Website Security Audit

Find the holes before
somebody else does.

Most people assume their site is secure because nothing has gone wrong yet. The trouble is that by the time something does go wrong the damage is already done, and clearing it up costs considerably more than checking would have. This is a thorough review of where your site is exposed, followed by the fixes, for a fixed fee of £495.

Book and pay £495 →

Anyone running a site that holds customer data, takes payments, or would be a genuine problem for the business if it vanished for a week. Which is most sites, once you think about it properly.

  • Google removes unsafe sites from search results entirely, not just further down them.
  • Automated bots scan millions of sites a day looking for a way in. Being small doesn't make you invisible, it makes you easier.
  • Cleanup, lost business, reputational damage and potential GDPR fines add up to a great deal more than prevention does.
  • If you're collecting emails, taking payments or holding customer records, keeping that safe is your responsibility whether you've thought about it or not.

A full audit first, using the industry standard tools plus manual checks, read against your actual setup rather than a generic scan. Known vulnerabilities, out of date software, exposed files, brute force risk, SSL configuration and the rest of it.

Then the fixes. Depending on what turns up that usually includes:

  • Updating WordPress core, themes and plugins to versions that aren't full of holes
  • Removing or replacing plugins that are vulnerable, abandoned or simply not needed
  • Hardening the WordPress configuration, including login protection, file permissions, XML-RPC and REST API exposure
  • Installing and configuring a security plugin and firewall that are actually worth having
  • Setting up or correcting SSL and HTTPS
  • Reviewing database access and tidying up user accounts
  • Checking for malware and suspicious code, and removing anything I find

You get a prioritised report of everything found and everything fixed, so there's a clear record of where you stood and where you now stand. Anything else I notice that affects your integrity, SEO or compliance gets flagged as well.

No scare tactics. Security gets sold on fear more than almost anything else in this industry, and I'd rather just tell you what's wrong, what it would actually mean if somebody exploited it, and what I've done about it.

I work on a staging copy wherever possible and let you know before anything happens on your live site. Access details are stored securely and deleted the moment the work is finished.

WordPress runs most of the web, which also makes it the most attacked platform on it. That's where I spend my time, so I know where the problems usually are and what's worth worrying about.

How it works

Fixed fee, fixed scope, so there's nothing to be surprised by. This is the whole thing from booking to report.

01. You book it

Pay the fixed fee of £495 and we get going. No lengthy forms and no unnecessary back and forth before anything useful happens.

02. I get access

I'll be in touch about access to your WordPress admin and, ideally, your hosting control panel. It's all stored securely and deleted once the job is finished.

03. The audit

A proper look at the WordPress install, plugins, themes and server configuration, checked against the known vulnerability databases relevant to your particular setup.

04. The fixes

The work gets done directly on your site, tested on a staging environment first wherever that's possible, so nothing breaks in the process of making it safer.

05. The report

Everything found and everything fixed, written up in plain English and put in priority order, so you know what mattered and what genuinely didn't.

06. What's next

Security isn't a one off. If you want ongoing monitoring and maintenance afterwards there's a plan for that, and if you don't, you'll at least know what to keep an eye on. Usually three to five working days from getting access.

Proof

Here's one that had already been through it:

Squash Wales

Squash Wales: Long Standing Digital Partner

A full rebrand and digital presence, followed by an ongoing partnership driving engagement. They came to me with a site Facebook had blocked outright for serving malicious code, and a membership system in a similar state. It got rebuilt from the ground up, and I've been their digital partner ever since.

Read the full story →

"What makes Alex special is how he combines top-notch technical skills with a genuine talent for communication. He has this great way of explaining complex technical stuff in plain English, which the stakeholders really appreciated."
Sir Alexander Skipwith, Fractional CPO
Frequently Asked Questions

Some things people often ask me:

What kind of websites do you work on?
Mostly WordPress and WooCommerce. If you're running something else, get in touch and I'll tell you whether I can help.
What if my site has already been hacked?
Get in touch before booking. An active breach needs emergency malware removal rather than a standard audit, and we should talk about that first. This service is aimed at sites that haven't been compromised yet.
Will this affect my live website?
I work on a staging environment wherever possible before deploying anything, and you'll always know before I go anywhere near your live site.
Do I need to give you access to my hosting?
Yes. To make the actual fixes rather than just list them I'll need your WordPress admin and ideally your hosting control panel. All access is stored securely and deleted once the work is complete.
What if my site needs more work than expected?
The £495 covers the audit and the standard fixes. If I find a serious active infection, or development work well beyond normal hardening, you'll be told up front with a separate quote before anything goes ahead.
Next Step

Ready to find out where you stand?
Book below and I'll come back to you within 24 hours to get started. If you'd rather ask a question first, send me an email.

People who trust me