Is a Site You Own as Safe as Squarespace?
Short answer: Yes, if it’s set up well. Squarespace is secure, and a site you own as plain files can be just as safe: there’s no login page, database, or plugins on the site for anyone to break into. What changes is where the risk lives. It moves to your accounts, so two-step sign-in on each one matters more than anything else.
Squarespace is secure
Squarespace handles security for you. Every site gets a free SSL certificate (the padlock in the browser), checkout pages meet the card industry’s security standard, and login passwords are always encrypted.1 If security is your main worry, that’s a fair reason to like Squarespace.
How most websites actually get attacked
Most website break-ins come through the parts of a site that run code on a server: login pages, databases, and add-ons. WordPress shows this clearly. In 2025, security researchers found 11,334 new security holes in WordPress plugins, themes, and core, and 91% of them were in plugins. Only 6 were in WordPress itself.2
Why a site of plain files is hard to break into
A site you own, built the way we build them, is a set of plain files: pages, styles, and images. There’s:
- No login page on the site to guess passwords on.
- No database to break into.
- No plugins to fall behind on updates.
The files are served by Cloudflare, which includes on its free plan:
- Free SSL certificates, issued and renewed automatically.3
- Unlimited protection from DDoS attacks, the floods of fake traffic meant to knock sites offline.4
- Free spam protection for forms (Turnstile), without making visitors solve puzzles.56
Where the risk moves: your accounts
On a site you own, the keys are yours. That’s the point, and it’s also the responsibility. Anyone who gets into these accounts could change your site:
| Account | What it controls |
|---|---|
| Your domain company | Where your website and email point |
| GitHub | Your site’s files |
| Cloudflare | Your hosting and domain settings |
| Claude, through the email or Google account you sign in with | The tool that edits your site |
Turn on two-step sign-in for every one that offers it. It’s the single most important step. A stolen password alone then isn’t enough. Claude signs you in through your email or Google account, so protect that account with two-step sign-in.7
Also:
- Use a password manager and a different password for each account.
- Turn on the domain lock at your domain company, so no one can move your domain without you.
- Don’t paste passwords or private keys into your site’s files.
Don’t forget email security
Your domain also proves your email is really from you, using settings called SPF, DKIM, and DMARC. Some domains are missing one or more of these, which makes it easier for someone to send fake email that looks like it came from you. A move is a good time to check and fix them.
What we do on every move
We set this up with you. On every move, we:
- Require two-step sign-in on your GitHub, Cloudflare, and domain accounts, and on the email or Google account you use to sign in to Claude.
- Turn on HTTPS, security headers, and the domain lock.
- Add spam protection to every form.
- Check and fix your email security settings.
- Keep every version of your site, so any change can be undone.
- Include a short security check in your move report.
Questions owners ask
Can my site get hacked if it’s just files? Nothing is ever impossible to attack. But with no login page, database, or plugins on the site, the usual ways in aren’t there. The bigger risk is someone getting into one of your accounts, which is why two-step sign-in matters.
What if Claude makes a bad change? Every version of your site is saved in GitHub, so you can go back. Sites we move also come with rules for Claude and a preview before anything goes live.
Who fixes security problems after the move? Plain files need very little upkeep. Cloudflare keeps its own systems updated. Your job is to keep your accounts protected.
Do I need a security plugin? No. There are no plugins on a site of plain files.
Sources
Footnotes
-
Squarespace Help Center, Squarespace and SSL. ↩
-
Patchstack, State of WordPress Security in 2026. ↩
-
Cloudflare Docs, Universal SSL. ↩
-
Cloudflare Docs, DDoS Protection. ↩
-
Cloudflare Docs, Turnstile plans. ↩
-
Claude Help Center, Logging in to your Claude account. ↩