Website Security Audit Leigh
A website security audit shows where your site is exposed before anyone takes advantage. We examine the WordPress install, the accounts that can log in and the server it runs on, then write up every weakness with the fix that closes it. It suits Leigh shops, makers, trades and logistics firms whose site works but has never been checked.
- Since 2003trading in Manchester
- 20,000+UK businesses helped
- Collect M8Unit 3, 116 Bury New Road
- A personchecks every file
Security and care
Every job is a fixed quote, agreed in writing before any work starts. No obligation.
- WordPress Malware RemovalWEB 101Quote
- Website Security Check-upWEB 102Quote
- WordPress MaintenanceWEB 103Quote
- Backups and RestoreWEB 104Quote
- SSL and HTTPS FixesWEB 105Quote
What a security audit means for Leigh websites
Many sites in Leigh grew in pieces. A maker at Leigh Spinners Mill starts with a portfolio, bolts on a shop, then adds a commission form that accepts file uploads. A logistics firm on the A580 adds a customer login so clients can download delivery notes. Each addition is a door that should be checked.
The audit examines those doors on a site that appears to be working normally. We do not clean infected files during an audit, and we do not run a penetration test unless that is agreed in writing. If we find signs of an existing hack, we stop and tell you, because that needs malware removal in Leigh rather than a report. The wider method is on our Manchester website security audit page.
Remote testing, with meetings at our office or yours
Every check can be done from our desks. You create a temporary administrator account and add limited hosting access if your host allows it, and we never ask for passwords by plain email. Findings are presented on a video call with a shared screen. To meet instead, our office in Cheetham Hill is roughly 35 to 45 minutes from Leigh by the East Lancashire Road, depending on traffic, or we can visit you by arrangement.
From scope to report
Agree what is tested
We write down the sites, subdomains and accounts in scope, and anything such as live payments that we must leave alone.
Inventory the software
Core, theme and plugin versions are listed and compared with WPScan and Patchstack vulnerability records.
Probe forms and uploads
We check which file types each form accepts, where uploads are stored and whether PHP can run in the uploads folder.
Look at logins and roles
Users, roles, password rules, two-factor authentication and login rate limits are all examined.
Test server settings
We check the PHP version, file permissions, XML-RPC, security headers and the HTTPS set-up.
Report and explain
You receive a risk-ranked report with a fix for each finding, then a call to go through it.
What lands in your inbox
- A plain-English report with findings ranked high, medium and low
- A list of outdated or abandoned plugins and themes
- Form and upload findings, including where files are kept
- A user list with suggested role changes
- Security header and HTTPS results with recommended values
- Notes on backups and whether a restore has been tested
- A fixed quote for the fixes, if you want us to do them
Weak spots we look for on maker shops and trade portals
- Nulled themes and plugins. Premium themes downloaded from unofficial sites often hide backdoors. We check licence status and compare files with official copies.
- Upload forms that accept anything. Commission and quote forms should limit file types and sizes, and store files where they cannot run as code.
- Customer portals. Client login areas need password rules, rate limiting and private pages that cannot be reached by guessing the address.
- Payment set-up on WooCommerce. We note whether card details are taken on the payment provider’s own page or inside your checkout, since the second needs closer care.
- Form entries kept for years. Many form plugins store every enquiry. We note what is kept and suggest a retention setting; on the legal side we follow published ICO guidance, and you should take advice for your situation.
Certificate and mixed content problems go to our SSL and HTTPS setup team, and sites running tracking scripts can use cookie consent setup for the banner and script blocking.
Frequently asked questions
Can the whole audit happen without anyone travelling to Leigh?
Yes. All the testing works through WordPress and hosting access, and the walk-through happens on a video call. If you would like to go through the report in person, we can meet at your premises by arrangement or at our office.
We trade from a unit at Leigh Spinners Mill and a freelancer built our shop. Do they need to be involved?
Not necessarily. We only need admin and hosting access, which you can grant yourself. It often helps to share the report with them, though, because some fixes, such as replacing a nulled theme, are easier for the person who knows how the site was put together.
Could the tests take our shop offline?
They should not. Most checks only read versions and settings, we keep away from live payments, and any restore test runs on a separate staging copy. Heavier scanning only happens if agreed first, at a quiet time for your business.
Do you check whether someone could send email pretending to be us?
Yes, as part of the domain checks. We look at your SPF, DKIM and DMARC records, which tell receiving mail servers which senders are genuine. Missing or loose records make it easier for scammers to send invoices or quote requests that appear to come from you.
Website security audits beyond Leigh
The same check is available through website security audits in Bolton, Eccles and Salford, and our Manchester audit page lists everything in scope. For all our other local services, see services in Leigh.
Share your site address and anything that already worries you, and we will suggest a scope and send a fixed quote before any testing begins. Book a security audit quote, call 0161 315 1151 or WhatsApp 07737 902425.
Website security audit across Greater Manchester and nearby
The same service, for businesses in other towns we work with from our Manchester office.
- Website security audit Manchester
- Website security audit Altrincham
- Website security audit Ashton-under-Lyne
- Website security audit Bolton
- Website security audit Bury
- Website security audit Chorlton
- Website security audit Droylsden
- Website security audit Eccles
- Website security audit Heywood
- Website security audit Hyde
- Website security audit Middleton
- Website security audit Oldham
- Website security audit Prestwich
- Website security audit Rochdale
- Website security audit Sale
- Website security audit Salford
- Website security audit Stockport
- Website security audit Stretford
Ready to get started?
Tell us what you need and we'll come back with an honest, fixed-price quote — no obligation.