Analisis Komparatif Kerentanan Website SMK At-Tamimi dengan Hosting InfinityFree Menggunakan Metode Penetration Testing
Abstract
This research is motivated by the increasing security needs of school digital services, while the management and configuration of systems on several school websites still has the potential to cause security gaps. The purpose of this study is to analyze and compare the security level of SMK At-Tamimi's website with InfinityFree hosting and recommend the most relevant improvements. The method used is non-destructive penetration testing with a comparative descriptive approach, through the stages of footprinting, scanning-fingerprinting, vulnerability verification, and reporting. The test was carried out on two school websites, namely SMK At-Tamimi and MAN 2 Situbondo, using the ZAP by Checkmarx application and supporting checks on the website security configuration. The test results show the difference in risk levels between websites. Both websites generate 9 alerts. The SMK At-Tamimi website contains 1 finding of High risk (11.1%), 2 Medium (22.2%), 2 Low (22.2%), and 4 Informational (44.4%), while MAN 2 Situbondo does not contain High (0%) findings, with 2 Medium (22.2%), 4 Low (44.4%), and 3 Informational (33.3%). The MAN 2 Situbondo website has the highest level of security because there are no indications of high-risk vulnerabilities as well as better configuration. The SMK At-Tamimi website is in a lower security position compared to its comparative website, because there is an indication of Cloud Metadata Potentially Exposed, but it is not accompanied by proof of access that can be validated within the test limit. The findings of the study indicate the need to strengthen the security configuration of school websites through the implementation of HTTPS/SSL, the addition of security headers, and regular system updates. Additionally, the use of paid hosting can be an alternative to gaining broader control over security configurations and reducing the risk of security misconfiguration.
References
F. Septian, M. H. Arfian, J. S. Asri, and B. Tjahjono, “Pengujian Keamanan Website dengan Metode Penetration Testing (Studi Kasus : Universitas Esa Unggul),” J. Soc. Sci. Res. Vol., vol. 4, pp. 3629–3647, 2024.
P. Kusuma, R. A. Pakkaja, and K. Kunci, “Analisis Vulnerability Assessment Menggunakan OWASP ZAP untuk Mengidentifikasi Celah Keamanan Website,” AICOM Artif. Intell. Comput., vol. 01, no. 04, pp. 115–123, 2026.
S. Azizah et al., “Keamanan siber sebagai fondasi pengembangan aplikasi keuangan mobile : Studi literatur mengenai cybercrime dan mitigasinya kehidupan , aplikasi keuangan mobile telah menjadi salah satu inovasi terkemuka yang bisnis dalam mengakses dan mengelola keuangan s,” vol. 17, no. April, pp. 221–237, 2024.
A. S. R. Saepudin Hidayat, “KEMANDIRIAN SIBER INDONESIA : TANTANGAN DAN PELUANG MENUJU KEDAULATAN DIGITAL,” Int. J. Soc. Manag. Stud., vol. 6, no. 5, pp. 98–102, 2025.
F. Widianto, E. S. Wijaya, A. P. Wicaksono, T. Informatika, F. Teknik, and U. M. Purwokerto, “Analisis Kerentanan Pada Aplikasi Web Menggunakan Metode PTES,” J. Pendidik. dan Teknol. Indones., vol. 5, no. 1, pp. 155–166, 2025.
A. Fatihah and P. Dinarto, “Analisis Keamanan Aplikasi Website Menggunakan Metode Penetration Testing Berdasarkan Framework ISSAF Pada Perusahaan Daerah XYZ,” Innov. J. Soc. Sci. Res. Vol., vol. 4, no. 2, pp. 4536–4549, 2024.
G. Arna and I. M. E. L. Saskara, “SECURITY TESTING WITH PENETRATION TESTING EXECUTION STANDARD (PTES) METHODS TO FIND MISCONFIGURATIONS VULNERABILITIES IN NETWORK DEVICES,” J. Elektro Luceat, vol. 10, no. 2, 2024.
A. Yahya, A. Wijaya, and W. E. Sary, “Pengembangan Strategi Digital Umkm Melalui Edukasi Pemanfaatan Website di Kedai Mbak Windah Bengkulu,” vol. 5, no. 2, pp. 218–229, 2025.
H. P. Fitrian, L. Abidah, K. W. Zahra, W. H. Hafidudin, T. Informatika, and U. T. Digital, “PENGARUH KESADARAN PENGGUNA TERHADAP KEBERHASILAN SERANGAN PHISHING DI JARINGAN PERBANKAN,” JATI (Jurnal Mhs. Tek. Inform., vol. 9, no. 2, pp. 1888–1892, 2025.
M. Wahyu, A. Saputra, S. A. Ashari, and E. Larosa, “Keamanan Data Sistem Informasi Akademik ITEkes Mahardika : Penerapan Sistem Pencadangan Basis Data dengan Enkripsi AES,” Invert. J. Inf. Technol. Educ., vol. 4, no. 1, pp. 79–85, 2024.
A. P. Armadhani, D. Nofriansyah, and K. Ibnutama, “Analisis Keamanan Untuk Mengetahui Vulnerability Pada DVWA Lab Testing Menggunakan Penetration Testing Standart OWASP,” vol. 21, no. 2, pp. 80–88, 2022.
M. A. N. Nanda Hidayat, “ANALISIS CELAH KEAMANAN PADA WEBSITE SMA NEGERI 3 BERAU Abstraksi Keywords : Pendahuluan Tinjauan Pustaka Metode Penelitian,” J. Inf. Syst. Manag., vol. 6, no. 2, pp. 102–108, 2025.
H. Pahlawansah, M. F. Basmar, and M. Yusuf, “Analisis Kerentanan Website SMK Muhammadiyah 2 Bontoala Makassar Menggunakan Metode OWASP (Open Web Application Security Project),” BIOS J. Teknol. Inf. Dan Rekayasa Komput., vol. 6, no. 2, pp. 92–100, 2025.
A. A. Zahrani, D. S. Alifah, Y. Cahyani, and I. Albana, “Analisis Vulnerability Assessment pada Sistem Informasi Website IITC Intermedia Universitas Amikom Purwokerto Menggunakan OWASP ZAP,” J. Publ. Sist. Inf. Dan Telekomun., vol. 3, no. 2, pp. 55–68, 2025.
A. Wirasto and D. Mustofa, “ANALISIS KEAMANAN APLIKASI BERBASIS WEB DI UNIVERSITAS HARAPAN BANGSA MENGGUNAKAN PTES,” J. Inf. Interaktif, vol. 8, no. 3, pp. 89–94, 2023.
P. Satya, S. Kiran, and D. Valluri, “Web Application Security through Comprehensive Vulnerability Assessment,” Procedia Comput. Sci., vol. 230, no. 2023, pp. 168–182, 2024, doi: 10.1016/j.procs.2023.12.072.
S. A. Nugroho and T. Rochmadi, “Analisis Keamanan Sistem Informasi Pusaka Magelang Menggunakan Open Web Application Security Project (OWASP) Dan Information Systems Security Assessment Framework (ISSAF) Security Analysis Of Magelang Pusaka Information System Using Open Web Applicati,” CyberSecurity dan Forensik Digit., vol. 7, no. 1, pp. 56–61, 2024.
A. Y. Lestari and J. N. Utamajaya, “Audit Sistem Informasi Aplikasi Sirekap KPU : Analisis Keamanan dan Efisiensi,” J. Sains dan Teknol. Inf., vol. 2, no. 5, pp. 23–32, 2024.
Y. Y. Pratama and I. Albana, “Analisis Risiko Keamanan Website Kompetisi Nasional Menggunakan Metode Vulnerability Assessment dan CVSS 4.0 Security Risk Analysis of National Competition Website Using Vulnerability Assessment Method and CVSS 4.0,” J. Electr. Electron. Mech. Inform. Soc. Appl. Sci., vol. 4, no. 2, pp. 12–28, 2025.
A. D. Rahmawati, “Analisis Keamanan Jaringan Menggunakan Metode Penetration Testing Terstruktur,” J. Sist. Inf., vol. 1, no. 1, pp. 1–8, 2025.
M. Tahir and M. Risky, “Analisis Keamanan Website Dinas Pemerintahan Yogyakarta Dengan Metode PTES (Penetration Testing Execution Standard),” J. Tek. Inform. Unika ST. Thomas, vol. 09, no. 01, pp. 118–125, 2024.
D. W. Febrian, R. B. Huwae, and A. Z. Mardiansyah, “Analisis Keamanan Website Perguruan Tinggi di Nusa Tenggara Barat terhadap Serangan SQL Injection , Cross-Site Scripting , dan Insecure Direct Object Reference melalui Pengujian Penetrasi Security Analysis of University Websites in West Nusa Tenggara,” J. Bumigora Inf. Technol., vol. 7, no. 1, pp. 25–38, 2025, doi: 10.30812/bite/v7i1.5032.
F. A. Maylani, M. Tahir, N. N. Juniar, D. Sari, and W. A. Zulaica, “ANALISIS KEAMANAN WEBSITE E-LIBRARY KAMPUS DENGAN METODE PTES (PENETRATION TESTING EXECUTION STANDARD),” JATI (Jurnal Mhs. Tek. Inform., vol. 9, no. 4, pp. 5643–5650, 2025.
M. A. Mira Orisa, “VULNERABILITY ASSESSMENT UNTUK MENINGKATKAN KUALITAS KEMANAN WEB,” J. Mnemon., vol. 4, no. 1, pp. 16–19, 2021.
I. N. B. I Kadek Ryan Jody Prayoga, Putu Wida Gunawan, “Analisis Keamanan Sistem Informasi Website Kampus Menggunakan Metode Penetration Test,” semanTIK, vol. 11, no. 2, pp. 115–123, 2025.
Copyright (c) 2026 Nabila Nabila, Firman Jaya, Nur Azizah

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors retain copyright and grant the EXPLORER right of first publication with the work simultaneously licensed under a Creative Commons Attribution License (CC BY-SA 4.0) that allows others to share (copy and redistribute the material in any medium or format) and adapt (remix, transform, and build upon the material) the work for any purpose, even commercially with an acknowledgement of the work's authorship and initial publication in EXPLORER.
Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in EXPLORER.
Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).





.png)















