Home / Services / Website security audit
Service · 06 / 12

Website security audit.

We run a comprehensive security audit of your web applications — from automated scanning to manual penetration testing. You receive a detailed report of the weaknesses found and a step-by-step remediation plan.

Starting at
€89
Timeline
1–60 days
Tech
8 tools
Pricing options

Two ways to start.

01
Manual expert audit
In-depth review by a human
starting at €3 500
Manual OWASP Top 10 review
Access-control and business-logic bypass testing
Source code review (Laravel, WordPress, custom)
Authorised penetration test
Findings ranked by real risk, with a fix for each
Re-test within 30 days after the fixes
Request this service →
02 MOST CHOSEN
Automated audit
For WordPress, Laravel, Drupal, Joomla and Moodle
€89–890 depending on scope
Automated vulnerability scanning
Version, plugin and dependency checks
Configuration and server settings review
Audit report with findings and priorities
Fast turnaround — days, not weeks
Request this service →

Fixed prices are indicative and exclude VAT. We prepare a precise quote after discussing scope — within 5–10 business days.

Included

Findings with evidence and fixes.

You receive a security assessment with a clearly defined test scope, evidence for every finding, risks ranked by priority, remediation guidance and a re-test once the vulnerabilities have been fixed. Depending on the risk the system carries, we run an automated vulnerability scan, a manual web application security audit, a penetration test or a source code review. We run automated system audits with a tool developed in-house at WEB MASTERS. Depending on the size of the order it runs anywhere from 100 to more than 10,000 tests, so the check can be repeated regularly rather than once a year, because doing so is far more cost-effective. We maintain the tool ourselves, so we know what every test does, and we extend the test set from real findings in client projects. We test websites, web applications, APIs and infrastructure: authentication, user access rights, the OWASP Top 10 risks, business-logic bypasses, server and database configuration and — where the agreed scope covers it — the source code. We run the more aggressive tests in a test environment or in a window agreed in advance, and we do not run destructive tests without your permission. The final report is written so that developers and management can both follow it: for every finding we set out the impact, the risk level, the evidence and a concrete route to remediation.

Technologies used
WEB MASTERS Scanner Burp Suite Professional ZAP Acunetix Nmap OWASP Top 10 CVSS SAST / SCA
  • Manual OWASP Top 10 review
  • Scanning with Burp Suite Pro and Acunetix
  • Automated scanning with the WEB MASTERS tool (100–10,000 different tests)
  • Configuration audit (server, DB, app)
  • Source code review (Laravel, WordPress, custom)
  • Penetration test — authorised and targeted
  • A detailed report with priorities and fixes
  • Re-verification after remediation
Process

How it works.

01
Scope
We define what is audited: web app, API, infrastructure.
02
Audit
Manual plus automated analysis. We don't stop at the first finding.
03
Report
Clear, actionable, with a prioritised list.
04
Verification
Within 30 days of the fixes — we check again.
FAQ

Frequently asked.

In most cases the automated audit with our own tool. It is very fast and covers a very wide scope: from 100 tests to more than 10,000, depending on the size of the order. That means it can be repeated regularly rather than once a year.
It is built and maintained by us, so we know what every test does and can tune it for a specific environment — WordPress, Laravel, Drupal, Joomla or Moodle. We expand the test set from real findings in client projects rather than waiting for a vendor update.
When the system handles payments or personal data, or is business-critical. Automation doesn't find access-control errors and business-logic bypasses — only a person who understands what the system does will. In practice a combination works well: regular automated audits plus a manual one once a year.
The automated audit is usually ready in days rather than weeks, and ends with an audit report of findings and priorities. A manual audit takes 1–3 weeks depending on scope.
We plan the tests with you. Aggressive checks run in a test environment or an agreed window. In production we work carefully and with advance notice.
We can. Many clients fix things with their own team and we verify afterwards. If you prefer, we do the fixing — that is separate work, estimated from the report.