About the service
Know your weak spots before attackers do
We look at your website the way an attacker would — and then go further. Automated scans cover the known issues; a manual review covers logins, user roles, plugins, security headers and forms. You get a clear list of fixes, ranked by risk.
-
Scan
Known vulnerabilities, checked
-
Review
Settings and access by hand
-
Rating
Risks ranked by impact
-
Fix list
Clear steps in priority order
The idea
Security is a list of small, fixable things
Most security problems are not spectacular. They are an old plugin nobody uses, a former employee’s account that still works, a contact form without spam protection.
Each one is small and fixable. The hard part is finding them all — and that is what an audit is for.
Business value
Risk you can see and plan for
A security incident costs more than the cleanup: lost orders, lost data, lost trust and many hours of your team’s time. An audit turns a vague worry into a short, prioritised list — so you know what to fix first and can budget for it.
When an audit is needed
- Nobody has checked the site in years
- You took over a site built by someone else
- A shop or form handles customer data
- A client asks how you protect their data
What you will get
- A report written for decision-makers
- Findings ranked by risk and effort
- A concrete fix for every finding
- A re-check once the fixes are done
Benefits
Why a security audit with Scaleable
Our audits are done by people who build and maintain WordPress sites — so every finding comes with a fix that actually fits your setup.
-
Beyond the scanner
Automated tools find the known issues. Our manual review finds the ones that depend on how your site is set up.
-
Plain-language report
Each finding explains what it means for your business, not just which setting is wrong.
-
Fixes, not just findings
If you wish, the same team applies the fixes and checks again that each gap is really closed.
-
Realistic priorities
We separate urgent risks from nice-to-haves, so your budget goes where it reduces risk the most.
Principles
Audit Principles That Drive Results
-
Scope Before Scanning
We agree what is checked and how before we start, so the audit is safe for your live site and nothing important is left out.
-
Context Over Checklists
A missing setting matters more on a shop with customer accounts than on a simple company site. We rate every finding in context.
-
Verified, Not Assumed
A fix only counts once it has been tested. After the changes we check again and mark every item as closed or still open.
The audit isn’t the finish line
We don’t just list the gaps. We close them.
Audit and hardening work as one job: the team that finds the weak spots also fixes them. No second provider has to read the report and guess what was meant.
Part one
Audit
Automated scans and a manual review of your website, rated by risk.
- Plugins, themes and WordPress core checked for known vulnerabilities
- A review of logins, user roles and file permissions
- A prioritised report with a fix for each finding
Part two
Hardening
The findings turned into real changes on your site — tested first, then applied live.
- Updates and removal of unused plugins
- Two-factor login and tidy user roles
- Security headers set and the file editor disabled
Process
Our Audit Workflow
An audit is only useful if it leads to action. Our workflow starts with a clear scope, combines tools with manual checks and ends with a re-check — so you can see that the risks really went down.
-
Scope
Sites, shops, forms and access agreed before testing starts.
-
Automated Scan
Known vulnerabilities in core, themes and plugins detected.
-
Manual Review
Logins, roles, settings and forms checked by hand.
-
Risk Rating
Every finding rated by impact and how easy it is to exploit.
-
Report & Fixes
A plain-language report with a concrete fix for each finding.
-
Re-Check
Fixes verified and the remaining risks documented.
Collaboration
Findings you can act on together
We walk you through the report in a call, answer your team’s questions and agree which fixes come first. Sensitive details stay in the report and go only to the people you name.
- Report walked through on a call
- Fix order agreed together
- Details only for named people