Website Security Audit: What Actually Gets Checked

Brass combination padlock sitting on a white laptop keyboard next to gold credit cards, illustrating a website security audit

By Nathan Duvall

Published

The Short Answer

A website security audit is a review of everything your site shows the outside world. Whether your certificate is valid, whether your software is current, what your site quietly tells strangers about itself, and whether someone has already gotten in. Most of what matters on a small business site can be checked from the outside in a few minutes.

Prices run from about $229 a year for a monitoring platform to $2,500 or more for a one-time manual review by a security firm. Cleanup after something goes wrong usually lands between $500 and $2,000, plus the weeks it can take to get a Google warning cleared.

After fourteen years of this, the part that still catches people off guard is how ordinary the findings are. Old plugins, and a site that volunteers more about itself than it should. That covers most of what we find.

What a Website Security Audit Actually Checks

This is the list we run, with what it means when something fails.

Your certificate is valid. An expired certificate puts a full-page browser warning in front of every visitor before they see anything else. Most visible problem on the list, and usually the quickest to fix.

HTTPS is enforced, not only available. Having a certificate and using it are two different things. If the plain http version of your site still loads, anything typed into a form can be read on the way to you.

Security headers are set. These are short instructions your server sends the browser about what is allowed on your pages. Most small business sites send none of them. In practice that means an attack that works somewhere else on the internet has an easier time working on you.

WordPress core is current. Every release fixes something the last one got wrong, and those fixes get published. Running an old version means running a list of known problems that anyone can look up.

Plugins and themes are current. This is the one that matters. Patchstack recorded 11,334 new WordPress vulnerabilities in 2025, a 42 percent increase over the year before, and 91 percent of them were in plugins rather than in WordPress itself. The weighted median time from a vulnerability being published to someone exploiting it is about five hours. We went deeper on why WordPress sites get targeted if you want the longer version.

Your version numbers are not broadcast. WordPress, plugins, and a lot of servers announce their exact version in the page source by default. That turns a general attack into a specific one, because now someone knows which known problems apply to you.

Usernames are not handed out. WordPress will list your author accounts through its own API unless that gets turned off. Half of a login is the username.

XML-RPC is off if you do not need it. Old WordPress feature that lets other software talk to your site. It also lets someone try hundreds of passwords in one request instead of one at a time. Most sites stopped needing it years ago.

Your uploads folder is not browsable. On some servers, visiting that directory returns a full file listing. Anything you uploaded and never linked to is sitting there.

No mixed content. A secure page pulling an image or a script over an insecure connection weakens the page and trips browser warnings.

Your domain is protected against email spoofing. SPF and DMARC records tell the world who is allowed to send email using your domain name. Without them, anyone can send an invoice that looks like it came from you. Not strictly a website problem, though it is the one that costs small businesses real money most often.

Your site is not already flagged. Google keeps a blocklist. If you are on it, your search listings get a warning attached and traffic drops off right away. Most owners find out from a customer.

What It Costs

Real prices, as of September 2026.

A monitoring platform is where most people start. Sucuri, the most recognized name here, runs $229 a year for its basic plan with a 30-hour cleanup response, $339 for a 12-hour response, and $549 for 6-hour with more frequent scanning. Those are subscriptions rather than audits. Software watches and cleans up. Nobody is walking through the site making judgment calls.

A one-time manual audit from a security firm starts around $2,500 and climbs from there, because you are paying for a person’s time. That is the right spend for an application handling payments or health records. For a brochure site it is usually more than the situation calls for.

The cost of skipping it is harder to predict, which is what makes it easy to put off. A malware cleanup runs $500 to $2,000. A blocklist removal takes days to weeks to clear after the site is already clean. And the one nobody budgets for is quieter than either. A contact form that stopped sending in March and got noticed in May. We broke down what ongoing care runs in how much website maintenance costs.

What We Do About It

We run this list during onboarding for every site that comes onto a Partnership Plan, then keep watching it after that. The plan starts at $175 a month and covers managed hosting, monthly maintenance with updates tested before they go live, security monitoring, daily backups, and support hours from the people who already know your site.

We are not a security firm and we do not sell penetration testing. That is outside our wheelhouse and we would rather say so than pretend otherwise. What we do is keep this list from drifting, which is where small businesses actually get hurt. The dramatic breaches make the news. What we see is almost always a plugin nobody updated. Our website maintenance services page walks through what that covers.

If you are not a client and you want to know where you stand, ask. We will run the list and send you what we find. No charge, no pressure.

Common Questions

How do I test if my website is secure?

Start with what is visible from outside. Load your site over plain http and see whether it redirects to https. View the page source and look for a generator tag naming your WordPress version. Visit your domain followed by /wp-json/wp/v2/users and see whether it returns a list of accounts. Check whether your uploads directory returns a file listing. Four checks, about five minutes, and they catch the most common problems.

Can I check website security myself?

Most of it, yes. The checks above need no special tools. Free scanners like Sucuri SiteCheck will tell you whether your site is already flagged or serving malware. What is harder to do on your own is judge how urgent a finding is, and that tends to be the part people want help with.

How can I check the security of a website that is not mine?

Everything described here reads only what a site already serves to the public, so looking is fine. Actively probing a site you do not own or have permission to test is a different thing and is not. If you are sizing up a vendor, asking them what they do about updates and backups will tell you more than a scan will.

How much does a website security audit cost?

Nothing, if you run the checks above yourself, and most of them take about five minutes. Paid options start around $229 a year for a monitoring platform like Sucuri and run to $2,500 or more for a one-time manual review by a security firm. The gap between those two numbers is almost entirely whether a person is involved rather than software. For a small business brochure site, the platform end is usually enough. For anything handling payments or patient records, pay for the person.

How often should a website be audited?

The full review is worth doing once a year, and any time you change hosts, change developers, or someone with admin access leaves. The pieces that drift, which is really core and plugin updates, need attention monthly at minimum. An annual audit on a site nobody maintains in between mostly produces an annual list of the same problems.

What is the difference between a security audit and a security plan?

An audit is a snapshot of where you stand today. A plan is someone being responsible for the site between snapshots. An audit on its own tells you what is wrong and leaves the fixing to you. For a site the business depends on, the ongoing arrangement is what prevents the problem, because prevention does not happen on demand.

Where to Start

Run the four checks in the first question up there. Five minutes, and they will tell you whether you have a small problem or a real one.

If you would rather we look, send us the URL. If the answer is that your site is fine, that is what we will tell you.

Ready to Start
Your Project?

CTA Blob
CTA Blob
CTA Blob
CTA Blob
CTA Blob