Website Security Audit Salford
A website security audit gives you a clear written picture of where your site is exposed and what to fix first. We audit WordPress sites for Salford start-ups, media and digital firms, retailers and hospitality businesses, often before a launch, a client handover or a supplier questionnaire.
- Since 2003trading in Manchester
- 20,000+UK businesses helped
- Collect M8Unit 3, 116 Bury New Road
- A personchecks every file
Security and care
Every job is a fixed quote, agreed in writing before any work starts. No obligation.
- WordPress Malware RemovalWEB 101Quote
- Website Security Check-upWEB 102Quote
- WordPress MaintenanceWEB 103Quote
- Backups and RestoreWEB 104Quote
- SSL and HTTPS FixesWEB 105Quote
Security questions Salford businesses get asked
Start-ups coming out of the University of Salford are often asked about security sooner than they expect: by an investor’s adviser, a large customer’s supplier form or a cyber insurance application. “Who can log in to your website?” is hard to answer honestly when the site was assembled in a rush.
Digital and media firms around MediaCityUK have another reason. When an agency hands a finished site to a client, the client inherits whatever was left behind: test accounts, debug settings, forgotten staging copies. An independent check before handover protects both sides. Retailers near Salford Shopping Centre in Pendleton face a third risk, because checkout pages are a favourite target for injected card-skimming scripts, even when payments go through a provider.
An audit is a check and a report, not a clean-up. If your site is already hacked, you need malware removal for Salford instead, and penetration testing happens only when agreed in writing. The full method is on our website security audit Manchester page.
How we carry out the check from just over the river
The audit itself is remote, using a temporary admin account and read-only hosting access where your host offers it, arranged by phone, email or WhatsApp. Nothing heavy runs against the live site without your agreement, and you can switch our access off the day the report lands.
Some Salford clients prefer the results in person. Our Cheetham Hill office is roughly 10 to 20 minutes by road depending on where you are and the traffic, so you can come to M8, or we can visit your office by arrangement.
Our audit sequence
Set the boundaries
We agree which domains, subdomains and environments are in scope, and record your consent for each test.
Map what is public
We look for staging copies, old subdomains and files that should never be reachable from a browser.
Match versions to known flaws
Core, theme and plugin versions are compared with public vulnerability records, and nulled or abandoned code is flagged.
Review accounts and keys
We check users, roles, two-factor login, application passwords and any API keys stored in theme or plugin settings.
Inspect server and headers
PHP version, permissions, XML-RPC, TLS configuration and headers such as HSTS and Content-Security-Policy are tested.
Deliver the ranked report
You receive findings ordered by risk, each with a fix, and a call to talk them through.
Deliverables at the end
- A risk-ranked written report that non-technical readers can follow
- A one-page summary suitable for an investor, insurer or client
- Exposed files, staging sites and subdomains we found, with fixes
- Vulnerable or abandoned plugins and themes, with replacements suggested
- An account list showing who holds admin rights and why
- Server, TLS and security header findings
- An optional fixed quote to put everything right
Leftovers we look for before a site launches or changes hands
On new or newly handed-over sites, most findings are things left behind during the build:
- WP_DEBUG and WP_DEBUG_DISPLAY switched on, printing file paths and errors to visitors
- A staging copy on a subdomain, public and indexed, running older plugins than the live site
- Backup archives or a wp-config.php.bak file sitting in the public web root
- An exposed .git folder or .env file revealing code history or credentials
- Test administrator accounts with simple passwords that nobody removed
- Usernames listed openly through the REST API at /wp-json/wp/v2/users
- Payment or email API keys hard-coded into theme files
Certificate and redirect problems are put right through our SSL and HTTPS set-up, and WordPress maintenance in Salford keeps fixes in place once the audit is done.
Frequently asked questions
We are an agency at MediaCityUK. Can you audit a client site before we hand it over?
Yes. An outside check is a sensible last step before handover, so nothing from the build stays behind. We can report to you, the client or both, and keep findings confidential until you decide how to share them.
You are close to Salford. Can we meet to go through the report together?
Yes. Our M8 office is a short drive from most of Salford, or we can come to your premises by arrangement. Some teams prefer a video call so remote developers can join.
An investor asked about our website security. Can we share the report?
Yes, and the one-page summary is written with that in mind. It records what we checked and what we found on the date of the audit. It is not a certification or a legal sign-off, so take advice on anything an investor or insurer formally requires.
Is this the same as a penetration test?
No. An audit reviews configuration, software and access without trying to break in. A penetration test actively attempts attacks and needs separate written permission, including from your host. If your situation calls for one, we discuss it with you first.
Do you fix the problems as well?
If you want us to. Every finding has enough detail for your own developer to act on, or we can quote to do the work ourselves and then recheck each item.
Audits for Eccles, Prestwich and Stretford businesses
The same service is available nearby through website security audit Eccles, Prestwich and Stretford. Read the Manchester audit page for more detail, or see our services in Salford for everything else we do locally.
Planning a launch, a handover or an insurance renewal? Request an audit quote, speak to us on 0161 315 1151 or WhatsApp the site address to 07737 902425.
Website security audit across Greater Manchester and nearby
The same service, for businesses in other towns we work with from our Manchester office.
- Website security audit Manchester
- Website security audit Altrincham
- Website security audit Ashton-under-Lyne
- Website security audit Bolton
- Website security audit Bury
- Website security audit Chorlton
- Website security audit Droylsden
- Website security audit Eccles
- Website security audit Heywood
- Website security audit Hyde
- Website security audit Leigh
- Website security audit Middleton
- Website security audit Oldham
- Website security audit Prestwich
- Website security audit Rochdale
- Website security audit Sale
- Website security audit Stockport
- Website security audit Stretford
Ready to get started?
Tell us what you need and we'll come back with an honest, fixed-price quote — no obligation.