YSYarra Secure

Melbourne CBD, Victoria · Operating Australia wide

Website security reviews for small business

Websites are usually set up once and left. Outdated plugins, exposed admin pages, forms that silently fail, and hosting accounts only the old developer can access are common — and quietly dangerous. Our baseline review checks what matters without touching anything, and gives your developer or host a clear fix list.

Who this is for

  • Businesses whose website takes enquiries, bookings, or payments
  • WordPress, Shopify, and custom-site owners without a recent security review
  • Owners unsure they could regain control of their site if their developer disappeared

What's included

  • TLS and security header review
  • Exposed admin paths and software disclosure signals
  • CMS and plugin hygiene checklist
  • Contact and booking form testing — where do enquiries actually go?
  • Backup and restore-path review
  • Owner recovery path: registrar, hosting, and access you control
  • A fix list split between owner, developer, and host actions

What's not included

  • Intrusive vulnerability scanning or penetration testing (separate signed scope required)
  • Custom application code review (scoped separately)
  • Implementing the fixes (available via sprints or your developer)

Pricing

From $2,000–$4,000 AUD depending on site size and platform.

Prices are in AUD. GST treatment to be confirmed; your written quote states the exact amount payable.

Get a written quote

Common questions

Could the review break or slow our website?

No. The baseline review is non-invasive by design: public observation, configuration review with your access, and approved test enquiries. Anything more active requires a separately signed testing scope.

Do you need our hosting passwords?

No — we never ask for your passwords. Reviews use screen-share sessions you drive, your own screenshots, or temporary accounts you create and control.

Our site was built by an agency — can you still review it?

Yes, with your written authorisation as the site owner. The fix list is written so your agency or any competent developer can act on it directly.

Request a website review

Book a free 20-minute discovery call with Sam, or start with a 48-hour Quick Cyber Risk Review. No fear-based sales pressure, no inflated reports.

Or call Sam directly on 0435 315 894.