Website Security Audit Bolton
A website security audit is a structured check of a working WordPress site that ends in a written report: what is weak, how serious it is and how to fix it. We carry these out for Bolton manufacturers, distributors, professional practices and retailers who want an honest picture before anything goes wrong.
- Since 2003trading in Manchester
- 20,000+UK businesses helped
- Collect M8Unit 3, 116 Bury New Road
- A personchecks every file
Security and care
Every job is a fixed quote, agreed in writing before any work starts. No obligation.
- WordPress Malware RemovalWEB 101Quote
- Website Security Check-upWEB 102Quote
- WordPress MaintenanceWEB 103Quote
- Backups and RestoreWEB 104Quote
- SSL and HTTPS FixesWEB 105Quote
Why Bolton firms ask for a security check
Many manufacturing and distribution businesses along the M61 supply larger companies, and those customers often send questionnaires asking how websites and online systems are protected. An audit gives you evidence: versions, settings and test results you can point to.
Practices and professional firms hold enquiries and uploads that carry personal data, while town-centre retailers selling online carry payment risk through their checkout. In each case the useful question is not whether the site works today, but where an attacker would try first.
An audit is not a clean-up. A site already redirecting visitors or sending spam needs malware removal instead, and we will tell you if we see signs of that. Nor is it a penetration test unless one is agreed in writing. Our Manchester website security audit page sets out the standard scope.
Running the audit for a Bolton business
The checks are done remotely, using a temporary administrator account and read-only hosting access where your host offers it. Both can be deleted the moment the report arrives. We prefer to go through findings on a video call with both screens open, because some fixes need your decision. If your director or IT contact would rather discuss it face to face, meet us at the M8 office or ask us to visit by arrangement; it is roughly 25-35 minutes by road via the A666 and M61, traffic depending.
From scoping call to written report
Fix the boundaries
We agree which domains, subdomains and hosting accounts are included, and anything we must leave alone.
List every component
WordPress core, the theme and each plugin are recorded with version numbers and matched against public vulnerability databases such as WPScan and Patchstack.
Test the front door
We look at user roles, password rules, two-factor authentication, login attempt limits and whether an account called admin still exists.
Inspect the server side
PHP version, file permissions, exposed directories, XML-RPC and the HTTP security headers your server sends are all checked.
Try a restore
With your agreement, the latest backup is restored to a private copy to see whether it actually comes back intact.
Write it up
Findings are graded high, medium or low, each with a plain explanation and the fix that addresses it.
In your audit report
- A one-page summary a director can read in five minutes
- Every finding, graded by risk, with the fix beside it
- An inventory of core, theme and plugin versions
- User accounts and roles, with any that should go flagged
- Security header results and recommended settings
- The outcome of the backup restore test
- An optional fixed quote if you want us to make the fixes
Matching the report to a supplier security questionnaire
Questionnaires vary, but certain questions come up again and again. We follow published guidance, and you should take advice on what a particular customer or insurer expects.
- Is software kept patched? The inventory shows what was current on the audit date and what was behind.
- Do admin accounts use multi-factor authentication? The accounts section lists who has it switched on.
- Are backups tested? The restore test records whether the most recent backup worked.
- Is traffic encrypted? Certificate, HTTPS redirect and HSTS results answer it, and gaps can go to our SSL and HTTPS setup service.
- Who can change the website? The user list names every account with editing rights.
Once fixes are in place, keeping them there is ongoing work, which is what WordPress maintenance in Bolton covers.
Frequently asked questions
Can the audit be done without anyone coming to our Bolton premises?
Yes. Every check runs against your website and hosting, so a firm at Horwich and one beside Bolton Market are audited the same way. A visit only makes sense to talk through the report, and that is arranged when it suits you.
Our IT support company is based outside Bolton. Can you work with them?
Yes. We can send the report straight to them and agree who carries out each fix. Involving them from the scoping call avoids two people changing the same setting.
Will the checks slow the site or set off our host’s firewall?
Most checks only read information, and anything that writes data, such as the restore test, runs on a separate copy. We do not run heavy automated scans against the live site unless we have agreed it with you and your host beforehand.
How long does an audit stay accurate?
It is a snapshot of one date; new plugin vulnerabilities appear constantly. Once a year suits most business sites, with a fresh check after a host move, redesign or major plugin change.
What if you find the site has already been hacked?
We stop the audit, tell you what we saw and quote for a clean-up through WordPress malware removal. Auditing an infected site gives a misleading picture, so the clean comes first and the check follows.
Security checks for Bury, Leigh and Salford sites
We audit sites across the neighbouring towns too, with pages for Bury security audits, website security checks in Leigh and Salford site audits, all based on our Manchester audit service. For other local work, see the Bolton services hub.
Send us your domain and mention any questionnaire you need to answer, and we will scope the audit and confirm a fixed quote before work begins. Request an audit quote, phone 0161 315 1151 or WhatsApp the address to 07737 902425.
Website security audit across Greater Manchester and nearby
The same service, for businesses in other towns we work with from our Manchester office.
- Website security audit Manchester
- Website security audit Altrincham
- Website security audit Ashton-under-Lyne
- Website security audit Bury
- Website security audit Chorlton
- Website security audit Droylsden
- Website security audit Eccles
- Website security audit Heywood
- Website security audit Hyde
- Website security audit Leigh
- Website security audit Middleton
- Website security audit Oldham
- Website security audit Prestwich
- Website security audit Rochdale
- Website security audit Sale
- Website security audit Salford
- Website security audit Stockport
- Website security audit Stretford
Ready to get started?
Tell us what you need and we'll come back with an honest, fixed-price quote — no obligation.