This check reads the settings, not the software behind them
Websitecontrole reads what a site shows from the outside: the security settings it sends, its connection, its domain, the third parties it loads. What it does not do is test the software itself. It does not read the code, it does not log in, and it does not check whether the platform, its extensions or the server software are up to date. That is a deliberate line, and it is worth knowing what is and is not in this grade.
Maintenance matters at least as much
Most sites are not breached through a missing header, but through outdated software: a platform, an extension or a server package with a known hole that was not closed in time. A tidy configuration helps, but it does not stop an outdated extension. Maintenance is not a side issue, it is the core of a secure site.
How fast you must update differs per platform
Some platforms set hard deadlines tied to severity: critical holes immediately, high within about a month, moderate within a few months. Some systems update their own core automatically, which helps, but the extensions and themes on top, where most of the vulnerabilities live, are often not updated for you by default. That is exactly where active maintenance is needed. The common thread: close security holes quickly, and critical ones ideally the same day.
A good grade is a snapshot
The grade on this site says something about how the configuration stands right now, not whether the software behind it is well maintained and still will be tomorrow. A site that scores an A today but gets no updates for six months is not secure six months from now. Treat this as a starting point and a periodic check, not a seal that keeps holding.
Good settings and good maintenance are two different jobs. This tool measures the first. The second is ongoing, and it is the one that keeps a site safe over time.