Find the Holes Before Somebody Else Does
Most sites are not singled out. They are found by automated scanners sweeping the web for an unpatched plugin, a weak login or a misconfigured server. We audit WordPress, Magento and Drupal sites, then fix what we find.
Get a security auditAlready been hacked?
Audits from £299, quoted before we start. A real person replies within one working day.


Common Vulnerabilities
A site running a plugin that has not been patched in two years is not unlucky when it gets breached. It is exposed. These are the three we find most often, and what we check for each one.
Outdated Software
The leading cause of compromise. Known vulnerabilities are published, and scanners start looking for them the same week.
- Core, plugin, theme and server package versions listed
- Each one cross-referenced against known CVEs
- Ranked by whether it is actually exploitable on your site
Weak Authentication
Default usernames, reused passwords and no second factor on an admin login that anyone can find.
- Admin accounts and roles reviewed
- Two-factor and login rate limiting checked
- Login URL exposure and brute-force protection tested
Misconfiguration and Code
Servers that expose files they should not, and custom code nobody has read with security in mind.
- File permissions and exposed directories checked
- Custom code reviewed for SQL injection and XSS
- Magento stores checked for payment skimming code
What the Audit Actually Covers
We audit sites we did not build. Most people come to us after a breach, or because a compliance requirement has surfaced. An independent read of an inherited codebase is often the most useful security work there is.
Day 1: Software version analysis
We list every outdated component across the core CMS, plugins, themes and server packages, then cross-reference each one against known CVEs. That tells us which are genuinely exploitable on your setup rather than just out of date.
Day 1 to 2: Configuration and authentication
Server settings, file permissions, admin access and login protection are all assessed. Every weak point is written down with the specific fix next to it, not a generic recommendation.
Day 2 to 3: Plugin and extension audit
On WordPress, Magento and Drupal the plugin ecosystem is usually where the risk hides. We check every active extension for known issues and flag the ones that should be removed or replaced.
Day 3 to 4: Code review and testing
Custom development is read for SQL injection and cross-site scripting. We run common attack patterns against the live site in a controlled way, agreed with you in advance, with no downtime.
Day 5: Prioritised remediation report
Every finding categorised by severity, with the risk explained, the fix named and the effort estimated. Written so your developers and your board can both read it. We can carry out the fixes or hand the report to your team.
Sites We Keep Patched and Monitored
Security is mostly something that happens quietly every week rather than once a year. Three long-running support engagements where the patching, monitoring and code review below are part of the job.
Sumo Group
Gaming
Job Applications / month Tickets submissions / month Tickets resolution time How to increase job applications by 40.63%
Read the case study
Beauty Hygiene Plus
Ecommerce
Sales Uplift, Hosting and Support Costs Enhanced Sales and Reduced Costs for Beauty Hygiene Plus
Read the case study
MT Finance
Finance & Insurance
Traffic Increase, Session Engagement Increase Long-Term Support Leads to 475.78% Traffic Growth
Read the case study
Already been hacked?
Call us rather than filling in a form. Containment comes first, then removing the malicious code, then restoring from a backup we have checked is clean. Once the site is back we find the way in, close it, and tell you what data may have been exposed.
We take on compromised sites we have never seen before.
Not been hit yet?
That is the cheaper conversation. Monitoring, patching inside an agreed window and daily offsite backups run continuously under a support plan, and an audit is the sensible place to start.
Questions people ask before booking
What do I get, and what does it cost?
Will the audit take my site down?
Do you fix what you find, or just report it?
How do I know if my site has already been compromised?
How often should a security audit be done?
We already have SSL. Is that not enough?
Can you help with PCI DSS compliance?
Find Out Where You Are Exposed
Tell us the site and the platform. Here is what the report gives you.
- Every outdated component, checked against known CVEs rather than just version numbers
- Server, file permission and admin authentication findings
- Every active plugin or extension assessed, with the risky ones named
- Findings ranked by severity, each with the fix and the effort beside it
- A fixed price agreed before any work starts, from £299
No pitch. A real person replies within one working day. If you think you are compromised right now, call instead.
Request a Security Audit
Tell us your site and which platform it runs on. We will look before we reply.