Website security

An outage shouts. A break-in keeps quiet.

A compromised website works normally. It looks the same, it responds the same, and only weeks later does it turn out that some visitors were being sent elsewhere. So we watch not only whether the site responds, but also what changes on it.

Script and redirect checks are included from the Start plan.

Scripts

A new script from a server that is not yours.

We record which servers your website loads scripts from. When a new one shows up, we check how many pages it appeared on at once. A script that lands on half the site immediately is usually not someone pasting a tag by hand, but a replaced template or plugin.

The first reading is the reference point, and addresses you know and accept are silenced once for the whole site.

Scripts the website loadsinventory of external servers, 12 pages State before the release
  • yourcompany.com known, silenced 12 of 12 pages
  • fonts.googleapis.com known, silenced 12 of 12 pages
  • www.googletagmanager.com known, silenced 12 of 12 pages
No change in the inventory

Every server is known from earlier checks. The first time we meet an address we record it as the reference point and wake nobody up.

Simulated. Click to see both states.

Where the visitor actually ends up.

We check server redirects, tags in the page code and commands in scripts. A jump to a foreign domain, a redirect chain and a loop are three separate findings.

Key addresses are watched separately, every 15 minutes.

Accounts with full permissions.

The plugin reports how many administrator accounts exist and whether the set of them has changed. A new account or a swapped one opens an event.

We do not transmit logins, so we know the set has changed without knowing who is in it.

Hygiene and overdue updates.

We check the settings that most often open the way in.

The version history answers the question of what changed just before the failure.

  • file editing from the panel
  • open registration
  • error messages on display
  • permissions on configuration files
  • PHP version
  • overdue updates

The limits, said plainly.

We do not scan for malware and we do not make backups. We do not verify checksums of system files. Detecting a change is not the same as undoing the effects of a break-in.

Our part ends with you finding out about the change the same day, rather than a month later, from a customer or from a search engine.

Check your website.
Free, in two minutes.

The free technical review covers availability, the certificate, the domain, email, content and forms. It ends with a score and a list of tasks you can hand to your developer. No payment card and no commitment.