Website Security Audit Manchester
A security check-up looks at your website before anything goes wrong and shows where the weak points are. We review WordPress sites for Manchester businesses, test the settings attackers usually target, and hand you a written report with fixes ranked by risk.
- Since 2003trading in Manchester
- 20,000+UK businesses helped
- Collect M8Unit 3, 116 Bury New Road
- A personchecks every file
Security and care
Every job is a fixed quote, agreed in writing before any work starts. No obligation.
- WordPress Malware RemovalWEB 101Quote
- WordPress MaintenanceWEB 102Quote
- Backups and RestoreWEB 103Quote
- SSL and HTTPS FixesWEB 104Quote
- Uptime MonitoringWEB 105Quote
Where WordPress sites are usually weak
Most break-ins start with something already known: a plugin with a published vulnerability, an admin with a weak password, or a login page that accepts unlimited guesses. We compare your core, theme and plugin versions with public vulnerability databases, and flag plugins their developers have abandoned or that were pulled from the WordPress.org directory.
Then we look outside WordPress itself: the PHP version your host runs, file permissions on wp-config.php, whether XML-RPC is open when nothing needs it, and which security headers the server sends. Strict-Transport-Security (HSTS), Content-Security-Policy and X-Content-Type-Options tell browsers how to treat your pages, and they are often missing.
Finally we confirm backups exist and actually restore. If your site is already infected, this is the wrong service; you need WordPress malware removal first.
Who books a security review
Owners who want to know where they stand, or who have been asked to show it.
- Online shops, where a breach hits customers directly
- Firms answering a cyber insurance or supplier security questionnaire
- Sites built years ago by a developer who has since moved on
- Membership and booking sites holding customer accounts
- Charities and schools with many editors holding admin rights
- Owners planning a redesign who want to know what to keep
How the check-up runs
Agree the scope
We confirm which sites and hosting accounts are included, and ask for limited access wherever possible.
Inventory and version checks
Core, theme and plugin versions are listed and matched against known vulnerabilities, with abandoned or unused items marked.
Accounts and login review
Every user and role is checked, and we test two-factor authentication and login rate limiting.
Server and header tests
PHP version, file permissions, XML-RPC, directory listing and response headers are all examined.
Backup restore test
With your agreement, we restore the latest backup to a private staging copy to confirm it works.
Report and walk-through
You receive findings ranked by risk, each with its fix, and we talk them through with you on a call.
What the report gives you
- A risk-ranked list of findings with plain explanations
- Software versions with known vulnerabilities noted
- A list of who holds admin rights and who should not
- Current and recommended security headers
- PHP, file permission and XML-RPC findings
- The result of the backup restore test
- An optional quote to carry out the fixes
Hardening steps that come up most often
Every site differs, but certain fixes appear on nearly every report, and none of them needs a rebuild.
- Two-factor authentication for every editor and administrator
- Limiting login attempts and retiring the default admin username
- Disabling XML-RPC when no app relies on it
- Blocking PHP execution inside the uploads folder
- Setting DISALLOW_FILE_EDIT so code cannot be edited from the dashboard
- Adding HSTS once HTTPS works everywhere
- Publishing a security.txt file, which our security.txt generator can create
Frequently asked questions
How is a check-up different from malware removal?
A check-up is preventive: we look for weak points on a site that is working normally. Malware removal is for a site already infected. If we spot signs of infection during the check-up, we stop, tell you and quote for a clean.
Could the audit break my site?
Most checks only read information, and anything that writes data, such as the restore test, runs on a separate staging copy. We never run aggressive scans that could trip your host’s firewall without agreeing it first.
What access do you need?
A temporary WordPress admin account and limited hosting access where your host offers it. You can delete both once the report is delivered. We never ask for passwords to be sent by plain email.
Does this satisfy GDPR or my cyber insurer?
The report documents the technical measures on your site, which helps with both. It is not a legal or compliance sign-off, so take legal advice on what your insurer or regulator needs in your situation.
How often should a site be checked?
Once a year suits most business sites, plus after big changes such as a host move, a new plugin set or a redesign. Shops and membership sites may want a lighter quarterly check as well.
Related services
- Web Design Manchester: every web service we offer.
- WordPress Malware Removal: for sites already hacked.
- WordPress Maintenance: keeps findings fixed month after month.
- Backups and Restore: sorts out backups the audit finds lacking.
- SSL and HTTPS Fixes: certificate and header problems put right.
Want to know where your site stands before an attacker finds out? Request a security check-up quote, ring 0161 315 1151 or send the site address on WhatsApp to 07737 902425.
Ready to get started?
Tell us what you need and we'll come back with an honest, fixed-price quote — no obligation.