IT or ops leader Security By Avani and Shashank Last updated on September 29, 2026 6 min read

How Do You Check If Your Website Is Secure?

There is no single test that confirms a website is secure. A green padlock, a clean blacklist result and a passing Google Safe Browsing check are the three most common ways people try to check if a website is secure, but each answers a different, narrower question, and none of the three looks inside the site's own files. The question this piece answers is what each of those free checks actually covers, what it misses, and what to run alongside them to see the parts they cannot.

#Diagnosing
TL;DR

Checking site security means running four separate signals: a Google Safe Browsing lookup, a blacklist (DNSBL) check, confirming the certificate is valid with no mixed content, and a file-level malware or vulnerability scan. A pass on one says nothing about the other three. The padlock is the weakest of the four on its own. It confirms encryption and server control at issuance, and most phishing sites now carry one too. Safe Browsing and blacklist checks are reputation signals from outside the site, and only a file-level scan looks at what is actually on the server, which none of the free browser-facing tools do. Run the four free checks first, since they take five minutes and cost nothing, then request NoDrama’s free website audit for the layer those checks cannot see.

Contents

  1. 01
    Understand what each check actually tells you
    The short answerHow it actually works
  2. 02
    Run the checks
    What good looks likeWhat to do about it
  3. 03
    Know what still isn’t covered
    Common misconceptionsWhat this does not solve

The short answer

Checking whether a website is secure means running four separate signals, not one. Each covers a different layer, and a clean result on any one of them is not a clean bill of health for the other three.

Signal What it checks What it misses
Google Safe Browsing status
Whether Google’s crawler classified the URL as malware, phishing, unwanted software or deceptive content on a recent pass Anything injected since that pass, or anything on a page the crawler never reached
Blacklist (DNSBL) check
Whether the domain or IP has been reported to a third-party list such as Spamhaus or Barracuda A fresh compromise nobody has reported yet
Certificate validity (the padlock)
That the connection is encrypted and that whoever requested the certificate controlled the server at issuance Patched software, server-side validation, or malware already on the site
File-level malware and vulnerability scan
The actual files and database for injected code, plus installed versions against known disclosures Nothing, but it is the one check none of the URL-only tools can run
The four checks that make up a website security check, and what each one covers.

How it actually works

Google Safe Browsing

Google’s Safe Browsing technology scans its own web index daily. As Google puts it, “Our Safe Browsing technology scans our web index on a daily basis to identify unsafe websites.” A URL that turns up gets classified as malware, phishing, unwanted software or deceptive content. Malware detection works by scanning sections of the index and testing pages in a virtual machine to see if it gets infected. Phishing detection runs on statistical models instead.

Once a site is flagged, the warning is added within minutes of detection, and it takes about half an hour on average to show up externally. That speed cuts both ways.

Catches

A site that was actively serving bad content at its last crawl.

Misses

Anything injected after that crawl, anything on a page the crawler never reached (behind a login, or blocked by robots.txt), and a vulnerable plugin sitting on the site that nobody has exploited yet.

Run the lookup directly at Google’s Safe Browsing site-status tool, and read how the scan actually works in Google’s Safe Browsing transparency FAQ. For the fuller process this single check feeds into, see the fuller checklist this feeds into.

Blacklist and DNSBL checks

A blacklist check is a DNS lookup, cross-referenced against third-party lists such as Spamhaus, Barracuda or SORBS. Each list sets its own listing criteria. A clean result here means the domain or IP has not been reported yet, not that the underlying code is clean. It also misses a site that was compromised recently and hasn’t been reported, and it can produce a false positive on shared hosting, where one bad neighbor gets an entire IP block listed.

The padlock and certificate

A valid certificate confirms two things only: the connection between browser and server is encrypted, and whoever requested the certificate had administrative access to the server at the moment it was issued. It does not confirm the software behind that connection is patched, that server-side validation is sound, or that the site is free of malware.

Free certificate issuance changed what the padlock actually signals. A phishing site can get the same valid HTTPS certificate a legitimate business gets, and vendor reporting on phishing incidents has noted that most reported phishing sites now carry a valid certificate too.

Read the padlock correctly

Treat the padlock as confirmation of encryption, never as confirmation of safety.

Malware and vulnerability scanning

This is the layer the first three checks cannot touch, because it requires looking at the site’s own files rather than at how the outside world sees the domain. A malware scan inspects the files and database for injected code, unexpected admin accounts and altered core files. A vulnerability check compares the installed versions of core, themes and plugins against public disclosure databases such as WPScan’s.

Both require server-side access or a direct look at the codebase. A URL-only checker run from outside the site cannot do either.

Where the free checks stop
External reputation
  • Safe Browsing
  • Blacklist
  • Certificate

Requires file-system access

Requires file-system access

On the server
  • Malware scan
  • Vulnerability check
A diagram showing the boundary between external reputation checks and a file-level security scan.

External reputation and file-level access are two different zones. Safe Browsing, blacklist status and the certificate all judge the site from outside. A malware scan and a vulnerability check are the only ones that look at what is actually sitting on the server.

What good looks like

A genuinely clean result means all four signals come back clear at once:

No Safe Browsing flag
No blacklist listing
A valid certificate with no mixed-content warnings
A file-level scan that turns up no injected code and no versions matching a known disclosure

One green result out of four is a start, not a finish. It tells you one layer looks fine today. It says nothing about the other three.

What to do about it

  1. 01

    Run the Google Safe Browsing site-status lookup directly against the domain.

  2. 02

    Run a blacklist (DNSBL) checker against the domain to see if it appears on Spamhaus, Barracuda or a similar list.

  3. 03

    Check the certificate’s validity in the browser, and look in the browser console for mixed-content warnings on pages that should be fully encrypted.

  4. 04

    Run a malware and vulnerability scan, either through a security plugin with file-system access or through a fuller audit.

Each of these is a snapshot, not a standing guarantee, so the useful habit is running all four again after any change to the site, not just once after a scare.

Get the layer those four checks can’t see.

NoDrama’s free website audit checks the site’s actual files and versions, no pitch attached.

Audit My Site

Common misconceptions

“HTTPS means the site is safe.”

It confirms encryption in transit and that someone controlled the server when the certificate was issued. That’s all it confirms.

“A clean Safe Browsing result means nothing is wrong.”

It reflects only what Google’s crawler has seen so far, and that can lag behind a fresh infection by hours or days.

“A security plugin covers all of this.”

A plugin scans what it has file-system access to. Reputation flags such as Safe Browsing and blacklist status are external judgments, and a local plugin cannot see or clear them.

What this does not solve

None of the four checks above replace an ongoing, operated security practice: updates tested before they go live, monitoring that runs continuously rather than once, and a documented process someone actually follows. A clean result across all four today answers only “as of today.” For how the security work is scoped, see how the security work is scoped, and for who actually watches this after today, see who actually watches this after today.

Conclusion

Checking whether a website is secure is four separate signals, not one: Google Safe Browsing status, blacklist status, certificate validity, and a file-level malware and vulnerability scan. Each one is narrow, each one misses what the other three catch, and the only honest answer to “is my site secure” comes from running all four rather than trusting whichever one came back clean first.

FAQs

No. It confirms the connection is encrypted and that whoever requested the certificate controlled the server at issuance. It says nothing about patched software or malware on the site.
Run a blacklist (DNSBL) checker against your domain against lists such as Spamhaus or Barracuda. A clean result means it hasn't been reported yet, not that the code behind it is clean.
Safe Browsing flags are based on what Google's crawler saw on its last daily pass, which can include content that was injected and later removed, or a page you haven't checked yourself. The flag can also lag a fresh infection by up to about half an hour after detection.
A blacklist check looks at the domain's outside reputation on third-party lists. A malware scan looks at the site's own files and database for injected code, which is the layer a blacklist check never touches.
Yes, for three of the four. The Safe Browsing lookup, a blacklist checker and a certificate check in the browser are all free and take about five minutes. The fourth, a file-level malware and vulnerability scan, needs file-system access or a tool that has it, such as NoDrama's free website audit.

See What The Free Checks Miss

Get Started
Cancel anytime
Yearly runs to the end of the paid year
Real team behind every plan