BadgerScan

WordPress & website security, in plain English

Practical guides from the CyberBadger team in Hamilton and Burlington, Ontario. No jargon, no fear-mongering, just what to check and how to fix it.

Your Business Was Just Hacked. Here Is What to Do in the First Hour.

The instinct is to fix it fast: reboot the computer, delete the bad email, change every password. Almost all of that makes things worse. The first hour is about stopping the spread and preserving what you will need, not cleaning up. Here is the order that actually helps.

The CyberBadger Team·

“Auto-Updates: On” Is Not the Same as Patched

A business called us: their WordPress admin password had been changed, and they hadn’t done it. What we found was a two-week-old compromise, traced to a single security update that a hosting setting had quietly blocked from ever installing. This is what we found, and how it happened.

Nathan Cross·

SPF Exceeds the 10 DNS-Lookup Limit: What It Means and How to Fix It

This is one of those findings that sounds obscure and is actually serious. Your SPF record still looks fine in your DNS, but the moment it needs an eleventh DNS lookup, receiving mail servers throw the whole thing out. Your anti-spoofing protection is off, and you would never know from looking at the record.

Nathan Cross·

Why So Many Small-Business Websites Score a D, and How to Climb Out

We ran the same free scan across every small-business website in whole cities and published the aggregate. The typical independent business scored a D. Not an F, not an A, a D, over and over. This is why that keeps happening, and it is almost never what site owners assume.

Nathan Cross·

How to Tell If Your WordPress Site Is Hacked: 9 Warning Signs

A hacked WordPress site rarely puts up a flashing alert. It leaks small, easy-to-miss clues first. Here are the nine warning signs that matter, what each one actually means, and the calm first steps to take before you touch a single file.

Nathan Cross·

Wordfence Alternative: What to Use Instead, and When You Still Want the Plugin

Most "Wordfence alternative" advice skips the honest part. Wordfence runs an active firewall and a malware scanner inside your site. A read-only assessment does not. Here is what actually replaces what, and when you still want Wordfence installed.

Nathan Cross·

BadgerScan vs Sucuri SiteCheck: Two Honest Tools for Different Jobs

Sucuri SiteCheck answers one question fast: does my public page look infected or blacklisted right now. BadgerScan answers a wider one: how exposed am I, inside and out, and what do I fix first. Here is where each fits, with no spin.

Nathan Cross·

Free WordPress Security Scanners Compared: How to Pick

Every free WordPress security scanner checks something different, and most check only half of what matters. Here is what the main approaches actually see, where each one is blind, and how to choose for a small-business site.

Nathan Cross·

Abandoned WordPress Plugins: How to Spot Them and What to Do

An unmaintained plugin does not announce itself. It just sits there, working fine, until a vulnerability is found and never patched. Here is how to recognise an abandoned plugin and replace it before it becomes the way in.

Nathan Cross·

WordPress Site Hacked? What to Do: A Calm Recovery Checklist

If your WordPress site has been hacked, take a breath: here is a clear, practical plan to contain the damage, clean it up, and stop it from happening again.

Nathan Cross·

Website Security Terms, in Plain English

Security reports are full of acronyms that assume you already know them. This glossary defines the terms a small-business owner actually runs into, one short sentence each, plus why it matters and where to check it on your own site.

Nathan Cross·

Free vs Paid Website Security Scanner: What Each One Actually Catches

Free scanners and paid ones are not better and worse versions of the same thing. They look at your site from different places. Here is what each one sees, where each one goes blind, and how to decide what you need.

Nathan Cross·

WordPress Security for Small Business: A 2026 Ontario Checklist

A skimmable, no-jargon checklist any Ontario small-business owner can work through to keep a WordPress website safe in 2026.

Nathan Cross·

HTTP Security Headers Explained, in Plain English

Security headers are short instructions your site sends to every visitor's browser. Here is what each one does, what a scan report is telling you, and the order to add them without breaking your site.

Nathan Cross·

A Website Security Scan That Sees Inside and Outside

Most free scanners only check what is visible from the street. The real risks usually sit behind the login, so the best website security scan looks at both and combines what it finds.

Nathan Cross·

WordPress Two-Factor Authentication Setup: How to Turn It On

A stolen or guessed password is one of the easiest ways into a WordPress site. Two-factor authentication shuts that door. Here is how to turn it on, which method to choose, and how to make sure every admin uses it.

Nathan Cross·

WordPress Plugin Vulnerabilities: Why 96% of the Risk Lives in Your Add-ons

The WordPress core software is remarkably solid, so the real danger to your small-business website almost always comes from the plugins and themes you bolt on top of it.

Nathan Cross·

Is My Business Email Spoofable? A Plain-English Guide to SPF, DKIM and DMARC

If your domain is missing three small DNS records, a stranger can send invoices and password requests that look exactly like they came from you, and your customers may never know.

Nathan Cross·

What Hackers See On My Website: The Outside of Your WordPress Site

Long before anyone touches your login page, your website quietly tells the outside world a great deal about itself, and a little of that knowledge is all an attacker needs to start.

Nathan Cross·