Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Website and certificates

HTTPS certificate

HTTPS certificate for your domain and www: issuer, validity, chain, cipher, key, signature and whether it still accepts TLS 1.0/1.1; HSTS preload if the homepage asks for it. It also checks the expiry and name of the certificates of subdomains already known from public certificate logs (at most 15, one TLS handshake each).

What it can report

Open each one to see what it means and how to fix it.

Expired certificate on a subdomain

What it means

The certificate of tienda.example.com, one of your website's other addresses, expired. It's the security certificate that lets the browser encrypt the connection to that address.

What could happen

Anyone who opens that address sees a browser security warning, and apps that connect to it (mail, VPN, portals) may stop working. Names like this are easy to forget because nobody opens them every day. If it's no longer used, it can also be a leftover worth cleaning up.

How an attacker would use it

Employees or customers who use this address learn to click through the warning because “it always says that”. Someone on the same Wi-Fi who intercepts the connection shows their own warning, and the person clicks through again.

How to fix it

  1. Decide whether tienda.example.com is still in use.Ask your team. It's often an old mail, portal or test address.
  2. If it's still used, renew its certificate in the service or hosting panel that serves it.
  3. If it isn't used, delete its record in your DNS settings so it stops existing.
  4. If it's used, turn on automatic renewal or add the date to a shared calendar.

How to check it's fixed

Ward checks the address's certificate again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Subdomain certificate expires soon

What it means

The certificate of tienda.example.com, one of your website's other addresses, expires soon. It's the certificate that lets the browser encrypt the connection to that address.

What could happen

When it expires, visitors and apps will see a security error. These names are easy to forget because nobody opens them every day. It is a low-severity notice: there is time to fix it.

How an attacker would use it

Nobody attacks here: it's an oversight. On the expiry day, the people who use this address get a red warning, and some learn to click through it, which is what someone intercepting on public Wi-Fi counts on.

How to fix it

  1. Decide whether tienda.example.com is still in use.
  2. If it is, renew its certificate in the service or hosting panel that serves it, before the date.
  3. Turn on automatic renewal if your provider offers it, or add the date to a shared calendar.
  4. If it's not used, delete its record in your DNS settings.

How to check it's fixed

Ward checks the address's certificate again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Subdomain certificate doesn't match the name

What it means

The certificate served on vpn.example.com, one of your website's other addresses, was issued for other names, not for this one. The browser warns that the connection can't be trusted.

What could happen

Whoever opens that address sees a security warning. It often means the name points to a server set up for something else, or that a service was moved and kept the old address. It's a low-severity notice, but it can also be a leftover that points to a server you no longer control.

How an attacker would use it

A name that points to a service nobody looks after is an easy place to get lost. Customers who reach it see an odd warning and either leave or learn to click through, and nobody on your team notices.

How to fix it

  1. Decide whether vpn.example.com is still in use.Ask your team. It's often an old mail, portal or test address.
  2. If it is, get a certificate that includes this name and install it where the name is served.
  3. If it isn't, delete its record in your DNS settings so it stops pointing anywhere.
  4. If you don't recognize the server it points to, tell your IT person.

How to check it's fixed

Ward checks the address's certificate again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

No HTTPS available

What it means

We tried to open a secure (HTTPS) connection to example.com and couldn't. HTTPS is what shows the padlock in the browser and encrypts what visitors send, like forms and passwords.

What could happen

Visitors see an error or the site without encryption. Anything they type can be read by someone on the same network, and browsers label the site “Not secure”, which scares customers away and hurts how Google ranks it.

How an attacker would use it

A customer connects from a café's public Wi-Fi and fills in a contact form on your site. Without encryption, someone else on that network can read what the customer typed, including their email and phone number, and may even change what the page shows.

How to fix it

  1. Check that example.com points to the right server in your DNS settings.A name that points nowhere also produces this error.
  2. Get a certificate for that name.Let's Encrypt certificates are free, and most hosts and website builders have a free “HTTPS” or “SSL” option in their dashboard.
  3. Turn on HTTPS in your hosting plan or server and install the certificate.
  4. Redirect the unencrypted address (http://) to the secure one (https://).
  5. Open example.com in a browser and check that the padlock shows.

How to check it's fixed

Ward tries the secure connection again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Expired certificate

What it means

The security certificate of example.com has expired. It's what proves the site is yours and lets the browser encrypt the connection, and it has a validity date like a passport.

What could happen

Browsers show a full-page security warning to everyone who visits, and most visitors will leave. Apps and integrations that connect to your site may also stop working. It is usually a forgotten renewal, not an attack, and it should be fixed today.

How an attacker would use it

Customers see the red warning on your site and some learn to click through it. Later, someone on the same café Wi-Fi puts a fake page in the way, which shows an equally alarming warning, and those customers click through as they always do.

How to fix it

  1. Renew the certificate today in your hosting panel or with whoever issued it.Most hosts renew with one click. If you use a free certificate, check why its automatic renewal stopped.
  2. Install the renewed certificate on the server, including the intermediate certificates the issuer gives you.
  3. Turn on automatic renewal, or put the expiry date in a shared calendar with a reminder a month before.
  4. Open example.com in a browser and check that the warning is gone.

How to check it's fixed

Ward checks the certificate's new expiry date. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Certificate expires soon

What it means

The security certificate of example.com expires soon. It's what lets the browser encrypt the connection, and it must be renewed before its validity date.

What could happen

If it isn't renewed in time, browsers will show a security warning to every visitor and most will leave. There is still time, but certificates that should renew by themselves usually fail quietly. Automatic renewal doesn't seem to be working.

How an attacker would use it

Nobody has to attack for this to hurt: on the expiry day your customers meet a red warning page. Some will learn to click through it, and that habit is what someone intercepting a connection on public Wi-Fi counts on.

How to fix it

  1. Renew the certificate now in your hosting panel or with whoever issued it.
  2. Find out why automatic renewal didn't work.Common causes: a changed DNS record, a redirect that blocks the renewal check, or an expired payment method.
  3. Install the renewed certificate on the server and check the new expiry date in the browser's padlock details.
  4. Put the next expiry date in a shared calendar, with a reminder a month before.

How to check it's fixed

Ward reads the new expiry date. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Certificate doesn't match the name

What it means

The certificate that example.com presents was issued for other names, not for this one. It's like showing an ID with someone else's name on it, and the browser warns that the connection can't be trusted.

What could happen

Visitors see a security warning when they open this address and many will leave. Nothing may have been broken into: it's often a certificate that doesn't include “www”, or a name pointing to a server set up for something else.

How an attacker would use it

Customers who see this warning get used to clicking through. Later, someone who puts themselves between a customer and your site on public Wi-Fi shows another certificate with another name, and the customer clicks through as before.

How to fix it

  1. Check which names the current certificate covers: open example.com in a browser and look at the certificate's details.The details of this finding also list the names it was issued for.
  2. Get a certificate that includes example.com, ideally together with the other names you use (for example, with and without “www”).
  3. Install it on the server or hosting plan that answers to this name.
  4. Check that the name in your DNS points to the server you intend. If you don't recognize that server, tell your IT person.
  5. Open example.com again and check that the warning is gone.

How to check it's fixed

Ward checks the certificate's names again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Incomplete certificate chain

What it means

The certificate chain of example.com is incomplete: the server presents your certificate but not the “intermediate” certificate that links it to the recognized authority. Some browsers and phones can't complete the link by themselves.

What could happen

Part of your visitors, often on phones or older systems, see a security error and give up, while others, on a computer, see nothing. That makes it hard to notice, and you lose customers without knowing. It's a configuration slip, not an attack.

How an attacker would use it

There is nobody attacking here. A customer opens your site on their phone and sees a security error, so they leave and buy from a competitor. You never hear about it because on your computer everything looks fine.

How to fix it

  1. Download the “full chain” (or “bundle”) file from whoever issued your certificate.
  2. Install that file on the server instead of the single certificate.Hosting panels usually have a field for the certificate and another for the “chain” or “CA bundle”.
  3. Restart or reload the web server, or ask your host to do it.
  4. Open example.com on a phone and on a computer to check that neither shows a warning.

How to check it's fixed

Ward checks the certificate chain again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Only old TLS versions

What it means

example.com only offers old versions of TLS, the technology that encrypts the connection. These versions have known weaknesses, and modern browsers no longer accept them.

What could happen

Browsers refuse or warn on the connection, so some customers can't open your site at all. Where it is still accepted, the encryption is weaker than it should be. Both reasons make this worth fixing soon.

How an attacker would use it

A customer connects from public Wi-Fi to your site, using the old connection type because that's all your server offers. Someone on the same network, taking advantage of its known weaknesses, can read or alter what the customer sends.

How to fix it

  1. Ask your host or IT person whether the server supports TLS 1.2 and 1.3.Any recent server does. If yours doesn't, the server's software is outdated.
  2. Turn on TLS 1.2 and 1.3 in the server's or hosting plan's settings.
  3. Turn off TLS 1.0 and 1.1.
  4. If the server can't be configured, update it or move to a hosting plan that is maintained.
  5. Open the site in a browser and check that it loads normally.

How to check it's fixed

Ward checks the connection versions again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Still accepts old TLS versions

What it means

example.com prefers a modern connection but still accepts the old versions of TLS (1.0 and 1.1) if a visitor asks for them. TLS is the technology that encrypts the connection, and those versions have known weaknesses.

What could happen

Most visitors use the modern version, so day to day nothing visibly fails. The open door is for old devices and for someone who forces a downgrade. It's a medium issue and a quick change in the server's settings.

How an attacker would use it

Someone on the same network as a customer pushes the connection to the old version, which your server still accepts. Taking advantage of its weaknesses, they can read part of what the customer sends.

How to fix it

  1. Ask your host or IT person to turn off TLS 1.0 and 1.1, leaving only 1.2 and 1.3.
  2. In your own server or hosting plan, look for the “minimum TLS version” setting and set it to 1.2.
  3. Check afterwards that the site works from a recent phone and a computer.
  4. If an old device or system you own stops working, plan to update it instead of reopening the old versions.

How to check it's fixed

Ward checks which versions are still accepted. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Certificate signed with SHA-1

What it means

The certificate of example.com is signed with SHA-1, an old method for sealing the certificate so it can't be altered. SHA-1 is considered broken for this use, and browsers and security software distrust it.

What could happen

Browsers and apps may reject the certificate and show a warning, so visitors can't use your site. It also means the certificate is older or was set up with outdated tools. Replacing it is routine.

How an attacker would use it

Because the old sealing method can be defeated with enough computing power, someone could in theory forge a certificate that looks like yours. They would use it on a copy of your site, and your customers would see the padlock.

How to fix it

  1. Ask whoever issued the certificate, or your host, to reissue it.Don't just “renew” the old one: ask for a new one with a modern signature (SHA-256 or stronger).
  2. Install the new certificate on the server in place of the old one.
  3. Check that the new certificate doesn't need an intermediate certificate that is also old.
  4. Open example.com in a browser and check the padlock.

How to check it's fixed

Ward reads the certificate's signature again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Certificate key too short

What it means

The certificate of example.com uses an RSA key that is too short. The key is the secret number behind the encryption, and today's guidance requires at least 2048 bits.

What could happen

A short key is easier to break with enough computing power, which would let someone read or forge traffic. Browsers may also warn about it. A key this short usually comes from a certificate that has been renewed for years without changing the key.

How an attacker would use it

Someone with enough computing power works out the secret behind your certificate. With it, they can pose as your website or read the data customers send you, and your customers see the padlock as always.

How to fix it

  1. Ask your host or whoever issued the certificate to create a new certificate with a new key of 2048 bits or more.ECDSA keys are also fine, if your host offers them.
  2. Make sure it's a new key, not just a renewal with the old one.Many panels have a “regenerate key” or “new private key” option.
  3. Install the new certificate on the server in place of the old one.
  4. Open example.com in a browser and check the padlock.

How to check it's fixed

Ward reads the certificate's key size again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Weak encryption negotiated

What it means

example.com negotiated a weak cipher for the connection. The cipher is the method used to scramble the data. This one lacks “forward secrecy” or relies on outdated algorithms.

What could happen

If someone records encrypted traffic today and the server's key leaks later, they could read the old recordings. It is a medium issue: day to day nothing fails, and the server can be set up to prefer stronger options.

How an attacker would use it

Someone silently records the encrypted traffic between your customers and your server for months. Later, your server's secret key leaks through another incident, and with this weak cipher they can read everything they recorded.

How to fix it

  1. Ask your host or IT person to turn on TLS 1.3 on the server.
  2. In the server's or hosting plan's settings, remove the weak ciphers and keep the modern ones.Modern ones are those that offer forward secrecy (ECDHE) and AES-GCM or ChaCha20.
  3. If your host doesn't offer these settings, ask whether a newer plan or server includes them.
  4. Check that the site works from a recent phone and a computer.

How to check it's fixed

Ward checks the negotiated cipher again. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Asks for HSTS preload but isn't listed

What it means

example.com tells browsers it wants to be on the “HSTS preload” list, a list built into browsers of sites that must always use HTTPS. Your site asks to be there but isn't on it yet.

What could happen

The first time someone visits your site from a browser that has never seen it, the connection can still start unencrypted. It's a small gap, informational only, and joining the list is optional: it is hard to undo, so don't do it casually.

How to fix it

  1. Check that all your subdomains work over HTTPS, including old ones.The list applies to every subdomain, so one without HTTPS would stop working for visitors.
  2. Check the requirements on the HSTS preload site (a long “max-age”, “includeSubDomains” and “preload”).
  3. Submit the domain at hstspreload.org once the requirements are met.
  4. Alternatively, remove “preload” from your header if you don't want to join.

How to check it's fixed

Ward looks up your domain's status on hstspreload.org. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.