Website surface
A five-page brochure site, an ecommerce store, and a SaaS product expose different page types, forms, scripts, cookies, account surfaces, and third-party services. More distinct components require more evidence and review time.
The price of a website security audit depends on the surface reviewed, the evidence required, and whether the work stays public or includes owner-authorized access. A useful audit does more than produce a scanner score: it explains what was observed, why it matters, and what to fix first.
Price should follow the real scope, not a vague promise to “check everything.” Three factors usually make the largest difference.
A five-page brochure site, an ecommerce store, and a SaaS product expose different page types, forms, scripts, cookies, account surfaces, and third-party services. More distinct components require more evidence and review time.
A quick automated list costs less than a report that verifies findings, records affected URLs, explains business impact, removes false positives, and gives developers a prioritized remediation plan.
Public checks can be performed without logging in. Testing roles, sessions, rate limits, MFA, or protected workflows requires written authorization, test accounts, agreed timing, and a separate safety plan.
Start with the smallest scope that answers the business question. Move to deeper testing only when there is a clear need and written permission.
| Scope | Price | What it is for | What the buyer receives |
|---|---|---|---|
| Free public preview | Free | Early view of obvious HTTPS, browser-security, trust, and public exposure signals. | A short first-pass summary intended to show whether deeper review is justified. |
| Public Website Security Audit | $790 | Businesses that need a deeper public-safe review without admin access or destructive testing. | Security-focused PDF, evidence, affected URLs or components, risk priorities, remediation guidance, and one agreed retest. |
| Owner-approved authenticated scope | Quoted | Role behavior, sessions, MFA, rate limiting, protected forms, or other authenticated workflows. | A written scope, rules of engagement, approved test accounts, evidence boundaries, findings, and retest plan. |
| Security Watch | From $99/month | Recurring public monitoring after the initial baseline and priority fixes. | Monthly public checks for selected pages and signals, change summary, and escalation of new visible risks. |
The standard service is intentionally public-safe. It documents browser-facing posture while staying outside private systems and customer data.
HTTPS behavior, certificate signals, HTTP redirects, HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, frame protections, and mixed-content risk.
Visible admin routes, source-map and backup-looking URLs, public technical files, indexing exposure, technology disclosure, and other externally observable signals. We do not retrieve suspected secret-bearing content.
Lead-form data minimization, privacy expectations, cookie flags, browser storage, external scripts, trust messaging, and whether critical third-party dependencies are understandable to the owner.
A long scanner export is not the same as an audit. Decision-ready reporting separates confirmed findings from risk signals and owner-only checks.
| Report field | Why it matters |
|---|---|
| Evidence | Shows the header, URL, response behavior, browser condition, or visible page signal behind the finding. |
| Status | Distinguishes confirmed issues, observable risk signals, and checks that require owner access. |
| Business impact | Explains how the issue may affect visitor trust, lead handling, operational continuity, advertising confidence, or exposure. |
| Recommended fix | Gives the owner and developer a practical next step instead of a generic warning. |
| Priority and retest | Separates urgent work from planned improvements and records whether the change was verified. |
Clear boundaries protect both the client and the auditor.
The provider should describe whether work is public, authenticated, or a formal penetration test. Password guessing, access bypass, exploitation, and destructive scanning should never be implied inside a basic public review.
Automated tools can identify symptoms without understanding business context. Important findings should be checked by a person before they reach the final report.
The report should identify who needs to act, what evidence to verify, how to reduce the risk, and what should be retested after implementation.
These answers define the commercial and safety boundaries before an order is placed.
A public preview can be free. Our evidence-led Public Website Security Audit is $790. Authenticated or penetration-testing work is separately scoped and quoted.
No. The $790 service is a public-safe audit. It does not guess passwords, bypass access controls, exploit systems, or perform destructive scans.
Evidence, affected URL or component, status, business impact, recommended fix, priority, and retest status for every meaningful finding.
Use these pages to compare scope, understand browser protections, and see how evidence is turned into a fix plan.
Use the free preview for an initial signal check. Choose the paid audit when you need evidence, prioritized remediation, and one agreed retest.