Website Security Audit: Find the Weak Points, Get a Fix List You Can Act On
You do not need a list of scary words. You need to know what is actually weak on your site, how serious each item is, and what to fix first — before someone else finds it.
A structured review of configuration, updates, access and recovery posture, ending in a prioritized report.
Site already hacked or defaced? Request Emergency Support.
1,000+ represents websites served cumulatively, not current actively audited sites. 2 hours means initial response on business days, not a fix time or 24/7 service.
What a Security Audit Is — and What It Is Not
Being clear about the boundary matters more here than anywhere else. An audit is a review that produces a plan, not a promise.
What it is
- A structured review of how the site is set up and maintained
- A prioritized list of findings, rated by severity
- A plain explanation of what to fix first, and why
- A point-in-time picture you can act on or hand to a developer
- A baseline to compare against as you fix things
What it is not
- A guarantee that a site can never be compromised
- Penetration testing — we do not offer that, and we will say so
- A substitute for ongoing patching and maintenance
- A cleanup service for a site that is already compromised
- A compliance certificate for a specific standard
Industry data shows that 39% of hacked WordPress sites were running outdated software. Currency of updates is one of the first things an audit checks — and one of the cheapest things to fix.
What We Review
Each area below is checked and then written up with a severity rating, so the report is a work list rather than a wall of warnings.
Platform and version currency
Core, CMS, plugin, theme and library versions, and how far behind they are.
Extension and plugin state
Abandoned, unmaintained or duplicated extensions that quietly widen the attack surface.
Authentication and access
Admin accounts, stale users, weak or shared credentials and who can reach the control panel.
Configuration and headers
Settings, permissions and response headers that either close or widen common attack paths.
Exposed files and directories
Backups, config files, logs and directories that are unnecessarily reachable from the web.
Backup and recovery posture
Whether backups exist, where they live, and whether a restore has ever been tested.
The Report You Get Back
Findings are rated so you can tell the difference between "fix this today" and "worth knowing".
| Severity | What it means | Typical action |
|---|---|---|
| Critical | Directly exploitable or already exposing data. | Fix first — often within days. |
| High | Meaningful risk that is likely to be targeted. | Schedule promptly as part of the next work. |
| Medium | Weakens defences or hides other problems. | Fix as part of routine maintenance. |
| Low | Hardening opportunity or best-practice gap. | Address over time or when convenient. |
Every finding comes with a short explanation of what it is, why it matters and what the fix involves — so you are not paying for a list you cannot read.
How an Audit Runs
Four steps, with the scope agreed before anything is touched.
1. Agree the scope
We confirm what is in scope, what access is required and how it is provided.
2. Review the surface
Automated checks run first to gather the broad picture quickly.
3. Manual verification
An engineer reviews the results, confirms real issues and discards false positives.
4. Report and walkthrough
You get the rated findings and a short walkthrough of what to fix first.
Automated Scan vs Professional Audit
A scanner is a useful first pass. It is not the same as an audit, and treating it as one is a common mistake.
A plugin or automated scan alone
- Flags many issues, including false positives
- Has no idea what matters for your business
- Cannot tell an abandoned plugin from a queued update
- Leaves you with alerts but no priority order
- Reads the surface only — configuration and access are missed
A professional audit
- Automated checks plus manual verification
- Findings rated by real severity and exploitability
- Context on what is worth fixing now, and what can wait
- A written explanation, not just a list of flags
- A baseline you can measure later remediation against
Silent Failures Are What We Catch
A site that goes down is obvious. The failures that cost the most are the quiet ones. A contact form stops sending. A checkout breaks for one payment method. Pages quietly drop out of search. Speed slips a little every week. Nothing crashes, so nothing shouts — the leads just stop.
That is the failure mode we watch for. Alongside uptime, we monitor the signals that go silent:
Form submissions
We test that your forms still reach their destination, so a broken contact or quote form does not sit unnoticed for weeks.
Checkout and orders
For stores, we watch the order path and flag signs that a payment step has stopped completing.
Search indexing
We check that your pages stay indexed, and that nothing is accidentally blocked from search after a change.
Speed and Core Web Vitals
We track real performance over time and flag gradual decline before it starts costing you conversions.
And You Hear About It Every Month
A maintenance plan should not be a silent invoice. Every month you receive a short report: what we updated and checked, what monitoring caught, what we fixed, and how much of your included hours were used. If nothing went wrong, the report still tells you what was verified — so “nothing happened” shows up as visible work, not silence.
You Own Your Site. Always.
Your domain, your hosting account, and your code belong to you. A maintenance provider should never be the only one holding the keys.
Your assets stay in your name
Domain, hosting, and site files remain yours and under your control. We work with your access — we do not take ownership of it.
A clean handover if you leave
If you move on, the agreement sets out how access, files, and credentials are returned. We do not hold your domain, and we do not charge a release fee.
This is written into our agreement, not just promised on a page.
Website Security Audit FAQ
What is a website security audit?
A structured review of how your site is configured and maintained, ending in a prioritized list of what to fix. We look at platform and extension currency, access and authentication, configuration, exposed files and permissions, and your backup and recovery posture — then rate each finding by severity and tell you what to fix first.
Do you offer penetration testing?
No. Penetration testing — actively attacking a system to find exploitable flaws — is a separate offensive-security discipline, and we do not present ourselves as offering it. If your situation calls for it, we will say so rather than stretch the word "audit" to cover it.
Is an audit a guarantee that my site is secure?
No, and no audit can be. An audit finds the weaknesses that are findable at a point in time. It reduces risk and gives you a clear fix list; it does not prove a site can never be compromised. That is why we recommend pairing it with ongoing maintenance.
How long does an audit take?
It depends on the size of the site and how many findings need verification. We confirm a delivery window before starting, and the report is written up after the manual review, not generated automatically.
Will you also fix the issues you find?
We can. The audit and the remediation are quoted separately so you can see the price of each. Many clients take the fix list and act on it, or move into a maintenance plan where routine fixes are covered.
Do you need my passwords to run an audit?
We work from the access you already own, and we ask for the minimum needed to inspect the site. Do not send credentials by email. We agree an access method and a scope in writing before any work starts.
Do you audit sites you did not build?
Yes. An audit does not depend on who built the site. In fact it is most useful on sites with an unclear history, or after a change of developer, host or platform.
Related Security and Recovery Services
Find Out What Needs Fixing
Send your site URL and tell us what prompted the request. We will confirm the audit scope, the access needed and the delivery window.
Already compromised? Request Emergency Support.