Skip to content
YSYarra Secure

Melbourne CBD, Victoria · Operating Australia wide

Authorised Website Security Baseline Review

A non-invasive review of your website's security baseline: TLS, headers, exposed admin paths, form handling, CMS and plugin hygiene, backups, and owner recovery path.

$2,000–$4,000 + GSTDepends on site size and platform.

Prices are in AUD and exclude GST. Yarra Secure is registered for GST, so 10% GST is added and itemised on your written quote and tax invoice.

Scope

Exactly what you get — and what you don't

Every Yarra Secure engagement has a written scope, a fixed price in AUD, and clear boundaries before work starts.

$2,000–$4,000 + GSTDepends on site size and platform.

Authorised Website Security Baseline Review

A non-invasive review of your website's security baseline: TLS, headers, exposed admin paths, form handling, CMS and plugin hygiene, backups, and owner recovery path.

Who it is for

Businesses whose website takes enquiries, bookings, or payments, or whose brand would be damaged by a defacement or outage.

The problem it solves

Websites are usually set up once and left. Outdated plugins, exposed admin pages, weak form handling, and unclear hosting ownership are common and quietly dangerous.

What is included
  • TLS and security header review
  • Exposed admin path and software signal review
  • Contact and booking form handling check (where do enquiries actually go?)
  • CMS and plugin hygiene checklist (WordPress and similar platforms)
  • Backup and restore-path review
  • Owner recovery path: can you regain control if your developer disappears?
What is not included
  • Intrusive vulnerability scanning or penetration testing unless a separate written testing scope is signed
  • Code review of custom applications (separately scoped)
  • Fixing the issues (available via sprints or your developer)
What you provide
  • Written authorisation from the website owner
  • Hosting and CMS details, or your developer's contact
Deliverables
  • Baseline report with evidence and risk ratings
  • Fix list for your developer or host
  • Owner action list

Timeline

5 business days.

Boundaries

Non-invasive by default. Any active testing beyond public observation requires a signed testing scope with explicit written authorisation.

Request a website review

Book a free 20-minute discovery call with Sam, or start with a 48-hour Quick Cyber Risk Review. No fear-based sales pressure, no inflated reports.

Or call Sam directly on 0435 315 894.