// Security insights
Notes on keeping a small business site from becoming an easy target.
21 July 2026
The security headers most sites never send — and what each one actually stops
A few lines of server configuration, shipped in an afternoon, that shut down entire classes of attack. Here's what they do and how to check yours.
Read more →2 June 2026
5 signs your website may already be compromised
Most compromised sites don't announce themselves. Here's what to actually check, and why each sign matters.
Read more →14 May 2026
Why an outdated plugin is still the #1 way small business sites get hacked
Most breaches aren't sophisticated. They're a publicly known vulnerability nobody patched, found by a bot, not a person.
Read more →8 April 2026
What is credential stuffing, and why rate limiting alone won't stop it
The attack doesn't guess your password — it already has it, from a breach that had nothing to do with you.
Read more →