$2,000–$4,000 + GST — Depends on site size and platform.
Authorised Website Security Baseline Review
A non-invasive review of your website's security baseline: TLS, headers, exposed admin paths, form handling, CMS and plugin hygiene, backups, and owner recovery path.
Who it is for
Businesses whose website takes enquiries, bookings, or payments, or whose brand would be damaged by a defacement or outage.
The problem it solves
Websites are usually set up once and left. Outdated plugins, exposed admin pages, weak form handling, and unclear hosting ownership are common and quietly dangerous.
What is included
- TLS and security header review
- Exposed admin path and software signal review
- Contact and booking form handling check (where do enquiries actually go?)
- CMS and plugin hygiene checklist (WordPress and similar platforms)
- Backup and restore-path review
- Owner recovery path: can you regain control if your developer disappears?
What is not included
- Intrusive vulnerability scanning or penetration testing unless a separate written testing scope is signed
- Code review of custom applications (separately scoped)
- Fixing the issues (available via sprints or your developer)
What you provide
- Written authorisation from the website owner
- Hosting and CMS details, or your developer's contact
Deliverables
- Baseline report with evidence and risk ratings
- Fix list for your developer or host
- Owner action list
Timeline
5 business days.
Boundaries
Non-invasive by default. Any active testing beyond public observation requires a signed testing scope with explicit written authorisation.