Website Security Terms, in Plain English

Security reports are full of acronyms that assume you already know them. This glossary defines the terms a small-business owner actually runs into, one short sentence each, plus why it matters and where to check it on your own site.

By Nathan Cross, Co-Founder, Network & Security Engineering·

How to use this website security terms glossary

Most website security writing is built for people who already speak the language. You run a free scan, get a report, and half of it reads like a different language: SPF, CSP, CVE, WAF. This glossary is the translation. Each term gets one plain-English sentence for what it is, then a short note on why it matters to you as the owner.

We have grouped the terms by theme rather than alphabetically, because that is how they actually show up in a report. Email security travels together. Transport and certificate terms travel together. WordPress-specific risks travel together. General terms sit at the end. Where a term maps to a free tool you can run yourself, we have linked it, so you can stop reading and go look at your own site in a minute or two.

One honest note before we start. Knowing the words is not the same as being secure, but it is the step that makes every report afterward readable. When you can tell a missing DMARC record from a missing security header, you can decide what to fix first instead of forwarding the whole thing to someone and hoping. If you want the wider how-to behind these terms, the WordPress security guide covers the hardening steps in order.

Email security terms (SPF, DKIM, DMARC)

These three records live in your domain's DNS and work as a team to stop scammers from sending email that looks like it came from you. They are invisible to visitors, which is exactly why they get neglected, and why spoofed invoices and phishing mail in your name are so common. You can check all three at once with the SPF and DMARC checker, and there is a fuller walkthrough in is your business email spoofable.

  • SPF (Sender Policy Framework): a DNS record that lists which mail servers are allowed to send email for your domain. Why it matters: without it, anyone can send mail claiming to be from your address, and receiving servers have no way to tell the difference.
  • DKIM (DomainKeys Identified Mail): a digital signature added to your outgoing email that proves the message really came from your domain and was not altered in transit. Why it matters: it gives receiving servers cryptographic proof of authenticity, so legitimate mail is trusted and forgeries stand out.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): a DNS policy that tells receiving servers what to do when an email fails the SPF and DKIM checks, such as reject it or send it to spam. Why it matters: SPF and DKIM only describe the rules; DMARC is what actually enforces them and stops spoofed mail from landing in inboxes.

Transport and certificate terms (TLS, SSL, HTTP security headers)

This group is about how your site travels to a visitor's browser and the ground rules it sets once it gets there. A TLS certificate encrypts the connection; security headers tell the browser how to behave. Both are checkable from the outside, so they are part of our free external scan. You can test your certificate with the SSL and TLS checker and your headers with the security headers checker.

  • TLS / SSL certificate: the certificate that encrypts the connection between your site and a visitor, shown as the padlock and the https:// in the address bar (SSL is the old name; TLS is the modern protocol that replaced it). Why it matters: without a valid one, data sent to and from your site travels in the clear, and modern browsers warn visitors away from the site.
  • HTTP security headers: short instructions your server sends with every page that tell the visitor's browser how to protect that visitor from common attacks. Why it matters: they close off whole categories of browser-side attack for a few lines of configuration, which makes them one of the cheapest wins in website security. For the full breakdown, see HTTP security headers explained.
  • HSTS (Strict-Transport-Security): a specific header that tells the browser to only ever connect to your site over HTTPS, even if someone clicks a plain http:// link. Why it matters: it blocks downgrade attacks where someone on the same network forces a visitor onto an unencrypted connection to read or tamper with the traffic.
  • CSP (Content-Security-Policy): a header that tells the browser exactly which sources of scripts, styles and images are allowed to load on your pages. Why it matters: a good CSP makes it very hard for an attacker to inject and run malicious JavaScript, though it is the fussiest header to configure and usually comes last.

WordPress-specific terms (CVE, WAF, 2FA, XML-RPC, user enumeration)

WordPress reports add their own vocabulary, mostly because so much of the platform's risk lives in third-party code. Plugins account for roughly 96% of WordPress vulnerabilities, with only a handful ever found in core itself (Patchstack), so the terms below are the ones that decide how exposed your particular install is. The WordPress security guide ties them all together.

  • CVE (Common Vulnerabilities and Exposures): a public catalogue ID assigned to a specific known security flaw, for example in a particular version of a plugin. Why it matters: once a CVE is published, automated scanners sweep the web for sites still running the affected version, so a known CVE on your site is a known way in until you patch it.
  • WAF (Web Application Firewall): a filter that sits in front of your site and tries to block malicious requests, such as injection attempts, in real time. Why it matters: it can stop some attacks before they reach your code, but it is active protection that you operate and tune; to be clear, BadgerScan does not provide a WAF, our plugin is read-only and only assesses and grades.
  • Two-factor authentication (2FA): a second login step, usually a code from your phone, required on top of your password. Why it matters: it means a stolen or guessed password is useless on its own, which closes off the most common route into an admin account. See setting up two-factor authentication on WordPress.
  • XML-RPC: an older WordPress feature that lets external apps talk to your site, often left enabled when nothing uses it. Why it matters: when unused, it is extra surface that attackers abuse for brute-force and amplification attacks, so it is commonly disabled.
  • User enumeration: the trick of pulling a site's valid usernames from public pages or URLs without logging in. Why it matters: once an attacker knows a real username, brute-forcing the password gets far easier, which is why a good setup hides them.

General terms (malware, blacklisting, attack surface, vulnerability scan)

These last terms describe the bigger picture: what an attack is, what happens after a successful one, and how the whole thing is measured. They are not WordPress-specific, but they frame everything else in a report. The distinction between your attack surface and a vulnerability scan, in particular, is the one that explains why inside and outside views both matter, covered in the inside and outside of a website security scan.

  • Malware: malicious code planted on your site, such as a script that redirects visitors, steals data, or sends spam. Why it matters: it harms your visitors and your reputation, and it often hides quietly, so it can run for weeks before anyone notices. If you suspect an active infection, start with the hacked-site recovery checklist.
  • Blacklisting (blocklisting): when Google, browsers, or email providers flag your domain as dangerous and warn people away from it. Why it matters: it can cut your traffic and your email deliverability overnight, and getting removed from a blocklist takes time even after the underlying problem is fixed.
  • Attack surface: the sum of everything about your site that an outsider can see and potentially target, from your DNS and certificate to your headers, exposed files, and detectable software versions. Why it matters: it is where an opportunistic attacker actually starts, so the smaller and cleaner your attack surface, the less there is to probe. See what attackers see outside WordPress.
  • Vulnerability scan: an automated check that compares your site against databases of known weaknesses and reports what it finds. Why it matters: it turns a vague worry into a concrete, prioritised list of what to fix; you can try one with the WordPress vulnerability scanner.

Putting the terms to work

The point of a glossary is not to memorise it. It is to make your next security report readable, so you can act on it instead of filing it. Once SPF, CSP, and CVE stop being noise, the report stops being intimidating and starts being a to-do list in priority order.

Notice that the terms split naturally into two camps. SPF, DKIM, DMARC, your TLS certificate, security headers, exposed files, and attack surface are all visible from the outside, which is what a free external scan reads. Your exact plugin and theme versions, which CVEs apply to them, whether 2FA is on, and whether XML-RPC is open all live on the inside, which needs an authenticated check. Most owners only ever see one half, which is why a problem on the other half goes unnoticed.

BadgerScan is built around closing that gap. The free external scan reads the outside view: DNS, email security, TLS, headers, exposed files, and known CVEs for versions it can detect. The read-only Pro plugin reads the inside view and fuses both halves into one plain-English letter grade and one deduplicated fix-list. The plugin is read-only by design: it assesses and grades, it is not a firewall and it never blocks traffic or exploits anything. Knowing the words is step one; seeing them graded on your own site is step two.

See these terms graded on your own site

Run the free BadgerScan external scan to check your SPF, DKIM, DMARC, TLS certificate, security headers, and exposed files in one plain-English report, no login needed. Add the read-only Pro plugin to see your exact plugin versions and their CVEs from the inside, fused into one grade and one fix-list.

Run a free security scan

Frequently asked questions

What is the difference between SPF, DKIM, and DMARC?

They are three DNS records that work as a team against email spoofing. SPF lists which servers may send mail for your domain, DKIM adds a signature proving a message really came from you and was not altered, and DMARC is the policy that tells receiving servers what to do when SPF or DKIM fails. SPF and DKIM set the rules; DMARC is what enforces them. You can check all three with the SPF and DMARC checker.

Is SSL the same as TLS?

In everyday use, yes. SSL is the original name for the technology that encrypts the connection between your site and a visitor; TLS is the modern protocol that replaced it. People still say SSL certificate out of habit, but what your site actually uses today is TLS. Either way, it is what produces the padlock and the https:// in the address bar.

What does a CVE number mean on a security report?

A CVE is a public ID assigned to one specific known security flaw, often in a particular version of a plugin, theme, or piece of software. When a report lists a CVE against your site, it means you are running a version with a publicly documented vulnerability. Because automated scanners hunt for sites still running affected versions, a known CVE is a known way in until you update or replace the affected component.

Is a WAF the same thing as a website scan?

No. A WAF (web application firewall) is active protection that sits in front of your site and tries to block malicious requests in real time. A scan is an assessment: it reads your site and reports what is wrong so you can fix it. BadgerScan is a scanner, not a WAF; our Pro plugin is read-only and only assesses and grades, it never blocks traffic or actively protects the site.

Keep reading

Sources

  1. Patchstack, State of WordPress Security

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.