On this page
What website security actually covers
Website security is the work of making sure your site does only what it was built to do. Visitors should be able to browse, fill in forms and buy things; they should not be able to read other customers’ data, upload a script to your server, or log in to your admin panel by guessing a password. Every public website is scanned constantly by automated tools looking for exactly those openings, whether the site belongs to a large brand or a small local business.
Our website security service is a defensive review and repair. We check your site against the weaknesses that are genuinely exploited in the wild — the categories described in the OWASP Top 10 — and fix what we find. It is carried out on systems you own or are authorised to change, with your written go-ahead before any testing begins.
Who needs it, and the warning signs
Any site that stores customer details, takes payments or has a login area benefits from a security review. Typical examples include a clinic with an online appointment form, an e-commerce store running WordPress and WooCommerce, a real estate portal where agents upload listings and photos, and a SaaS startup whose web app holds customer accounts.
Some signs that a review is overdue:
- Plugins, themes or frameworks that have not been updated in months.
- An admin panel reachable at a predictable address such as /wp-admin or /admin, with no extra protection.
- File upload forms that accept almost anything.
- Browser or search engine warnings about the site, or unexpected redirects reported by visitors.
- Nobody can say when the site was last checked, or by whom.
What’s included
The exact scope depends on your platform, but a typical engagement covers:
- Input handling — checking forms, search boxes and URL parameters for SQL injection and cross-site scripting (XSS) risks, and fixing validation and output encoding.
- Authentication and admin access — login rate limiting, two-factor authentication where supported, and restricting admin paths.
- File uploads — type and size restrictions, storage outside executable paths, and safe file naming.
- Components — outdated plugins, themes, libraries and CMS versions updated or replaced.
- Security headers and cookies — Content-Security-Policy, X-Frame-Options, Secure and HttpOnly cookie flags, and CSRF protection on forms.
- A written report — what was found, how serious it was, what we changed and what still needs a decision from you.
How we deliver it
- Agree scope in writing. Which domains, environments and systems are in scope, and confirmation that you own them or are authorised to have them tested.
- Take a backup. Before any change, we make sure a restorable copy of the site and database exists.
- Review. We combine automated scanning with a manual look at configuration, code and plugins, preferably on a staging copy rather than your live site.
- Prioritise. Findings are ranked by real-world risk to your business, not by how alarming a scanner’s label sounds.
- Fix and verify. Changes are applied, tested, and re-checked to confirm the issue is actually closed.
- Report. You receive a plain-language summary plus the technical detail your developers need.
Standards and tools we work with
We use the OWASP Top 10 as the backbone of the review, alongside the security guidance published for your specific platform, whether that is WordPress, Laravel, a Node.js application or a custom PHP codebase. Transport security is checked with external TLS testing, and where a site needs an extra layer, we can place it behind a web application firewall (WAF) such as Cloudflare’s.
What affects timeline and cost
A brochure site with a contact form is a much smaller job than a store with customer accounts or a portal with multiple user roles. The main factors are:
- The number of pages, forms, user roles and integrations in scope.
- Whether a staging copy exists or has to be created first.
- How far behind the software is — a site several major versions out of date may need careful, staged upgrades.
- Whether custom code is involved, which needs manual review rather than just configuration changes.
Common mistakes we see
- Installing a security plugin and assuming the job is done, while the plugins around it stay outdated.
- Sharing one admin login between staff and agencies, so nobody knows who changed what.
- Leaving old test copies of the site, database dumps or backup archives in public folders.
- Relying on hosting-provider backups that have never been restored.
Security is also not a one-time event. Once the site is clean, ongoing security updates keep it that way.
Frequently asked questions
Will the review take my website offline?
Not normally. We prefer to test on a staging copy, and changes to the live site are scheduled with you. If a fix needs a short maintenance window, we agree the time in advance.
Do you need written permission before testing?
Yes. We only test systems you own or are authorised to have tested, and we confirm the scope in writing before any work starts.
Can you guarantee my site won’t be hacked afterwards?
No honest provider can. We remove the known weaknesses, harden the configuration and recommend ongoing updates and monitoring, which substantially reduces the risk but never removes it entirely.
Do you work on sites you didn’t build?
Yes. Most of our security work is on sites built by someone else. We start with a short assessment so our recommendations reflect what is actually there.
What do we receive at the end?
A written report listing each finding, its severity, what we changed and anything that still needs a decision, plus notes your own developers can follow.
Talk to us about website security
Close the common holes: injection, XSS, exposed admin paths and outdated plugins.