Security & resilience
Website & Code Security Audit
£500+ VAT
Fixed-scope, fully remote and human-reviewed.
One standard small-business website. We confirm it fits the fixed scope before payment.
Practical inclusions
- One primary domain, one related codebase or WordPress installation, and one production environment.
- Non-destructive public-site, code, dependency and configuration checks.
- Authentication, permissions, forms, uploads and API-boundary review.
- Manually validated findings with evidence and clear priorities.
- Plain-English report plus a 30-minute remote walkthrough.
- One limited retest of agreed fixes within 14 days.
Scope
A fixed scope, agreed first
The package covers one primary domain, one related codebase or WordPress installation, and one production environment. We confirm that the site fits before payment; larger e-commerce, multi-tenant or regulated platforms need separate scoping.
Review
What we review
We use non-destructive checks to review the public website and agreed test-user journey, source code or WordPress setup, dependencies, configuration, exposed secrets, authentication, permissions, forms, uploads, API boundaries, HTTPS, security headers and cookies.
Deliverables
What you receive
You receive manually validated findings ranked Critical, High, Medium or Low, evidence for each finding, a plain-English fix-first action plan, a 30-minute remote walkthrough, and one limited retest of agreed fixes within 14 days.
Boundaries
Clear boundaries
The fixed audit excludes destructive testing, denial-of-service, social engineering, third-party infrastructure, compliance certification, incident response and implementing the fixes. No audit can promise to find every possible vulnerability or prevent every future attack.
Why this matters now
See what recent AI-agent security incidents mean for an ordinary business website.
Read the practical incident guide →Useful questions
Before you book the audit.
What type of website fits the £500 audit?
A standard small-business website with one primary domain, one related codebase or WordPress installation, and one production environment. We confirm the fit before payment.
Will you take the website offline?
No. The fixed package uses non-destructive checks. Denial-of-service, destructive exploitation and testing third-party infrastructure are excluded.
Do you fix everything you find?
The £500 fee covers the audit, report, walkthrough and one limited retest. We can quote separately for fixes, or your existing developer can use the action plan.
Does the audit guarantee the website cannot be hacked?
No honest audit can guarantee that. It reduces uncertainty by identifying validated weaknesses in the agreed scope and putting the most important fixes first.