Skip to main content

All articles

How to Tell If a Website Is Secure (And Why So Many Small Business Sites Aren't)

7 min read

Most small business owners have no idea whether their own website is actually secure. They see a padlock in the address bar, assume everything's fine, and hope for the best. That assumption is the single biggest reason UK small business sites get hacked. Here's the two-minute check anyone can run — and why so many WordPress and Wix sites quietly fail it.

The quick way to check right now

You don't need to be technical to spot most of the warning signs. Open your website in a normal browser tab and run this list:

  1. Is there a padlock next to the URL? No padlock (or a red warning triangle) means the site isn't even using HTTPS. In 2026 that's a dealbreaker — Chrome actively labels these sites as "Not Secure".
  2. Click the padlock and check the certificate. It should say the connection is secure and the certificate is valid. An expired or self-signed certificate is a red flag.
  3. Look for "mixed content" warnings. If some images or scripts load over plain HTTP while the page is HTTPS, browsers will flag it. It usually means someone forgot to update old links after moving to HTTPS.
  4. Try loading /wp-admin or /wp-login.php. If a login page appears, your site is running WordPress with a public admin panel. That's the single most-attacked surface on the web.
  5. Google your own business name. If Google shows a "This site may be hacked" or "Deceptive site ahead" warning, you've already been compromised.
  6. Does the site feel old or plugin-heavy? Chat widgets that break, cookie banners layered on cookie banners, forms that don't send — all signs of an unmaintained plugin stack quietly rotting.

If any of those raise a flag, the rest of this article explains what's actually going on underneath.

A padlock doesn't mean 'secure'

This is the most common misconception we hear. The padlock icon only tells you one thing: the connection between your browser and the website is encrypted, so nobody on the same Wi-Fi can read the data in transit. That's it.

It says nothing about whether the website itself is safe. A hacked WordPress site serving malware to visitors can — and usually does — have a perfectly valid padlock. HTTPS is the bare minimum, not the finish line. If a web designer is selling "SSL security" as a feature in 2026, they're either behind the times or hoping you don't know the difference.

Why WordPress and Wix sites are the most common target

WordPress powers roughly 40% of the web, which makes it the single largest target for automated attacks. The vast majority of small business breaches follow the same script every time: an outdated plugin, a forgotten admin account with a weak password, or a cheap theme downloaded from a dubious source.

The problem isn't WordPress itself — it's that a typical small business site runs 15-30 plugins from different authors, each one a potential entry point. Miss a single security update for a couple of weeks and bots will find you. We cover the wider trade-offs in our static vs WordPress and Wix comparison, but security is the part small business owners underestimate most.

Wix and Squarespace are more locked down because the platform manages updates for you, but they still expose authenticated admin surfaces, third-party app marketplaces, and shared infrastructure — meaning a breach elsewhere on the platform can still affect your site.

Once a "This site may be hacked" warning appears in Google search results, the damage isn't just the hack itself. Rankings collapse almost immediately, and the trust label lingers for months even after cleanup. For a small business relying on local search, that can be worse than any single sale lost.

Why hand-coded sites are structurally harder to compromise

A static, hand-coded website works completely differently. Each page is delivered as a pre-built HTML file from a CDN. There's no admin panel to brute-force, no plugin chain to exploit, no database queries running on every page load, and no user accounts to phish.

That's not marketing — it's just architecture. The attack surface is genuinely tiny compared to a plugin-based CMS. You could leave a well-built static site running untouched for years and it would remain as secure as the day it shipped, because there's simply nothing running on the server for an attacker to talk to.

That doesn't make hand-coded sites bulletproof — nothing is — but it removes the most common entry points that plague small business sites in the first place.

What to ask before you hire a web designer

If you're about to commission a new site (or you're already unsure about your current one), these are the questions worth asking any designer or agency before signing anything:

  • What CMS or platform will my site actually run on, and why that one?
  • Who is responsible for security updates, and how quickly are they applied?
  • How will the site be backed up, where, and how often?
  • Is there an admin login page? If so, is it protected by two-factor authentication and rate limiting?
  • What happens if the site gets hacked — who fixes it, and at what cost?
  • Will the site still be secure in 3 years if nothing else changes?

Any decent web designer should have a clear answer to each of these. If the answer is a shrug or "we'll cross that bridge when we come to it", that's your answer.

Every site we build at A9 is hand-coded from scratch and shipped with fully managed hosting — daily backups, edge CDN, free SSL and 24/7 monitoring included. There's no plugin chain to patch and no admin login page for bots to find.

Common questions

Is HTTPS enough to make a website secure?

No. HTTPS only encrypts the connection between the visitor and the site — it doesn't stop the site itself from being hacked. A WordPress site with an out-of-date plugin can be fully HTTPS and still be compromised the same day.


How do I know if my website has been hacked?

The most common signs are a "This site may be hacked" warning in Google search results, unexpected redirects to gambling or pharmacy pages, new admin users you didn't create, or a sudden collapse in rankings. Google Search Console will usually flag security issues under the Security & Manual Actions tab.


How often does a small business website need security updates?

A WordPress or plugin-based site typically needs updates monthly at minimum, and critical patches within days of release. A hand-coded static site has no plugins or admin panel, so it doesn't need routine security patching in the same way.

Want a website that does this automatically?

Every site we build is hand-coded for performance, SEO and security from day one. Free, no-pressure chat — usually within a day.

Free 30-min strategy callGet a quote