Press Enter to search or Esc to close

Website Security

A free vulnerability scan of your Joomla or WordPress site within 24 hours, a written audit when something looks wrong, and the cleanup done for you. Nothing is installed and nothing on your site changes until you ask.
Starting from
Free
Up to 24 hours
  • A score from 0 to 100 and every item that keeps your site from it, free, within 24 hours
  • Every file checked against the vendor's bytes when you want certainty, in 3 days
  • Nothing installed, nothing changed, no admin access handed over
  • A report you can hand to your host, your developer or your insurer
Website Security

External Vulnerability Scan

Which website should we scan?

A site that lives in a folder is given with the folder: example.com/shop.

Nothing is installed and nothing on your site changes: we read what any visitor can reach. Free for Fastw3b customers. You get a score from 0 to 100, every item that keeps your site from 100 with what to do about it, and how far behind your software and extensions are. It runs tonight; the report's in your account in the morning.

Pricing

Three ways in, from free to done for you

Every package starts from the same place: what your site shows the outside world. Pick the depth you need.
External Vulnerability Scan
Free
Up to 24 hours
A high score means nothing visible from outside, not a clean site.
Where we look From outside
Software What it shows
Stray files Probed by name
Blacklists
Core files
Added files
The .htaccess doors
The way in, named
What you receive A score out of 100
Admin or FTP access needed
When Up to 24 hours

For any Fastw3b customer, on your account. Run it on a site nobody has looked at from outside in a while.

Cleanup and Hardening
Custom quote
After the audit
Priced on what the report found, before any work starts.
Where we look Every file, fixed
Software Updated
Stray files Removed
Blacklists Delisted
Core files Replaced
Added files Removed
The .htaccess doors Closed
The way in, named Closed
What you receive A clean bill
Admin or FTP access needed
When Quoted

For a site the audit found compromised. The quote names the day it is approved by and the day the site is clean and verified.

Nobody pays before we've looked. The scan is free, we answer within 24 hours, and the audit is ordered only after you've read the scan.

Nothing to cancel, nothing renews. One payment, one report. Monitoring will be the only subscription we sell, and it stops with one click.

What $490 is instead of. A security subscription costs $229 to $549 a year and never shows you a file. The audit is one payment, and the report is yours to take anywhere.

Included

What you get, free and paid

The free scan finds what a break-in leaves in plain sight. The audit finds the rest, file by file, from a backup you link to.

Your software and how far behind it is: the CMS, its version, the release lag, and every extension the site reveals with its own currency. The audit reads the full list from the install itself.

Free scan Audit Cleanup

Files no install ships, blacklists, injected code and open doors, probed from outside by the scan and read from every file by the audit.

Free scan Audit Cleanup

A score from 0 to 100 with every item that keeps your site from 100, what to do about each and how critical it is, in your account.

Free scan Audit

Nothing executed and no access handed over. The scan reads what any visitor can reach; the audit extracts your backup in a quarantine directory no web server serves.

Free scan Audit

Every file diffed against the vendor's bytes at the installed version: the core and each third-party extension, not only what a plugin directory publishes.

Audit Cleanup

Modified core files and added files that no package ships, listed with their location and their modification date.

Audit Cleanup

The .htaccess layer checked against the vendor's copy, because that is where a break-in keeps its doors open.

Audit Cleanup

The way in, named: the probable entry vector, read from the pattern of what was planted and when.

Audit Cleanup

A written report you can hand to your host, your developer or your insurer, with the evidence for every line, and the cleanup quoted on it.

Audit

The core replaced from the vendor's package, every extension reinstalled from its vendor, nulled copies named and replaced or removed.

Cleanup

Custom code reviewed and the entry vector closed: the vulnerable component updated or removed, credentials rotated, the .htaccess layer restored.

Cleanup

A clean bill you can verify: the same diff we ran for the audit, run again on the cleaned site, attached to the ticket.

Cleanup
How it works

How it works, from the free scan to a clean site

Start with the free scan today. Order the audit when the score says something is wrong, or when you want the certainty before a migration, a sale or a handover.

Run the free scan

Press the button, sign in, type the address. The scan runs within 24 hours and the report lands in your account: the score, the items, and what to do about each.

Order the audit with a backup link

Pay $490 and paste a download link to a files-only backup of your site: an Akeeba files-only archive, a control-panel compress, or a Dropbox or WeTransfer link. No upload limits to fight, and no admin access to hand over.

Every file against the vendor

The archive lands in a directory nothing serves and nothing runs. We read the CMS, its version and every extension from the manifests. We obtain the vendor's package at your installed version and hash every file against it. Modified, added and missing files fall out of the diff; the .htaccess files get the same treatment.

Your report, then the cleanup if you want it

The report lands on your ticket within 3 days: the verdict, the file lists with evidence, the entry vector, and what we'd do about it. If a cleanup makes sense we quote it on the report; if a rebuild makes more sense we say so.

Requirements

Before you start

A site on Joomla, WordPress, or a PHP framework such as Laravel or Symfony, so there is a vendor package to diff against. Hand-written custom PHP is quoted after a first look.

For the audit, a files-only backup you can link to. Your host's backup tool or the file manager's compress makes one in under an hour. The database isn't needed.

Your host, name and roughly when the site was last updated. Everything else we read from the archive.

FAQ

Frequently Asked Questions

  • Won't a free scanner do?

    Partly, for one platform. A free command-line tool can verify WordPress core and directory-hosted plugins against published checksums. It can't verify premium or third-party extensions at your installed version, it doesn't exist for Joomla, it doesn't check the .htaccess layer, and it runs inside the site it's checking. The audit covers all of that and gives you a report.

  • Do you need access?

    No. The scan reads what any visitor can reach. The audit works from a backup you link to, in quarantine. Nothing of yours is executed and nothing on your live site is touched. Only the cleanup needs access, and only once you've approved the quote.

  • What if the site is clean?

    Then you get a report that says so, file by file, and a short list of the doors we'd close anyway. That answer is worth having before a migration, a sale or a new agency takes over.

  • Is the $490 credited?

    No. The audit is a product in its own right, and you can take the report anywhere. Cleanup and Hardening is quoted separately once we know what the site needs.

  • Why not delete the files?

    Because the files we found are the ones we recognised. On the last site we cleaned, the signature pass found 135 files and the vendor diff found 16 more doors it had missed. Replacing the core from the vendor is the only step that doesn't depend on recognising every trick, which is what the cleanup does.

  • My site isn't a CMS.

    We can still help, but there is no vendor package to diff it against, so it's a review, and we price it as one. Run the free scan first; we'll quote the review after a first look.

  • Can you keep watching?

    Soon. Security Monitoring is a separate subscription, $29/mo or $290/yr, that runs the outside scan on a schedule and alerts you on a change. It's offered to audited or cleaned sites; reply on your ticket and we'll tell you when it opens.

  • Do I tell my customers?

    The report tells you what was on the server and since when, which is what a breach-notification decision rests on. Whether you must notify anyone is a legal question for your jurisdiction; the report gives you the facts, not the legal advice.

Website Security: Inquiry

Choose Your Package

Deep Compromise Audit
$490
3 days
Cleanup and Hardening
Custom quote
After the audit
Not sure, help me decide
We'll see all fields and recommend the best option.

Your Business

Drop files here or click to browse

Max 10MB per file
The email your host or Google sent, if you have one

Requirements

Allowed: JPG, PNG, GIF, WebP, PDF, DOC, DOCX, TXT, ZIP, RAR (max 10MB per file)
  • Client Login

    Restore password
  • New Registration

Make sure @fastw3b.com email domain is white-listed in your email client to restore password, verify registration, get order confirmations, etc.