ShieldSafe Blog
We write about what actually breaks on small business websites, how to check your own site without any tools, and what to do once you have a report. No scare tactics and no promises of total protection.
Your website was hacked: what to do in the first 24 hours
A calm order of operations: what to do in the first hours, why deleting everything immediately is a mistake, and in which order to change passwords so the attacker does not simply walk back in.
An exposed .git directory and a forgotten .env: how source code leaks out
The .git directory lands on production during an ordinary copy-based deploy,
and your source code goes public along with the full history of changes — including
passwords that were once committed and later “removed”.
Free vulnerability scanners: what they find and what they will never show you
Where the limits of a free scan are, why a one-off scan is not a substitute for a regular one, how a scanner differs from hosting antivirus — and a four-point checklist you can go through yourself in five minutes.
Some articles are published in Russian only — see the Russian version of the blog.