Web security & performance guides
Clear, jargon-free explanations of what our scanner checks — and how to fix what it finds. 34 guides across 6 topics.
SSL / TLS & Encryption 6
What Is SSL/TLS? A Plain-English Guide
How SSL/TLS encryption actually works, why every website needs HTTPS, and what the padlock in the browser really proves.
Read guide →TLS 1.3 Explained: What Changed and Why It Matters
A clear breakdown of TLS 1.3 — faster handshakes, forward secrecy, and how to check whether your site supports it.
Read guide →SSL Certificate Types: DV, OV and EV Compared
Domain, Organization and Extended Validation certificates compared — which one your site actually needs.
Read guide →Let's Encrypt vs Paid SSL Certificates
When free Let's Encrypt certificates are enough and when a paid or organization-validated certificate is worth it.
Read guide →How to Fix Mixed Content Warnings
Why the padlock disappears on HTTPS pages and a step-by-step method to find and fix mixed content.
Read guide →Why SSL Certificates Expire and How to Stay Ahead
Certificate lifetimes are shrinking. How expiry works, what breaks when a cert lapses, and how to monitor renewals.
Read guide →HTTP Security Headers 7
HTTP Security Headers: The Complete Checklist
Every important HTTP security header explained, what it protects against, and a copy-paste starting configuration.
Read guide →HSTS Explained: Strict-Transport-Security Done Right
How HSTS forces HTTPS, what the preload list means, and how to roll it out without locking yourself out.
Read guide →Content Security Policy (CSP) for Beginners
How CSP stops cross-site scripting, why it is hard to get right, and a safe way to deploy your first policy.
Read guide →X-Frame-Options and Clickjacking Protection
How clickjacking attacks work and how X-Frame-Options and frame-ancestors stop your site being embedded maliciously.
Read guide →Referrer-Policy: Controlling What You Leak
How the Referrer-Policy header controls the data your site leaks to other websites, and a sensible default.
Read guide →X-Content-Type-Options and MIME Sniffing
What MIME sniffing is, why it is dangerous, and how a one-line header shuts the attack down.
Read guide →Permissions-Policy: Locking Down Browser Features
How the Permissions-Policy header restricts camera, microphone, geolocation and other powerful browser features.
Read guide →Performance & Core Web Vitals 7
What Is TTFB (Time to First Byte)?
What Time to First Byte measures, what counts as good, and the most common causes of a slow TTFB.
Read guide →Core Web Vitals Explained for Non-Developers
LCP, INP and CLS in plain language — what Google measures, the thresholds, and how they affect rankings.
Read guide →How to Improve Largest Contentful Paint (LCP)
Practical, prioritized steps to bring LCP under 2.5 seconds, from image handling to render-blocking resources.
Read guide →How to Reduce Cumulative Layout Shift (CLS)
Why pages jump around while loading and the concrete fixes that keep your layout stable.
Read guide →Brotli vs Gzip: Which Compression Should You Use?
How text compression speeds up your site and why Brotli usually beats Gzip for the modern web.
Read guide →Browser Caching and Cache-Control Explained
How Cache-Control and ETags work, and how to set caching that is fast without serving stale content.
Read guide →Image Optimization: The 2026 Practical Guide
Formats, sizing, lazy loading and WebP/AVIF — the biggest, easiest performance win most sites are missing.
Read guide →DNS, Hosting & Infrastructure 6
How DNS Works: A Site Owner's Guide
From typing a domain to loading a page — how DNS resolution works and the records every site owner should know.
Read guide →What Is a CDN and Do You Need One?
How content delivery networks make sites faster and more resilient, and when they are worth adding.
Read guide →HTTP/2 and HTTP/3 (QUIC) Explained
What changed between HTTP/1.1, HTTP/2 and HTTP/3, and why the newest protocol matters for speed.
Read guide →Shared vs VPS vs Dedicated Hosting
The real differences between hosting tiers and how to pick one for your traffic and security needs.
Read guide →LiteSpeed vs Nginx vs Apache
How the three most common web servers compare on speed, caching and configuration.
Read guide →How to Redirect HTTP to HTTPS Correctly
The right way to force HTTPS with 301 redirects, without redirect loops or SEO damage.
Read guide →Privacy & Compliance 4
GDPR Website Checklist for Small Businesses
A practical, jargon-free checklist to bring a small website in line with GDPR, from cookies to data requests.
Read guide →The NIS2 Directive Explained for Website Owners
What the EU NIS2 directive is, who it applies to, and the baseline security it expects.
Read guide →Cookie Consent Done Right
How consent banners are supposed to work under EU law and how to avoid the most common compliance mistakes.
Read guide →What Every Privacy Policy Needs
The core sections a website privacy policy should contain and the plain-language way to write them.
Read guide →Fundamentals 4
Website Security Basics: Where to Start
A beginner-friendly roadmap to securing a website, in the order that actually matters.
Read guide →How to Read a Website Security Scan
What the scores and findings in a security report mean, and how to prioritize the fixes that matter.
Read guide →The Most Common Website Vulnerabilities
The everyday weaknesses that get small sites compromised, explained without the jargon.
Read guide →WordPress Hardening Checklist
Practical steps to lock down a WordPress site, from logins and plugins to headers and backups.
Read guide →Put a guide into practice
Run a free scan of your site and see exactly which of these fundamentals you’ve already nailed.
Run a free scan