For any Fastw3b customer, on your account. Run it on a site nobody has looked at from outside in a while.
For a site the scan flagged, or one you need certainty about before a migration, a sale or a handover.
For a site the audit found compromised. The quote names the day it is approved by and the day the site is clean and verified.
Nobody pays before we've looked. The scan is free, we answer within 24 hours, and the audit is ordered only after you've read the scan.
Nothing to cancel, nothing renews. One payment, one report. Monitoring will be the only subscription we sell, and it stops with one click.
What $490 is instead of. A security subscription costs $229 to $549 a year and never shows you a file. The audit is one payment, and the report is yours to take anywhere.
Your software and how far behind it is: the CMS, its version, the release lag, and every extension the site reveals with its own currency. The audit reads the full list from the install itself.
Files no install ships, blacklists, injected code and open doors, probed from outside by the scan and read from every file by the audit.
A score from 0 to 100 with every item that keeps your site from 100, what to do about each and how critical it is, in your account.
Nothing executed and no access handed over. The scan reads what any visitor can reach; the audit extracts your backup in a quarantine directory no web server serves.
Every file diffed against the vendor's bytes at the installed version: the core and each third-party extension, not only what a plugin directory publishes.
Modified core files and added files that no package ships, listed with their location and their modification date.
The .htaccess layer checked against the vendor's copy, because that is where a break-in keeps its doors open.
The way in, named: the probable entry vector, read from the pattern of what was planted and when.
A written report you can hand to your host, your developer or your insurer, with the evidence for every line, and the cleanup quoted on it.
The core replaced from the vendor's package, every extension reinstalled from its vendor, nulled copies named and replaced or removed.
Custom code reviewed and the entry vector closed: the vulnerable component updated or removed, credentials rotated, the .htaccess layer restored.
A clean bill you can verify: the same diff we ran for the audit, run again on the cleaned site, attached to the ticket.
Press the button, sign in, type the address. The scan runs within 24 hours and the report lands in your account: the score, the items, and what to do about each.
Pay $490 and paste a download link to a files-only backup of your site: an Akeeba files-only archive, a control-panel compress, or a Dropbox or WeTransfer link. No upload limits to fight, and no admin access to hand over.
The archive lands in a directory nothing serves and nothing runs. We read the CMS, its version and every extension from the manifests. We obtain the vendor's package at your installed version and hash every file against it. Modified, added and missing files fall out of the diff; the .htaccess files get the same treatment.
The report lands on your ticket within 3 days: the verdict, the file lists with evidence, the entry vector, and what we'd do about it. If a cleanup makes sense we quote it on the report; if a rebuild makes more sense we say so.
A site on Joomla, WordPress, or a PHP framework such as Laravel or Symfony, so there is a vendor package to diff against. Hand-written custom PHP is quoted after a first look.
For the audit, a files-only backup you can link to. Your host's backup tool or the file manager's compress makes one in under an hour. The database isn't needed.
Your host, name and roughly when the site was last updated. Everything else we read from the archive.
Partly, for one platform. A free command-line tool can verify WordPress core and directory-hosted plugins against published checksums. It can't verify premium or third-party extensions at your installed version, it doesn't exist for Joomla, it doesn't check the .htaccess layer, and it runs inside the site it's checking. The audit covers all of that and gives you a report.
No. The scan reads what any visitor can reach. The audit works from a backup you link to, in quarantine. Nothing of yours is executed and nothing on your live site is touched. Only the cleanup needs access, and only once you've approved the quote.
Then you get a report that says so, file by file, and a short list of the doors we'd close anyway. That answer is worth having before a migration, a sale or a new agency takes over.
No. The audit is a product in its own right, and you can take the report anywhere. Cleanup and Hardening is quoted separately once we know what the site needs.
Because the files we found are the ones we recognised. On the last site we cleaned, the signature pass found 135 files and the vendor diff found 16 more doors it had missed. Replacing the core from the vendor is the only step that doesn't depend on recognising every trick, which is what the cleanup does.
We can still help, but there is no vendor package to diff it against, so it's a review, and we price it as one. Run the free scan first; we'll quote the review after a first look.
Soon. Security Monitoring is a separate subscription, $29/mo or $290/yr, that runs the outside scan on a schedule and alerts you on a change. It's offered to audited or cleaned sites; reply on your ticket and we'll tell you when it opens.
The report tells you what was on the server and since when, which is what a breach-notification decision rests on. Whether you must notify anyone is a legal question for your jurisdiction; the report gives you the facts, not the legal advice.