Skip to content
Security audit

Know exactly how secure your WordPress is - with evidence and clear priorities.

We review your WordPress installation end to end - core, plugins, users, server configuration - and deliver a prioritized report: what to fix first, what can wait, and why. No scare tactics, just evidence.

The problem

What a security audit is (and what it isn’t)

A WordPress site can run flawlessly for months and still have a door standing open that nobody has walked through yet. Most sites that end up hacked showed no visible signs that anything was wrong - the problem was already there, unexploited, until someone found it. An audit is about getting there first: reviewing your site with the same lens an attacker would use, before one does.

It’s not a five-minute automated scan that spits out a generic list of “best practices”. It’s a manual review of your actual installation: which plugins you run, on which versions, who has access and how the server is configured. The result isn’t an alarm - it’s a report with concrete findings, ordered by what genuinely matters to your business, not just by technical severity.

If you’ve never had your site audited, that doesn’t necessarily mean something is wrong - it’s the most common case there is. The first step is simple: you give us read-only access, and within a few days you have the full picture, with no obligation to buy anything else.

What's included

The full scope, no fine print

Every item is concrete, verifiable work. If something doesn't apply to your case, we say so in the diagnosis - not in an invoice.

  • Review of your WordPress, theme and plugin versions against known-vulnerability databases (CVE)
  • Review of administrator accounts, roles and permissions - catches unauthorized accounts and users with more access than they need
  • Check of password strength and whether two-factor authentication (2FA) is in place
  • Review of wp-config.php: security keys (salts), exposed debug constants and file permissions
  • Check of whether the site appears on Google Safe Browsing or other blocklists
  • Review of HTTP security headers: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options
  • Verification of your backups: whether they exist, where they live and whether they actually restore
  • Review of the web application firewall (WAF), if there is one, and whether it's properly configured
  • Malware and suspicious-file scan, even if the site shows no visible symptoms
  • Review of outdated plugins and themes, ones abandoned by their developer, and ones with reported vulnerabilities
  • Verification of the TLS/HTTPS certificate and its configuration
Process

How we do it

Steps in order, with honest timelines. When a deadline depends on a third party, we say so.

  1. 01

    Access and scope

    You give us read-only access to your hosting and WordPress. We agree on what gets reviewed and what stays out of scope, if your case calls for it.

    before we start
  2. 02

    Technical review

    We audit the core, plugins, themes, users, server configuration and security headers, using our own tooling plus external scanners.

    2–4 business days depending on the size of the site
  3. 03

    Prioritization of findings

    We rank every finding by severity and by its real impact on your business - not just by how technical it sounds.

    1 business day
  4. 04

    Report and review call

    You get the written report and a short call to go through it together and resolve any questions.

    at the close of the job
Deliverables

What you get at the end

The job doesn't end with "done" - it ends with something you can read, keep and verify.

  • An audit report in PDF: every finding with its severity, the evidence and how to fix it
  • A prioritized list of what to fix first, what can wait, and why
  • The results of the blocklist checks and external scans
  • A review call to resolve questions about the report
  • Concrete recommendations - with the option of having us implement them, or doing it yourself with the report as your guide
Questions

Frequently asked questions

How much does a security audit cost?

It depends on the size of your site and how many plugins and users it has - which is why we confirm the scope first. With that, you get a fixed quote before we start, with no open-ended hourly billing.

Will the audit disrupt my site or affect how it works?

No. It's a read-only review: we don't install anything or change any configuration during the audit. Your site keeps running exactly as before while we work.

What happens if you find something serious during the review?

We tell you immediately - we don't sit on it until the final report. If there's an actively exploitable vulnerability, or evidence that someone already got in, you hear about it the same day we find it.

Do you implement the fixes, or just report them?

The audit delivers the report and the priorities; implementing the fixes is the hardening service, quoted separately. You can take the report and apply it yourself, or ask us to do it for you.

Audit my site

Tell us about your site and what you need - we'll reply within one business day, with a fixed quote before anything starts.

Would you rather this never happened again?

The monthly plans include continuous monitoring, backups and incident response - the managed version of the recommendations in your report.

View plans