Web developers: how do you currently handle security for client websites?
Hi, I’m currently researching how small web agencies and freelance developers handle website security for their clients.
I’m not trying to sell you anything. I’m simply trying to understand the current workflow and the problems people actually face.
If you have a few minutes, I’d really appreciate your honest answers to these questions:
How many client websites do you currently manage?
What tools or methods do you currently use to check the security of those websites?
How often do you perform security checks?
When a security tool reports multiple issues, how do you decide which issue needs to be fixed first?
What part of the security-checking process takes the most time or effort?
Do you ever find security reports difficult to understand or difficult to explain to your clients? If yes, what makes them difficult?
After discovering a vulnerability, how do you usually figure out how to fix it?
Do you have to manually search Google, documentation, GitHub, or vendor websites to find the correct solution?
Have you ever received a false alarm from a security scanner? If so, how did you handle it?
What is the biggest frustration you currently have with website security management?
If you could completely remove one part of your current security workflow, what would it be?
Approximately how much time do you spend each month dealing with website security across your clients?
Are you currently paying for any security tools? If yes, which ones and approximately how much?
If a tool could automatically monitor your clients' websites, identify the most important security problems, explain them in simple language, and give you clear step-by-step instructions for fixing them, would that be useful to you?
What would make a tool like that genuinely valuable enough for you to pay for?
There are no right or wrong answers. I’m particularly interested in your actual experience, even if it means telling me that this idea wouldn't be useful.
Thank you for your time.
[link] [comments]