Security · Performance · Plugin audits
An honest second opinion. No strings attached.
We audit inherited sites, bloated plugin stacks, security posture, and performance. You get a written report and prioritised fix list. No hard sell on us doing the work — take the report anywhere.
- Security audit against OWASP Top 10 — written findings with severity ratings
- Performance and query audit — what's slow and exactly why
- Plugin stack review — what to keep, consolidate, replace, or remove
- Quoted after a short scope call. Delivered in 5 business days.
Audit report preview
HIGH
Unauthenticated REST endpoint exposes user data
MED
Uncached WooCommerce cart queries (480ms avg)
MED
3 abandoned plugins with known CVEs, no updates since 2022
LOW
Missing HSTS header on 3 subdomains
INFO
SSL/TLS configuration is current and correct
Prioritised fix list included
24 findings → 5 critical actions
scoped around your audit goals
0
Quote
business days from engagement to written report
0
hard sell — take the report anywhere you like
0
auditing WordPress stacks of every shape and size
0
Yrs
Audit types
Technical consulting: four audits, one honest report.
Each audit is scoped independently or bundled. All delivered as a written report with a prioritised action list and severity ratings.
Security audit
OWASP Top 10 review, unauthenticated endpoint testing, file permission audit, user role audit, plugin CVE check, server header review, and SQL injection surface mapping. Severity-rated findings with remediation guidance.
Performance audit
Core Web Vitals baseline, slow query analysis, object cache review, CDN configuration, image delivery, render-blocking resources, and server response time. Every slow path identified with the exact cause and fix.
Plugin stack audit
Every active and inactive plugin reviewed: purpose, last update, known CVEs, redundancy with other plugins, performance impact. Recommendations: keep, replace, consolidate, or remove. Replacement shortlist included.
SEO & technical health audit
Crawl analysis, duplicate content, canonicalisation, hreflang, redirect chains, schema validity, Core Web Vitals, and internal linking. Presented as a prioritised list with estimated ranking impact per fix.
Code & architecture review
Theme and custom plugin code review: naming conventions, SQL injection risks, unescaped output, deprecated function usage, and database schema design. For inherited codebases or pre-acquisition due diligence.
Hosting & infrastructure review
Server configuration, PHP version, SSL/TLS, backup regime, uptime monitoring, and disaster recovery readiness. Compared against best-practice benchmarks with a clear upgrade roadmap.
Process
Brief to written report in five days.
01
Brief & access
30-minute call to scope the audit. Read-only access requested — admin for WordPress, SSH not required unless performance audit includes server logs.
02
Audit
Automated scanning and manual review. We combine tooling (Semgrep, WPScan, Screaming Frog) with experienced human eyes on the results.
03
Findings
Every finding documented with: severity, affected file/URL, reproduction steps, and recommended fix. No raw exports — we translate what the scanner found.
04
Written report
Executive summary for stakeholders, technical appendix for developers. PDF and editable Word format. Delivered in 5 business days.
05
Readout call
Optional 60-minute walkthrough of findings with your team. Q&A on remediation options. No obligation to continue with us — the report is yours.
FAQ
Questions about technical audits.
Yes, if you want us to. You can either have your existing developer implement the recommendations or hire us to complete the work. The audit report is designed to be useful regardless of who performs the fixes.
The required access depends on the type of audit. Most website audits only require read-only WordPress administrator access, while performance or infrastructure reviews may also require hosting or server access.
Every audit includes an executive summary, a prioritised list of findings, technical recommendations, and a practical action plan to help you resolve issues efficiently.
Yes. We provide pre-acquisition technical audits to identify security risks, performance issues, code quality concerns, plugin dependencies, and potential maintenance costs before you invest.
No. We also review Laravel applications, Next.js projects, custom PHP applications, WooCommerce solutions, APIs, and bespoke plugins.
Absolutely. We regularly collaborate with in-house developers and external agencies, providing clear documentation and technical guidance to help implement our recommendations.
Yes. We review website security, plugin vulnerabilities, user permissions, server configuration, authentication, and other potential risks that could affect your website.
Yes. We analyse page speed, Core Web Vitals, database performance, hosting configuration, caching, images, JavaScript, and other factors that impact website performance.
Most audits are completed within a few business days, depending on the size and complexity of the website. Larger enterprise systems may require additional time.
Our audit services are ideal for businesses, agencies, eCommerce stores, charities, SaaS companies, and organisations that want to improve their website’s security, performance, maintainability, and long-term reliability.
Know exactly what you've got.
A scoped technical audit in 5 business days. Written report, prioritised fix list, no obligation to use us for the work. Ask for a quote and we’ll shape it around the exact audit you need.