Advisor Web Risk Scorecard

Twelve questions. Honest answers.

Never / Partial / Yes. Scoring is client-side until you unlock results.

Security · 1/12

Do you have offsite, tested backups with a known restore drill in the last 12 months?

Security · 2/12

Are core, themes, and plugins updated on a defined cadence by someone accountable?

Security · 3/12

Is admin access limited (2FA, least privilege, no shared staff/vendor logins)?

Security · 4/12

Do you run malware / file integrity monitoring with same-day human response?

Compliance · 5/12

Can you clearly answer who hosts the site, where data lives, and who has root/admin access?

Compliance · 6/12

Are forms and any PII-adjacent data handled with documented retention and encryption in transit?

Compliance · 7/12

Has compliance/legal reviewed claims, testimonials, and third-party scripts in the last 12 months?

Performance · 8/12

Do you know typical homepage load time and treat slowdowns as a business issue?

Performance · 9/12

Is there an uptime expectation and named owner when key pages are down during market hours?

Vendor · 10/12

Is hosting with a vendor who understands advisory / financial-services expectations?

Vendor · 11/12

Could you exit the vendor in under 30 days with full site, DB, and DNS control?

Vendor · 12/12

Is there a named internal owner for the WordPress stack and a written vendor list for audits?