Security · Performance · Plugin audits

An honest second opinion. No strings attached.

We audit inherited sites, bloated plugin stacks, security posture, and performance. You get a written report and prioritised fix list. No hard sell on us doing the work — take the report anywhere.
Audit report preview
HIGH Unauthenticated REST endpoint exposes user data
MED Uncached WooCommerce cart queries (480ms avg)
MED 3 abandoned plugins with known CVEs, no updates since 2022
LOW Missing HSTS header on 3 subdomains
INFO SSL/TLS configuration is current and correct
Prioritised fix list included 24 findings → 5 critical actions
scoped around your audit goals
0 Quote
business days from engagement to written report
0
hard sell — take the report anywhere you like
0
auditing WordPress stacks of every shape and size
0 Yrs
Audit types

Technical consulting: four audits, one honest report.

Each audit is scoped independently or bundled. All delivered as a written report with a prioritised action list and severity ratings.

Security audit

OWASP Top 10 review, unauthenticated endpoint testing, file permission audit, user role audit, plugin CVE check, server header review, and SQL injection surface mapping. Severity-rated findings with remediation guidance.

Performance audit

Core Web Vitals baseline, slow query analysis, object cache review, CDN configuration, image delivery, render-blocking resources, and server response time. Every slow path identified with the exact cause and fix.

Plugin stack audit

Every active and inactive plugin reviewed: purpose, last update, known CVEs, redundancy with other plugins, performance impact. Recommendations: keep, replace, consolidate, or remove. Replacement shortlist included.

SEO & technical health audit

Crawl analysis, duplicate content, canonicalisation, hreflang, redirect chains, schema validity, Core Web Vitals, and internal linking. Presented as a prioritised list with estimated ranking impact per fix.

Code & architecture review

Theme and custom plugin code review: naming conventions, SQL injection risks, unescaped output, deprecated function usage, and database schema design. For inherited codebases or pre-acquisition due diligence.

Hosting & infrastructure review

Server configuration, PHP version, SSL/TLS, backup regime, uptime monitoring, and disaster recovery readiness. Compared against best-practice benchmarks with a clear upgrade roadmap.
Process

Brief to written report in five days.

01

Brief & access

30-minute call to scope the audit. Read-only access requested — admin for WordPress, SSH not required unless performance audit includes server logs.
02

Audit

Automated scanning and manual review. We combine tooling (Semgrep, WPScan, Screaming Frog) with experienced human eyes on the results.
03

Findings

Every finding documented with: severity, affected file/URL, reproduction steps, and recommended fix. No raw exports — we translate what the scanner found.
04

Written report

Executive summary for stakeholders, technical appendix for developers. PDF and editable Word format. Delivered in 5 business days.
05

Readout call

Optional 60-minute walkthrough of findings with your team. Q&A on remediation options. No obligation to continue with us — the report is yours.
FAQ

Questions about technical audits.

Yes, if you want us to. You can either have your existing developer implement the recommendations or hire us to complete the work. The audit report is designed to be useful regardless of who performs the fixes.
The required access depends on the type of audit. Most website audits only require read-only WordPress administrator access, while performance or infrastructure reviews may also require hosting or server access.
Every audit includes an executive summary, a prioritised list of findings, technical recommendations, and a practical action plan to help you resolve issues efficiently.
Yes. We provide pre-acquisition technical audits to identify security risks, performance issues, code quality concerns, plugin dependencies, and potential maintenance costs before you invest.
No. We also review Laravel applications, Next.js projects, custom PHP applications, WooCommerce solutions, APIs, and bespoke plugins.
Absolutely. We regularly collaborate with in-house developers and external agencies, providing clear documentation and technical guidance to help implement our recommendations.
Yes. We review website security, plugin vulnerabilities, user permissions, server configuration, authentication, and other potential risks that could affect your website.
Yes. We analyse page speed, Core Web Vitals, database performance, hosting configuration, caching, images, JavaScript, and other factors that impact website performance.
Most audits are completed within a few business days, depending on the size and complexity of the website. Larger enterprise systems may require additional time.
Our audit services are ideal for businesses, agencies, eCommerce stores, charities, SaaS companies, and organisations that want to improve their website’s security, performance, maintainability, and long-term reliability.