Two ways to start.
Fixed prices are indicative and exclude VAT. We prepare a precise quote after discussing scope — within 5–10 business days.
Findings with evidence and fixes.
You receive a security assessment with a clearly defined test scope, evidence for every finding, risks ranked by priority, remediation guidance and a re-test once the vulnerabilities have been fixed. Depending on the risk the system carries, we run an automated vulnerability scan, a manual web application security audit, a penetration test or a source code review. We run automated system audits with a tool developed in-house at WEB MASTERS. Depending on the size of the order it runs anywhere from 100 to more than 10,000 tests, so the check can be repeated regularly rather than once a year, because doing so is far more cost-effective. We maintain the tool ourselves, so we know what every test does, and we extend the test set from real findings in client projects. We test websites, web applications, APIs and infrastructure: authentication, user access rights, the OWASP Top 10 risks, business-logic bypasses, server and database configuration and — where the agreed scope covers it — the source code. We run the more aggressive tests in a test environment or in a window agreed in advance, and we do not run destructive tests without your permission. The final report is written so that developers and management can both follow it: for every finding we set out the impact, the risk level, the evidence and a concrete route to remediation.
- ✓ Manual OWASP Top 10 review
- ✓ Scanning with Burp Suite Pro and Acunetix
- ✓ Automated scanning with the WEB MASTERS tool (100–10,000 different tests)
- ✓ Configuration audit (server, DB, app)
- ✓ Source code review (Laravel, WordPress, custom)
- ✓ Penetration test — authorised and targeted
- ✓ A detailed report with priorities and fixes
- ✓ Re-verification after remediation