School websites function as public educational service platforms that must ensure the confidentiality, integrity, and availability of information. This study evaluates the security of the SMK Negeri 2 Situbondo website using OWASP ZAP as a Dynamic Application Security Testing tool within the public-access scope. The novelty of this research lies in the cross-comparison of three school websites within the same region, the mapping of findings to OWASP A05 Security Misconfiguration, and the integration of the results with educational digital transformation governance, data protection policies, and Sustainable Development Goals. The scanning results of the primary website identified 26 alert types, consisting of 0 High, 12 Medium, 7 Low, and 7 Informational findings. The dominant vulnerabilities were related to weaknesses in Content Security Policy, HTTP security header configuration, cookie controls, and third-party resource governance. The comparison websites exhibited similar vulnerability patterns, although with different quantities and severity levels. Priority recommendations include hardening Content Security Policy, HSTS, anti-clickjacking mechanisms, X-Content-Type-Options, cookie attributes, anti-CSRF tokens, and Subresource Integrity implementation. These findings provide an operational baseline for school administrators to strengthen the security of digital education services gradually and systematically.
Copyrights © 2026