AI-Enabled Websites

Find the Holes Before Somebody Else Does

Most sites are not singled out. They are found by automated scanners sweeping the web for an unpatched plugin, a weak login or a misconfigured server. We audit WordPress, Magento and Drupal sites, then fix what we find.

Get a security auditAlready been hacked?

Audits from £299, quoted before we start. A real person replies within one working day.

Two colleagues going through a printed audit report together at a desk
£299Fixed-price WordPress audit
5 stagesEvery audit, every site
DailyBackups stored offsite
24/7Monitoring and alerting
Why It Matters

Common Vulnerabilities

A site running a plugin that has not been patched in two years is not unlucky when it gets breached. It is exposed. These are the three we find most often, and what we check for each one.

Outdated Software

The leading cause of compromise. Known vulnerabilities are published, and scanners start looking for them the same week.

  • Core, plugin, theme and server package versions listed
  • Each one cross-referenced against known CVEs
  • Ranked by whether it is actually exploitable on your site

Weak Authentication

Default usernames, reused passwords and no second factor on an admin login that anyone can find.

  • Admin accounts and roles reviewed
  • Two-factor and login rate limiting checked
  • Login URL exposure and brute-force protection tested

Misconfiguration and Code

Servers that expose files they should not, and custom code nobody has read with security in mind.

  • File permissions and exposed directories checked
  • Custom code reviewed for SQL injection and XSS
  • Magento stores checked for payment skimming code
How We Work

What the Audit Actually Covers

We audit sites we did not build. Most people come to us after a breach, or because a compliance requirement has surfaced. An independent read of an inherited codebase is often the most useful security work there is.

1

Day 1: Software version analysis

We list every outdated component across the core CMS, plugins, themes and server packages, then cross-reference each one against known CVEs. That tells us which are genuinely exploitable on your setup rather than just out of date.

2

Day 1 to 2: Configuration and authentication

Server settings, file permissions, admin access and login protection are all assessed. Every weak point is written down with the specific fix next to it, not a generic recommendation.

3

Day 2 to 3: Plugin and extension audit

On WordPress, Magento and Drupal the plugin ecosystem is usually where the risk hides. We check every active extension for known issues and flag the ones that should be removed or replaced.

4

Day 3 to 4: Code review and testing

Custom development is read for SQL injection and cross-site scripting. We run common attack patterns against the live site in a controlled way, agreed with you in advance, with no downtime.

5

Day 5: Prioritised remediation report

Every finding categorised by severity, with the risk explained, the fix named and the effort estimated. Written so your developers and your board can both read it. We can carry out the fixes or hand the report to your team.

Already been hacked?

Call us rather than filling in a form. Containment comes first, then removing the malicious code, then restoring from a backup we have checked is clean. Once the site is back we find the way in, close it, and tell you what data may have been exposed.

+44 (0) 20 8068 0360

We take on compromised sites we have never seen before.

Not been hit yet?

That is the cheaper conversation. Monitoring, patching inside an agreed window and daily offsite backups run continuously under a support plan, and an audit is the sensible place to start.

Questions people ask before booking

What do I get, and what does it cost?
A written report listing every finding by severity, each with the risk explained, the fix named and the effort estimated. It covers software versions against known CVEs, server and authentication configuration, every active plugin or extension, and a review of your custom code. It is written so your developers and your board can both read it. A standard WordPress audit is £299. Larger sites, or those needing a full custom code review, are quoted individually once we have seen the site. You get the price in writing before any work starts, and it does not move afterwards.
Will the audit take my site down?
No. The analysis and review stages touch nothing on the live site. The one stage that does, the controlled attack testing, is agreed with you in advance and scheduled around your traffic. If we recommend changes, those are separate work you approve first.
Do you fix what you find, or just report it?
Either. Plenty of clients take the report to their own developers, and that is a perfectly good outcome: the fixes are named and prioritised so someone else can act on them. If you would rather we did the work, we quote the remediation separately once you have seen the findings, so you are not committing to it blind.
How do I know if my site has already been compromised?
The usual signs are visitors being redirected somewhere unexpected, files in the codebase nobody recognises, spam leaving your domain, a warning in Google Search Console, or your host flagging unusual activity. Any one of those is worth a call the same day. If you are not sure, we can tell you inside an hour from a look at the site and the server logs.
How often should a security audit be done?
Once a year covers most sites. Twice a year if you take card payments or hold a lot of customer data. Beyond that it is event-driven: a platform upgrade, a new payment or login integration, or taking on a site built by someone else all justify a targeted review rather than waiting for the annual one.
We already have SSL. Is that not enough?
No, and it is the most common misunderstanding we hear. SSL encrypts the connection between a browser and your server, which stops someone reading traffic in transit. It does nothing about an outdated plugin, a weak admin password or a misconfigured server, which is how nearly every site we clean up was actually reached.
Can you help with PCI DSS compliance?
Yes. We advise on the requirements, implement the technical controls and prepare the documentation. Full certification needs a qualified assessor, which is not us, but we get the site to the point where the technical side passes.
Security Audit

Find Out Where You Are Exposed

Tell us the site and the platform. Here is what the report gives you.

  • Every outdated component, checked against known CVEs rather than just version numbers
  • Server, file permission and admin authentication findings
  • Every active plugin or extension assessed, with the risky ones named
  • Findings ranked by severity, each with the fix and the effort beside it
  • A fixed price agreed before any work starts, from £299

No pitch. A real person replies within one working day. If you think you are compromised right now, call instead.

Request a Security Audit

Tell us your site and which platform it runs on. We will look before we reply.

We ask for your work email so we can look at your site before we reply.