See What Hackers See: The Free Website Security Scanner Built for Law Firms
In 60 seconds, Tzu Shield's free scanner runs the same reconnaissance an attacker would use to find your firm's exposures. Here is exactly what it checks, why each check matters for a law firm specifically, and what to do with the results.

The Scan Someone Is Already Running Against Your Firm
Attackers don't hand-pick their targets. They scan huge ranges of websites automatically, looking for the same handful of tells — outdated software, missing security headers, exposed admin interfaces, DNS misconfigurations that leak internal structure. Law firms make it onto those lists constantly because the payoff is high: privileged communications, financial records, M&A details, litigation strategy, and client PII all sitting in one place.
You can run the exact same scan on your own site right now — free, no login, 60 seconds — using Tzu Shield's free security scanner. This post walks through what it actually checks, why each check matters for law firms, and what to do with the results when they come back.
The Four Checks the Scanner Runs
1. Infrastructure Analysis
What server is your site running on. What ports are open. What DNS records exist and whether any of them leak internal structure (development subdomains, staging environments, exposed mail servers). What TLS/SSL configuration you're using and whether it's up to date.
Why it matters for law firms: most firm sites are hosted somewhere the firm chose years ago and haven't audited since. Old TLS versions, exposed development subdomains, and misconfigured DNS records are common — and they're exactly what attackers scan for when building target lists. The fix is usually simple, but you can't fix what nobody's looked at.
2. CMS & Plugin Scan
If your site runs on WordPress, Squarespace, Wix, Webflow, or a custom stack, the scanner identifies the CMS and checks for outdated versions, vulnerable plugins, and known exploits. WordPress plugins are the #1 attack surface for small firm websites in the U.S. — most attacks against law firm sites are via unpatched plugins, not sophisticated zero-days.
Why it matters for law firms: most firms have a WordPress site their nephew or a local marketing agency built five years ago. The plugins are outdated. Something is running an admin path. The scanner surfaces those in one pass.
3. Threat Intelligence
Cross-references your domain against known threat intelligence feeds — has your site been compromised, phished from, listed on malware databases, or associated with breached credentials? This is the check that catches issues you didn't cause: a former hosting provider, a compromised third-party plugin, or a subdomain someone forgot to decommission.
Why it matters for law firms: firms that had a compromised third-party form five years ago often don't know their domain is on threat feeds today. That flag makes their email land in spam and their site trigger browser warnings. See our Email Command Center service for the email deliverability angle on the same problem.
4. Security Headers
The invisible-but-critical layer. Modern browsers respect specific HTTP headers (CSP, X-Frame-Options, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy) that dramatically reduce common attack surfaces — cross-site scripting, clickjacking, mixed-content downgrades. Most law firm sites don't have them set at all.
Why it matters for law firms: missing security headers are the single most common finding on legal-site scans. Fixing them is a config change at your hosting provider or CDN — no code rewrite required — and it moves the site out of the "obvious target" bucket immediately.
What to Do With the Results
Every scan turns up something. Here's a triage framework for what to fix first:
Fix this week (high risk, low effort):
- Missing HTTPS/SSL, expired certs, or outdated TLS versions
- Outdated CMS core (WordPress, Drupal, etc.)
- Missing critical security headers (HSTS, X-Frame-Options, X-Content-Type-Options)
- Exposed admin interfaces on default paths (/wp-admin, /admin, etc.)
Fix this month (medium risk):
- Outdated plugins with known CVEs
- Exposed development or staging subdomains
- Threat-feed listings that need cleanup
- Missing Content Security Policy
Address in your next roadmap (lower risk, higher effort):
- Custom CSP tuning
- WAF (web application firewall) deployment
- DNSSEC
- Ongoing monitoring setup
For firms with in-house or on-retainer IT: hand them the scan report and ask for a fix timeline. For firms without: this is exactly the kind of finding Paralegal Power Up's Guardian is designed to route into an actionable next step, and Tzu Shield's national cybersecurity guide provides the policy framework to actually assign accountability.
Why This Is Free (and Why That Matters)
The scanner is genuinely free because the same-day CTA is running the scan, not paying anything. Firms that run the scan and find issues become natural buyers of the deeper products — state compliance packs and the national guide.
That's a good deal for firms: the highest-value diagnostic in security tooling is the initial "what's actually broken right now?" scan, and you can get that answer without a call or an invoice.
How Often Should You Rescan?
- Baseline scan today if you haven't done one this year
- Rescan after any site change — plugin updates, CMS upgrades, hosting migration, new subdomains
- Rescan quarterly as a discipline — takes 60 seconds
- Rescan immediately if you suspect a breach, get a browser warning, or start seeing your legit emails land in spam
The Bigger Picture
Website security is one of the more tractable pieces of law firm cybersecurity — the checks are objective, the fixes are usually well-understood, and the tooling is now free. It's also the piece attackers are most actively probing at any moment.
Take a minute this week to run the scan on your firm's site. If it finds nothing, you've validated the discipline. If it finds something, you've caught it before someone else did.
For firms that want the full cybersecurity + compliance stack — scanner + national guide + state pack + Paralegal Power Up's Guardian for internal posture — see our introduction to Tzu Shield or book a strategy call if you want us to walk through your specific rollout.

Christopher Costa
Founder of Legal Search Marketing, helping law firms transform their practice with AI. Expert in GEO optimization, AI implementation, and legal technology strategy.
Ready to Implement AI at Your Firm?
Schedule a discovery call to discuss how AI can transform your practice.
Schedule Discovery Call

