The Website Auditor Blog
Practical articles on the web-security decisions that actually change your risk profile.
- headersheaders7 minUpdated 2026-01-14
Why Your Website Needs HSTS in 2026
One header, one config line, and downgrade attacks stop reaching your users. If your site doesn't ship HSTS in 2026, you're leaving free security on the table.
- headersheaders9 minUpdated 2026-01-10
How to Roll Out CSP in Report-Only Mode
CSP is one of the most effective XSS defenses ever shipped — and one of the most feared to deploy. Report-only mode turns a scary launch into a boring one.
- dnsdns8 minUpdated 2026-01-05
DMARC in Plain English
SPF, DKIM, DMARC. Three DNS records, one goal: stop other people from sending email as you. Here is what each one actually does — and how to turn them on without losing legitimate mail.
- securitysecurity10 minUpdated 2026-01-02
WordPress Security Hardening Checklist
WordPress powers a huge chunk of the web and, being popular, is a huge target. Most compromises exploit old, known bugs — here is what to lock down first, in order.