Menu
Security audit and hardening

Find it before somebody else does

A website and server security audit that looks where scanners do not — then closes what it finds, with the whole thing written so your own developers can check it.

What we do

A website security audit that looks where scanners do not

Most sites are not attacked. They are found.

Nobody targeted your business. A script went looking for a known weakness across a million addresses, found yours, and used it. That is how almost every small-business compromise happens, and it is why “we are too small to be a target” is not the protection people think it is.

The exposures that matter are rarely exotic. A backup file left in a folder anybody can reach. Credentials in a configuration file the web server will happily serve. A directory where uploaded files can be executed rather than merely stored. An admin account still using a password from three years ago.

What a scan will not find

Security plugins check what they know to look for, which is the published list of vulnerable plugin versions. They do not know that your uploads folder will run code, or that a 483 MB database export has been sitting at a guessable address since March.

We know because we found exactly that on our own infrastructure — four live exposures in one day, none of which any scanner had flagged. A database archive anybody could download. Plaintext credentials at the web root. Code execution in the uploads directory. And a disk at 99%, days from taking the site down on its own.

Then we close it

A website security audit that produces a list and stops is half a service. Findings come ranked by what they would actually cost you if exploited, and remediation is quoted alongside — so you can fix the serious ones now and schedule the rest.

Everything is written so your own developers can verify it. A security report you have to take on faith is not a report, it is a sales document.

What this is not

This is not penetration testing, and it is not a compliance certification. If you need a formal accredited assessment for an insurer or a tender, you need a specialist firm and we will tell you so.

What this is: somebody who builds these systems looking properly at yours, and closing what they find. Note also that under POPIA, a breach involving personal information carries notification obligations — which makes finding the exposure first considerably cheaper than finding it second.

A security plugin reports that everything is fine. That is not the same as everything being fine.

DIGIDMN
See what is included
website security audit server and application review

What an audit finds

What a website security audit turned up on our own infrastructure

Four live exposures, none of them flagged by a scanner, all closed the same day.

4

Live exposures found and closed in one day

483MB

Database archive found publicly downloadable

0

Of them flagged by an automated scanner

1 Week

Typical turnaround for an audit report

What is included

Every security audit includes

1

Exposure review

What is reachable from outside that should not be — files, folders, archives, endpoints.

2

Application review

Plugin and theme versions against known vulnerabilities, plus configuration that scanners do not check.

3

Server review

Web server configuration, file permissions, execution rules, disk headroom and certificate state.

4

Access and credential review

Who has access, at what level, and whether anything is stored where it should not be.

5

Ranked findings

Every issue rated by what it would actually cost you if exploited, not by a generic severity score.

6

Remediation

The serious findings closed, the rest quoted and scheduled. Verified afterwards, not assumed.

Common questions

Website security questions answered

What people ask before commissioning a website security audit.

The audit is a fixed price based on the size of the site and whether the server is included. You get the findings whether or not you ask us to fix anything.

Remediation is quoted afterwards, once we know what is actually there. Quoting the fix before finding the fault would be guessing, and on security it would be guessing in the direction that suits us.

Tell us the address and what it runs on, and we will price the audit.

Start here

Get a security audit before you need one

Send us the address and tell us what it runs on. We will find what is exposed, tell you what each finding would cost you, and quote the fixes — and you get the report whether or not we do the work.