Printable template
Website Security & Trust Audit
Business: [Business name]
Website: [Website address]
Audit date: [Date]
Evidence reviewed: [HTTPS, SSL, public headers, mixed content, policies, contact trust, proof]
Executive Summary
[Overall public trust and visible security posture, top risks, and first fixes.]
Audit Score
Security Score: [Score]/100
Trust Score: [Score]/100
| Criterion | Weight | Score | Evidence |
|---|---|---|---|
| HTTPS and redirects | 15 | [ ] | [Evidence] |
| SSL validity | 10 | [ ] | [Evidence] |
| Security headers | 20 | [ ] | [Evidence] |
| Mixed content | 10 | [ ] | [Evidence] |
| Privacy policy | 10 | [ ] | [Evidence] |
| Terms/legal pages | 8 | [ ] | [Evidence] |
| Cookie/consent notice | 7 | [ ] | [Evidence] |
| Contact trust | 10 | [ ] | [Evidence] |
| Reputation/trust proof | 10 | [ ] | [Evidence] |
Risks
- [Risk]
Observation: [What was found]
Evidence: [Header, URL, page element, policy, or screenshot reference]
Business Impact: [Trust/security impact]
Recommendation: [Specific fix]
Priority: [Critical/High/Medium/Low]
Estimated Time to Fix: [Time]
Estimated Effort: [Low/Medium/High]
Expected Benefit: [Expected improvement]
Critical Issues
- [Use the same evidence-based finding format.]
High Priority Issues
- [Use the same evidence-based finding format.]
Medium Priority Issues
- [Use the same evidence-based finding format.]
Quick Wins
- [Fast trust/security improvement with evidence and expected benefit.]
Recommendations
- [Recommended action to improve website safety or customer trust.]
30-Day Action Plan
- Week 1: [Fix visible trust blockers]
- Week 2: [Improve policy/contact/legal clarity]
- Week 3: [Review headers and mixed content]
- Week 4: [Recheck public trust path]
Final Recommendation
[What to fix first and what requires specialist review.]
Audit Limitations
This is a public-surface security and trust review, not penetration testing, vulnerability scanning, malware analysis, or legal advice.