$1,000.00 inc GST
A one day block, from $1,000 inc GST. We go through your website, the server under it, its logs and everything sitting in front of it, then tell you in plain English where you stand and what to fix first.
What you get
- A situation report. A plain-language account of your current security state, with a red, amber or green rating and the reasoning behind it. Written so you can hand it to your board, your insurer or your own client.
- Every finding, in priority order, with why each one matters in business terms rather than jargon.
- Remediation steps for each finding. Specific enough for a competent developer to act on, or for us to quote against.
- An hour with us to walk through the report, in person in Brisbane or by video, including how to explain the findings to other people.
What we look at
Your website
- Versions of WordPress, PHP, plugins and themes, how updates are handled, and whether the site was left open during known attack windows.
- Signs that someone has already been in: hidden administrator accounts, concealed plugins, code injected into themes, updates quietly switched off, scheduled tasks nobody created.
- Who has access: user accounts, two-factor authentication, orphaned accounts, and agencies or contractors still holding keys.
- What is installed but unused: abandoned plugins and themes, file managers, database tools, duplicates, and expired licences that silently block security updates.
- Configuration: debug settings left on, files the public can read, site address and certificate settings, and whether your email is easy to forge (SPF, DKIM, DMARC).
- Backups: what takes them, how often, where they go, whether they are encrypted, and whether a restore has ever been tested.
- Security tooling: what you have, whether it is switched on, what it would actually catch, and who receives the alert.
Your server
- Hosting platform, and who actually owns the account.
- Patch state of the operating system and installed software.
- Remote access: what is exposed, key management, open ports and firewall rules.
- Cloud account review where the platform is AWS: users, keys, snapshots and backup settings.
- Whether your server can be reached directly, going around whatever sits in front of it.
Your logs
- Web, PHP, WordPress and login logs, as far back as they go.
- Evidence of attempted and successful intrusions, logins from unexpected places, file changes and outbound connections.
- Where logs are missing or too short to be useful, we say so. That is a finding in itself.
Your edge
- DNS, nameservers, the firewall or content network in front of the site, and whether your real server address is exposed in public records.
Where this fits
Patching, restricting administrator access, multi-factor authentication and tested backups are four of the Australian Government’s Essential Eight. This audit tells you where you actually stand on them, for your website and the server under it, rather than where you assume you stand.
How it works
One day block, from $1,000 inc GST. Larger or multi-site environments may need more than one block. We will tell you that before we start, not after.
Your report is confidential to you. We do not contact anyone else about it, and what you share with your own clients, insurer or board is your decision.

