A full review of the files, the database, the configuration and the access history, turned into a report you can read in one sitting, hand to a client, and act on the same day.
Get a security auditOne-time, per site. The full sample report is below, free to read.
One sentence telling you where you stand, then the numbers behind it. Everything below is a real audit, published in full, with the site name and every identifying detail replaced.
Reading every PHP file on disk, vendor copies included
Reading options, scheduled tasks and stored code snippets
Checking every account against the permissions it actually holds
Requesting each public address and recording what answers
Matching installed versions against published advisories
Built to be read top to bottom by someone who is not a security engineer, and to survive being forwarded to one.
Severity counts, the inventory of what was reviewed, and what is still live today.
A dated reconstruction, and the two gaps that mattered more than the events.
The values to block, and to go searching for on the rest of your portfolio.
Each one a sentence, with where it is, what it costs you, and the action that closes it.
What answered when a stranger asked, as a checklist you can work through.
What came back clean, so you know how wide the review actually went.
Ordered by risk removed, not by severity. The first four are marked for today.
Which findings a setting you already have would have caught on its own.
What it costs to have the remediation done for you, and what is not promised.
Every finding is a full sentence describing the consequence, not a CVE number. These are real titles from the sample report.
No example at this severity.
Each finding carries its own Action line. The report cross-references them, so you can see when one weakness is what makes another one dangerous.
Every address below was requested from the public internet on the day of the report, and the server answered. Only the response status is recorded, and no file contents are kept.
Eleven addresses in the sample report, shown here with the site-specific parts masked. The report lists them in full, with a button that copies the lot.
Not ordered by severity label, and not a backlog. Every step says who carries it out, so nobody has to work that out on the call afterwards.
Delete the leaked configuration copy and rotate everything it exposed
YouThe database password, nine authentication keys and the mail API key. Rotation is the part that matters, not the deletion.
Close public access to the customer document folders
Your hostAt the web server, then serve them through a script that checks who is asking. Ask your host for the folder access logs at the same time.
Stop PHP executing in the media folder
Your hostOne server rule, and the single most valuable change on the list. This is the condition that made the backdoor work.
Identify the unknown admin session source and end every session
Your agencyEight sessions from an unidentified server, valid for another two weeks. Rotating the keys in step one ends them.
Update the plugins with published advisories, then the rest
One toggleRequire a second factor on every administrator account
YouDisable the built-in file editor and force HTTPS in the admin area
One toggleRemove the diagnostic console from the live site
YouTranslate the protective rules to the web server you actually run
Your hostReduce the administrator count and close the remote management channel
Your agencyClean the leftovers
YouAsk your host for the access logs covering the intrusion window
Your hostSteps tagged One toggle are already sitting in your WP Umbrella dashboard, and the report links straight to the page that switches them on.
No retainer, no subscription, no seat count. You can stop after the report, and plenty of people do.
20€ one-time, per site
The full review and the report described on this page, delivered as a single self-contained page you can keep, print or forward.
180€ one-time intervention
If you would rather not work through the list yourself, we carry out the remediation and hand you a before and after report.
What we need: SFTP or FTP access. Everything else is handled as part of the cleanup.
On the cleanup we commit to an obligation of means: every step is applied, but no one can guarantee against reinfection until the way in is closed.
No. Most of what an audit finds is exposure rather than intrusion: files reachable without logging in, protective rules that stopped working, credentials left behind by a plugin that was removed years ago. The sample report is a site that was compromised, but the same review on a healthy site tells you what a stranger can reach today.
That is what it is written for. Every finding is a full sentence describing the consequence, technical terms are explained inline, and the report prints cleanly. It is a document you can forward without rewriting it first.
No. A scanner tells you whether it recognises a file. An audit reconstructs what happened from your login records and scan history, verifies from the public internet what is actually reachable, reads the database for persistence, and states what it ruled out. In the sample, the scanner had already reported the backdoor six days earlier and nobody had read the alert.
Nothing you are obliged to buy. The report is complete on its own and the plan is written so you or your agency can work through it. If you would rather not, the managed cleanup is available separately.
Read it before you buy it
A real audit, published in full, with every identifying detail replaced and the findings, counts and reasoning left exactly as they were.