Website Security Guides
Defence guides for site owners and developers: SQL injection, XSS, CSRF, file uploads, sessions, security headers, backups and incident response.
For account and device security (phishing, two-factor authentication, passwords), see the Information Security guides.
14 guides
- Website security guide: where should you start?Threat types, layered defence, priorities and a roadmap to all the security guides. About 10 min read
- What is SQL injection and how do you prevent it?Prepared statements, allowlists, a least-privilege database user and hiding error messages. About 8 min read
- What is XSS and how do you prevent it?Context-aware output escaping, Content-Security-Policy, HttpOnly cookies and rich-text sanitising. About 9 min read
- What is CSRF and how do you prevent it?CSRF tokens, SameSite cookies, Origin checks and using POST for state-changing actions. About 9 min read
- File upload security and web shellsSecure upload rules, disabling execution in the upload folder, signs of a web shell and what to do if you find one. About 9 min read
- Login and session securityPassword hashing, attempt limits, session fixation, cookie flags and authorisation checks on every request. About 8 min read
- Security headers and HTTPSHSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, with an .htaccess example. About 8 min read
- DDoS and bot attacksSigns, CDN and WAF, rate limiting, caching and working together with your hosting provider. About 9 min read
- Software updates and plugin securityKeeping the CMS, plugins, themes and libraries up to date; removing what is unused; supply chain risk. About 10 min read
- Server and hosting securitySFTP/FTPS, file permissions, directory listing, error display, sensitive files and database access. About 9 min read
- Website backup and monitoringFile and database backups, restore drills, file integrity, logs and uptime monitoring. About 10 min read
- What to do if your website is hackedStep-by-step incident response: maintenance mode, evidence, passwords, clean-up, entry point, restore and notifications. About 11 min read
- WordPress securityUpdates, few and trusted plugins, administrator accounts, wp-config protection, XML-RPC and login limits. About 9 min read
- Website security checklistWeekly, monthly and yearly tasks; every item links to the relevant guide, and the list is printable. About 7 min read
Other categories
Let us review your website together
BYK Yazılım builds corporate websites. Write to us with any questions about your site.
Contact us Our corporate website service