Home / Services / Security audit / Fix and Verify

Fix and VerifySecurity audit

$649Done in 15 business days30-day cover

What this package is

Complete is testing plus doing the fixing, rather than handing you a report and leaving you to find someone to act on it.

Every high and critical finding gets fixed, then re-tested afterwards to confirm it is genuinely closed rather than assumed closed. The three slowest pages get speed work at the same time, because speed hits revenue immediately and is usually fixable in the same pass.

Whatever is left for you to do comes as a short ordered list saying what is urgent and what can wait, rather than a long list you have to prioritise yourself.

See it working

Fixed, then re-tested, shown side by sideThis package does not end at the report. Every high and critical finding is fixed, then re-tested the same way it was found, to confirm it is genuinely closed rather than merely hidden.

High and critical are fixed. Medium findings are written up as recommendations.

One customer can open another customer's orderCritical
Before

Changing 10482 to 10481 in the address opens it. The system never checks whose order it is.

Awaiting re-test

A regular staff account can reach the admin dashboardCritical
Before

The menu is hidden, but typing the address directly works, and prices can be edited from there.

Awaiting re-test

The slip upload accepts any file at allHigh
Before

Renaming the extension let an executable file land in the image folder.

Awaiting re-test

The amount to pay is sent from the browserHigh
Before

The number can be edited before paying. The server takes what it is given instead of recalculating.

Awaiting re-test

The figures here are built for the demonstration and are not any client's data.

The authenticated testing and the external assessment are part of this package too

This package is not only the remediation. Both earlier packages are included in full, and every button works the same way.

Every page that matters, not just the front oneThe free scanner reads one address at a time, and only what is open to the public. The pages behind a login are where the customer data and the money actually live.
PathWhat it isBehind loginFound
/HomePublic1
/productsProduct listPublic0
/loginSign inPublic1
/account/ordersCustomer order historyBehind login2
/checkoutPayment pathBehind login1
/account/uploadSlip uploadBehind login1
/adminAdmin dashboardBehind login1

7 pages tested · 4 of them behind a login · 7 findings in total

The four pages behind a login are the ones a basic scan never reaches, and three of the four worst findings are there.

A worked example for example-shop.test, built for the demonstration and not any client's data.

The scanner and the basic report are part of this package too

This package is not only the authenticated testing. The whole external assessment from the basic package is included.

Open full screen in a new tab →

The scanner is free and open to anyone. It works entirely from the outside and never touches the inside of your site. What this package adds is the full report in the second tab, ranked by severity with a fix for each finding and a summary written twice, once for people and once for engineers, instead of showing three findings and locking the rest.

Both pages are live on this site rather than mock-ups. You can use them from inside the frame.

Everything you get

This list is the entire scope of the package. Nothing is hidden in a contract.

Not included in this package
  • Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
  • A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
  • Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
  • Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
  • Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.

What I need from you before starting

Every question needs an answer, because these are the settings your system is built from. None of them can be skipped. If one is not settled yet, put down what you know today and we adjust it when work starts.

How the work runs

1

Send me the link

The URL on its own is enough to start. For the authenticated test I also need a throwaway test account.

2

Permission and scope in writing

Before I touch anything I need written confirmation from you that the site is yours. You also get a short contract in English covering scope, the delivery date, and who owns what I produce.

3

I test it

My own tools do the first pass, then I go through by hand for the things tools do not catch. You never get raw scanner output handed to you as a report.

4

Report, walkthrough, then 60 days of questions

You get the PDF, and from the authenticated test up, a video where I talk through it. After handover you can keep asking me questions for 60 days.

Paying and getting started

Full price of this package$649
  • Paid in full at order The price is fixed and the scope is written out. No numbers appear later.
  • Work starts as soon as it lands No call to book and no quote to wait for.
  • 30 days of cover after delivery Anything wrong with my work is fixed at no charge.

Bank transfer or PromptPay. A receipt is issued every time, and a stamped work contract if you want one.

How to reach you

Questions about this package

What if a fix breaks the site?

I back up before every change and work on a test copy where one exists. If something goes wrong after going live it can be rolled back within minutes, and changes are scheduled for your quietest window anyway. During the 30 days of cover after delivery, anything wrong with work I did is fixed at no charge.

Does everything found get fixed?

Every high and critical finding does. Medium and low come as a prioritised list. A few things genuinely cannot be fixed because they sit inside the platform you use or with an outside provider, and I say plainly where the wall is and what the ways around it are.

What does re-testing after fixing mean?

Running the same checks again once the work is done, and showing before and after side by side for each finding. Not simply reporting that it was fixed. This matters because fixes that look right but do not actually close the hole happen more often than people expect.

Why is speed work included?

Because while fixing security I am already inside that code and that server. Improving the three slowest pages is therefore cheap for me and quick to show up in your revenue. It is not in there to make the package look bigger.

Do I need to keep paying after the job?

No. The job ends with the doors closed and re-tested. A monthly care package exists if you want someone still watching, but it is not required, and the remaining items are written up as a list so your own team can work through them.

Often booked together

← Back to all three packages