number and what they asked for.

How to fix it

  1. Find the form in the technical details: the address in “action” starts with http://.
  2. Change that address to https://, in the page, the theme or the form plugin's settings.
  3. Check that the new address works over HTTPS, otherwise the form will fail.
  4. Send a test submission and check that it arrives.

How to check it's fixed

Ward reads the form's address from your homepage again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Script loaded without encryption

What it means

Your page loads a script (a piece of code) from an unencrypted address (http://), even though the page itself uses HTTPS. That's called “mixed content”.

What could happen

Browsers often block that script and the page can break or lose features, such as a map, a chat or a payment button. Because it travels unencrypted, someone on the way could also change it, and a changed script runs inside your page with your visitors watching it.

How an attacker would use it

A customer uses public Wi-Fi to open your page. Someone on that network swaps the unencrypted script for their own, which runs inside your page. It can show a fake login box or capture what the customer types.

How to fix it

  1. Find the script address in the technical details.
  2. Change it to https:// in the page, the theme or the plugin that adds it.
  3. If the provider of that script doesn't offer HTTPS, replace the service.
  4. Reload the page and check in the browser that the padlock has no warning.

How to check it's fixed

Ward reads the page's scripts again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Hidden spam on the home page

What it means

Your homepage contains links or blocks that visitors can't see but search engines read, about casinos, betting, pharmacy or loans. It's the typical sign of a hacked website.

What could happen

Attackers are using your site's good reputation to promote theirs. Google can mark your site as dangerous or drop it from results, customers may see warnings, and the intruders may also have access to your data. It is serious and should be treated as a break-in.

How an attacker would use it

Someone gets into your site through an outdated plugin or a stolen password and plants hidden pages. Your visitors notice nothing, but search engines show your domain for casino and pharmacy searches. Your reputation sinks, and the same access could be used for worse.

How to fix it

  1. Ask whoever maintains your site, or your host, to restore a clean backup from before the infection.
  2. Update the content system, the theme and all plugins, and delete the ones you don't use.
  3. Change every password: site admin, hosting, FTP and database. Delete users you don't recognize.
  4. Look for how they got in, such as an old plugin or a shared password. Otherwise it will happen again.
  5. Check Google Search Console for security warnings and request a review once the site is clean.

How to check it's fixed

Ward reads your homepage again and looks for the hidden content. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Website redirects to another domain

What it means

When someone opens example.com, they end up at otro-dominio.com, which isn't your domain. It's normal if you set it up, for example an online store on another platform.

What could happen

If you set it up on purpose, nothing is wrong. If you didn't, it's what happens after someone takes over your hosting or DNS. That is why it's worth confirming, and why the severity is medium until you do.

How an attacker would use it

Someone takes over your hosting for a moment and adds a redirect on your homepage. Your customers type your usual address and land on a page that looks similar, where they enter their details or are offered a fake payment. They blame your company.

How to fix it

  1. Ask your team and your web provider whether the redirect to this address is intentional.
  2. If it is, mark the finding as an accepted risk, with a note saying why.
  3. If it isn't, check your hosting and DNS for redirect rules you don't know, and remove them.
  4. Change every password (hosting, website admin, DNS and registrar) and turn on two-step verification.
  5. Ask your provider to restore a clean copy if the site was changed, and scan it for hidden code.

How to check it's fixed

Ward opens your homepage again and follows the redirects. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Legal pages not found

What it means

We don't see links on your homepage to some usual legal pages. These pages say who runs the site, what you do with visitors' data and how cookies are used. This is a guide: we only read the homepage, and the links may exist elsewhere.

What could happen

A privacy policy is expected, and legally required in several places, when a site collects personal information, even through a contact form. Missing pages can cost you customers' trust and expose you to complaints. The severity is low, and it's mostly a matter of publishing the texts.

How an attacker would use it

It isn't something an attacker uses against you. The exposure is on the legal side: a customer or a competitor who finds no privacy policy next to your forms can file a complaint with the regulator, and you would have to prove what you do with the data.

How to fix it

  1. Check your site's footer: the pages may exist but with other names, or not be linked from the homepage.
  2. If they don't exist, have them written for your business.A lawyer or a specialized advisor is best. Generic generators can be a starting point, but they need review.
  3. Publish them as pages on your site.
  4. Link them from the footer of every page, and next to any form that collects personal data.
  5. Make sure the cookie notice matches the cookies your site really sets.

How to check it's fixed

Ward reads the links on your homepage again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

vosotros

Example with sample data. In your dashboard, the explanation uses your own domain and details.