Fix and VerifySecurity audit
What this package is
Complete is testing plus doing the fixing, rather than handing you a report and leaving you to find someone to act on it.
Every high and critical finding gets fixed, then re-tested afterwards to confirm it is genuinely closed rather than assumed closed. The three slowest pages get speed work at the same time, because speed hits revenue immediately and is usually fixable in the same pass.
Whatever is left for you to do comes as a short ordered list saying what is urgent and what can wait, rather than a long list you have to prioritise yourself.
See it working
High and critical are fixed. Medium findings are written up as recommendations.
Changing 10482 to 10481 in the address opens it. The system never checks whose order it is.
—
The menu is hidden, but typing the address directly works, and prices can be edited from there.
—
Renaming the extension let an executable file land in the image folder.
—
The number can be edited before paying. The server takes what it is given instead of recalculating.
—
The figures here are built for the demonstration and are not any client's data.
The authenticated testing and the external assessment are part of this package too
This package is not only the remediation. Both earlier packages are included in full, and every button works the same way.
| Path | What it is | Behind login | Found |
|---|---|---|---|
| / | Home | Public | 1 |
| /products | Product list | Public | 0 |
| /login | Sign in | Public | 1 |
| /account/orders | Customer order history | Behind login | 2 |
| /checkout | Payment path | Behind login | 1 |
| /account/upload | Slip upload | Behind login | 1 |
| /admin | Admin dashboard | Behind login | 1 |
7 pages tested · 4 of them behind a login · 7 findings in total
The four pages behind a login are the ones a basic scan never reaches, and three of the four worst findings are there.
A worked example for example-shop.test, built for the demonstration and not any client's data.
The scanner and the basic report are part of this package too
This package is not only the authenticated testing. The whole external assessment from the basic package is included.
The scanner is free and open to anyone. It works entirely from the outside and never touches the inside of your site. What this package adds is the full report in the second tab, ranked by severity with a fix for each finding and a summary written twice, once for people and once for engineers, instead of showing three findings and locking the rest.
Both pages are live on this site rather than mock-ups. You can use them from inside the frame.
Everything you get
This list is the entire scope of the package. Nothing is hidden in a contract.
- Everything in the authenticated test
- I fix every high and critical finding myself
- Retested after the fixes so you can see they actually closed
- The three slowest pages sped up
- Any code I write comes with English comments and a README your own developer can read
- A plain list of what is left for you to handle, and why I left it
- 60 days of follow-up on everything I touched
- Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
- A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
- Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
- Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
- Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.
Questions about this package
What if a fix breaks the site?
I back up before every change and work on a test copy where one exists. If something goes wrong after going live it can be rolled back within minutes, and changes are scheduled for your quietest window anyway. During the 30 days of cover after delivery, anything wrong with work I did is fixed at no charge.
Does everything found get fixed?
Every high and critical finding does. Medium and low come as a prioritised list. A few things genuinely cannot be fixed because they sit inside the platform you use or with an outside provider, and I say plainly where the wall is and what the ways around it are.
What does re-testing after fixing mean?
Running the same checks again once the work is done, and showing before and after side by side for each finding. Not simply reporting that it was fixed. This matters because fixes that look right but do not actually close the hole happen more often than people expect.
Why is speed work included?
Because while fixing security I am already inside that code and that server. Improving the three slowest pages is therefore cheap for me and quick to show up in your revenue. It is not in there to make the package look bigger.
Do I need to keep paying after the job?
No. The job ends with the doors closed and re-tested. A monthly care package exists if you want someone still watching, but it is not required, and the remaining items are written up as a list so your own team can work through them.