Website security audit
The website works, enquiries keep coming in, and security feels like something to deal with later. Yet a break-in rarely looks spectacular: far more often it is a quiet script inside an outdated plugin that sends spam for months, swaps links in search results or quietly copies your customer database. The owner is the last to find out — from the hosting provider, from a browser warning screen or from the customers themselves.
A security audit is a check of your website before an attacker gets to it first. We look at the site the way an intruder would, but the result goes to you: a list of weak spots, a risk rating for each of them and a plan in plain words — what to fix today and what can wait.
We review not only the pages, but everything around them: the server, the control panel, mail, payment integrations and third-party scripts. A single fatal hole is rare — usually it is a chain of small things, each of which looks harmless on its own.
What the audit covers
- Reconnaissance and inventory: domains and subdomains, open ports, forgotten copies of the site, staging servers and admin panels reachable from the internet.
- Versions and updates: the CMS, plugins, themes, libraries and server software are checked against databases of known vulnerabilities.
- Code and forms: SQL injection, XSS, arbitrary file upload, authentication bypass, unsafe handling of sessions and cookies.
- Access rights: accounts and roles in the admin area, file and folder permissions, access to backups, logs and configuration files.
- Connection and headers: the certificate, redirects, HSTS, CSP, protection against clickjacking and data leaks through third-party scripts.
- Traces of infection: foreign code in templates, hidden links and doorway pages, extra scheduled jobs, suspicious records in the logs.
- Resilience: whether backups exist, whether restoring them has ever been tested and how long it takes to bring the site back.
Automated scanners find the typical mistakes, but logical holes are visible only to a person: someone else’s order opened by a direct link, access to another customer’s account, a discount that can simply be placed into the request. That is why tools here do not replace manual work — they support it.
What you receive
The report is written in normal language instead of being exported from a scanner. For every finding you see where it was found, what it means for the business and how to fix it.
- A list of vulnerabilities by priority: critical, important, minor.
- Step-by-step instructions for your developer or hosting support.
- An estimate of the effort needed to close each finding.
- A short summary for the manager, with no technical terms.
If you have no team of your own, we fix what we found ourselves: update the engine, clean infected files, close unnecessary access, set up backups and file change monitoring so that the next attempt is visible immediately. When the work is done we run the check again and make sure the holes are closed and the site has lost nothing along the way.
We start with a short discussion of the task. We clarify what exactly is being checked, whether access to the server and the control panel is available, whether the live version may be touched and when the load is at its lowest. Testing on a production project is done carefully: we do not use scenarios that could take the site down or damage data, and the vulnerabilities we find are never published or passed to third parties.
The price and the schedule depend on the size of the site, its engine and the depth of the check: for a business-card website it is a few days, for an online store with integrations noticeably longer. Write to us and describe the project in a couple of sentences — we will estimate the work and suggest the format that solves your task.