Website safety review

Website safety review for businesses that need customer trust and scam resilience

A non-invasive public review of your business website, HTTPS setup, browser security headers, security contact signals and basic scam-risk exposure.

What this review covers

This review is designed for businesses that want practical website safety observations before spending money on a larger security project. It does not require admin access and does not attempt to break into systems.

  • HTTPS and HSTS
  • Content Security Policy
  • X-Frame-Options
  • Referrer Policy
  • Permissions Policy
  • security.txt
  • Robots and sitemap signals
  • Visible contact and company trust signals
  • Public scam-risk notes

Buyer, inputs and deliverables

This service is for a business owner, website manager or agency that needs a time-specific review of one public website. Provide the website URL, one email domain and the customer-trust or scam concern. The Starter deliverable is a prioritised PDF report covering the public website, HTTPS, browser headers, email-domain signals and practical recommendations.

For background before ordering, see how to check whether a link is safe and phishing protection for small business.

Sample output

Example finding: "Strict-Transport-Security header not detected. Priority: medium. Business impact: first-time visitors do not receive the browser's HTTPS-only instruction from this domain. Recommendation: confirm HTTPS coverage for all subdomains before enabling an appropriate HSTS policy."

See the sample report format.

Useful before a larger cyber project

The output helps you decide what to fix now, what to monitor and what may need a deeper penetration test or vulnerability assessment later. It is especially useful for booking websites, online shops, consultants, agencies and businesses that receive enquiries or payments online.

Need implementation?

Custom quote
Quote

If you need a website, web app or internal business tool built or improved, request a custom software quote.

Website review FAQ

Do you need website admin access?

No. The standard review is remote and non-invasive and uses public website and domain evidence.

Is this a penetration test?

No. It does not exploit vulnerabilities, bypass authentication or test private systems.

What is excluded?

Code changes, server configuration, remediation, penetration testing and additional websites are not included unless separately quoted.

How do I confirm scope?

Use the Business enquiry form with the public website and concern. Do not submit credentials or private documents.