Services / Security audit
Find out before someone else does.
A written security audit of any website costs £750, once. It covers headers, dependencies, exposed endpoints, login handling, email spoofing records, backups and what you store about customers — ranked by what would actually be exploited first. You do not have to be a client, there is no subscription attached, and if nothing needs doing the report says so.
£750 one-off
one site · written report · no subscription
What gets opened up
Headers and content policy
CSP, HSTS, frame-ancestors, referrer and permissions policy. The cheapest protections in existence and the ones most often absent entirely.
Dependencies
What you are running, what has a known advisory against it, and whether anything auto-updates without review — the dominant compromise route in 2026.
Exposed endpoints and admin routes
What is reachable from the internet that should not be. Staging URLs, open APIs, admin panels answering to the world.
Login, sessions, rate limiting
How the login behaves under repeated attempts, whether sessions expire, whether cookies are set correctly, whether two-factor exists.
SPF · DKIM · DMARC
Whether someone can send email as you. Effectively mandatory since the 2024 mailbox-provider enforcement, and most small businesses still fail all three.
Backups, and the restore
Not whether backups exist — whether a restore has ever been performed. A backup nobody has restored is a hope.
What you store about customers
Retention, deletion on request, and whether the consent banner does what it claims. Compliance exposure, but the same conversation.
Speed and Core Web Vitals
Included because it is measured in the same pass and because it is usually the finding with the clearest commercial value.
The questions people actually ask
- Do I have to be a client?
- No, and it does not turn you into one. It is the one thing we sell to people who have never worked with us and may never — including sites we did not build and would not have built.
- What if you find nothing?
- Then the report says so. A report that manufactures findings to justify its price is worth less than no report, and you would be right never to trust the next one.
- Will you fix what you find?
- We will quote for it, and for a site we did not build we will usually tell you honestly whether fixing or rebuilding is the better spend. We do not take on ongoing upkeep for other people's code — inheriting an unknown plugin stack means inheriting someone else's incident.
- Is this a penetration test?
- No, and anyone selling you one for £750 is not selling you one. This is a configuration and exposure audit: what is misconfigured, what is out of date, what is reachable that should not be, and what you are keeping about your customers.
- How long does it take?
- Usually two to three working days from access. You get a written report ranked by what would actually be exploited first, not by what scores worst on a scanner.
- What do you need from me?
- The address, and read access to anything you want checked properly — the hosting panel or repository if you have one. We can do a meaningful external audit with nothing but the URL.
The most common way a small business gets hacked is a plugin nobody updated.