THE QUESTIONS YOU’RE ALLOWED TO ASK
You don’t have to speak developer.
Straight answers to the questions a new owner should feel comfortable asking. Take these into your next website conversation.
40 questions found
Is outdated WordPress okay if I use a current PayPal plugin?
No. A current payment plugin does not patch old WordPress core, a vulnerable theme or another plugin. An attacker who can edit the page can replace the PayPal destination or add a fake payment form. Update the whole site, or replace it with a clean static site and remove the abandoned PHP installation, including old copies in neighboring folders.
Sources: WordPress: Hardening WordPress (external) ↗ · PCI Security Standards Council: FAQ 1604: outsourced payments and ASV scans (external) ↗
Is WordPress itself an unsafe choice?
No. Supported WordPress with maintained extensions, prompt updates, strong authentication and tested backups can be a practical choice. The unsafe assumption is that an abandoned installation is fine because it is small or rarely visited. Our “outdated WordPress” comparison means unsupported or known-unpatched components, not simply a version number that is not the newest feature release.
Sources: WordPress: WordPress: security and supported releases (external) ↗
Does using React make my website secure?
No. Client-only static React, React backed by an API, and React with server components are different systems. Dependencies, build tools, account access and custom code all matter. A static build can be appropriate on cheap hosting; a live application needs a separate security and maintenance plan.
Sources: React: React Server Components security advisory (external) ↗ · OWASP Top 10:2025: Software Supply Chain Failures (external) ↗
Can React run on the cheapest shared hosting?
A prebuilt React website can: the host serves ordinary HTML, JavaScript and CSS. Building happens on your computer. A Next.js or other server-rendered app may need a supported Node runtime; do not assume the cheapest plan provides that configuration. Ask your designer what actually runs on the server.
Does HTTPS protect my customer database?
HTTPS protects traffic in transit between browser and server. It does not repair a vulnerable plugin, prevent account takeover or make a public backup file private. Use the included certificate, but evaluate storage, access and maintenance separately.
Do I have to buy an SSL certificate?
Not usually when the host includes a working, automatically renewed certificate. Our shared-hosting reference includes SSL. Verify that HTTPS works on the real domain and subfolder, that renewal is automatic and that assets load over HTTPS. A paid certificate alone does not make insecure application code safe.
Sources: Hawk Host: Budget shared-hosting reference (external) ↗
Can customers pay without giving my website any personal information?
Yes: a direct link can send them to a provider-hosted checkout before they enter names, addresses or card information. The provider still needs information, and you may receive some of it in reports. Server logs may contain IP addresses. Say “no payment information entered on this site,” rather than promising that no personal data exists anywhere.
Sources: PayPal US: Payment Links (external) ↗ · Stripe: Payment Links (external) ↗
Is an embedded payment form the same as leaving the site?
No. An iframe can isolate the provider’s payment fields, but the surrounding page still matters. Direct navigation to a recognizable provider domain is often easier for a small site to reason about. PCI has a specific script-related eligibility distinction between embedded forms and redirects; that is not a blanket exemption from all obligations.
Sources: PCI Security Standards Council: FAQ 1588: SAQ A script eligibility (external) ↗
Do external checkout links remove all PCI responsibilities?
No. Merchants validating with SAQ A can still have responsibilities for the page that sends buyers to checkout, including applicable external ASV scans. Ask your processor or acquiring bank which validation applies to the actual integration. Linking to an Amazon or Steam product page is also a different commercial relationship from operating your own merchant checkout.
Sources: PCI Security Standards Council: FAQ 1604: outsourced payments and ASV scans (external) ↗
Does a host’s malware scanner count as a required PCI scan?
Not automatically. PCI external scans must use the required approved scanning vendor and scope when applicable. Malware detection, a firewall and a formal external vulnerability scan are different services. Ask for the actual deliverable before paying for a bundle.
Sources: PCI Security Standards Council: FAQ 1604: outsourced payments and ASV scans (external) ↗
Can you tell me the percentage chance that my customers will be hacked?
Not defensibly from the framework alone. Public breach reports describe observed incidents, not annual theft rates for these exact solo-business configurations. We use relative exposure judgments and a labeled hypothetical calculator. A claimed 2% or 80% annual risk without a population, timeframe and method would create false confidence.
Sources: Verizon: 2026 Data Breach Investigations Report findings (external) ↗
Can a static website still be hacked?
Yes. Someone can take over the hosting account, registrar, DNS or build machine and replace the published files. A dependency can introduce malicious code. Static hosting removes several application attack paths, but you still need strong account protection and a known-good copy of the site.
Sources: OWASP Top 10:2025: Software Supply Chain Failures (external) ↗
Should I pay for a web application firewall?
For a small static brochure it is often optional. For a dynamic CMS, a WAF can reduce some hostile requests, but timely patching and recovery matter more than a badge. Buy a service when it closes a specific gap—such as managed cleanup or monitored restoration—not because every site must have the same add-on.
Do I need a CRM before I launch?
Usually not. An order dashboard may be enough for goods, a newsletter tool for fans, and no contact database at all for an Amazon referral site. A therapist needs an appropriate private client system; a nonprofit may need donor follow-ups. Start with the workflow and only keep the records needed for it.
Can I put API keys or customer spreadsheets in the Build folder?
No. Treat every uploaded file and frontend bundle as public. Keep payment secrets, client records, donor exports and backups outside public web directories. A filename that is difficult to guess is not access control.
What should my designer hand over?
The source files, upload-ready build, account ownership, dependency and update instructions, a known-good backup and a tested restore procedure. Ask who handles urgent patches and what happens if the designer is unavailable. You should control the domain and billing accounts.
What do I do if the payment button suddenly looks wrong?
Temporarily remove the affected page or replace it with a known-clean notice. Contact the host and payment provider, secure accounts from a clean device, preserve relevant logs and investigate what changed. Restore only after closing the entry point. Assess whether customer notification or reporting is required for the incident.
Can I leave old WordPress in another folder after moving to static HTML?
Not safely by default. A vulnerable installation elsewhere in the same writable hosting account may still provide a route to your new site. Back up needed material privately, then remove or properly isolate and maintain the old application. A static export alone does not disable PHP left on the server.
Do I need a privacy notice if I use hosted checkout?
Explain the real data flow: which provider handles payment, what reports you receive, where newsletter signup happens, and any analytics or logs. Outsourcing entry does not erase your responsibilities for personal data you receive or use. Avoid copying a notice that promises practices you do not actually follow.
Sources: FTC: Protecting Personal Information: A Guide for Business (external) ↗
Can I keep an old WordPress site just for the Buy Me a Coffee button?
An external button reduces the data you collect, but old site code can still be exploited to replace it. Update the site or replace it with a clean static export and remove the old executable CMS.
Read the business guideShould newsletter signup be required to buy the game?
No. Keep the purchase route simple and offer newsletter signup separately. Buying your game is not automatically permission to send ongoing marketing.
Read the business guideDo I need to store game keys on my web host?
Usually not. Use the stores’ delivery systems. If you distribute review keys, keep that list private and access-controlled outside the public site.
Read the business guideCan I use Etsy for any jewelry I buy and resell?
No. Check the actual eligibility rules. General resale of recently manufactured jewelry is not automatically allowed; a resale marketplace such as eBay may fit better.
Read the business guideCan a Buy Now link oversell a one-of-a-kind ring?
Yes, unless the payment or commerce system enforces the available quantity. A visual “sold” label on your site is not a payment lock.
Read the business guideDo I need a CRM for every buyer?
No. The platform’s order tools may be enough. Add a minimal relationship record only when it solves a real follow-up need, and do not subscribe buyers to marketing automatically.
Read the business guideDoes every hypnotherapist have to comply with HIPAA?
No. It depends on covered-entity or business-associate status and the actual activity. Other applicable laws and confidentiality obligations still matter. Resolve this before selecting an intake system.
Read the business guideCan I ask clients what they want help with in my contact form?
That invites sensitive information onto your web host or email system. Put intake in the private portal and label ordinary inquiries “Please do not include health or confidential details.”
Read the business guideCan I use my existing Zoom account?
Possibly. Check the plan, privacy settings and whether a BAA is required and in place. Do not reuse a publicly posted meeting room for all clients.
Read the business guideIs Bandcamp’s fee a security fee?
It is a platform revenue share, not an insurance policy. It pays for platform services; you still need to protect your account and any customer data you export.
Read the business guideCan I hide paid songs in a folder on my site?
Hiding a link does not provide access control. Use hosted delivery or an authenticated server, and keep public previews separate from paid files.
Read the business guideCan I email every purchaser about new releases?
Use a separate, appropriate marketing permission process. Purchase records and a newsletter subscription are different things.
Read the business guideIs an up-to-date PayPal plugin safe on old WordPress?
No assurance follows from that combination. The plugin cannot repair the old core, other plugins, the theme or the hosting account. Patch the whole system or use clean static pages with hosted PayPal links.
Read the business guideDo memberships require a login on our website?
Only if there is an actual access-controlled service. Recurring payments and a private membership roster can operate without public-site accounts.
Read the business guideDoes accepting charity payments mean we qualify for PayPal’s charity rate?
No. The rate is subject to eligibility and approval. Check the actual account and transaction classification.
Read the business guideDo I need an ecommerce plugin to link to Amazon?
No. A normal HTML link is sufficient. An ecommerce plugin introduces no necessary benefit for this goal.
Read the business guideWill Amazon share every buyer’s email with me?
Do not plan on that. Build a separate permission-based reader list if you want direct announcements. Never require readers to share their Amazon credentials.
Read the business guideCan my designer use React on cheap hosting?
Yes, if the finished site is static files. A runtime Node server or server-rendered application is a different hosting requirement.
Read the business guideIs every print-on-demand account a ready-made store?
No. Some services only fulfill orders sent from a separate store. Pick an actual hosted storefront if you want checkout and addresses kept off your website.
Read the business guideDoes the printer handle all taxes and refunds?
Not necessarily. Merchant-of-record and support responsibilities depend on the specific service and contract. Do not infer them from who prints the mug.
Read the business guideShould I install WooCommerce for three mugs?
Usually there is a simpler route. Hosted product links avoid maintaining an order database and several integrations for a tiny catalog.
Read the business guide