Example document. The website and the findings below are illustrative and do not describe a real customer.

Sample report

Sample Website Security Check report

This is the format a fixed-scope Website Security Check produces. Findings are grouped by severity, each one is written in plain language, and every recommendation says what to do about it.

Back to the Website Security Check

Plan represented

None required. The Website Security Check is a separate fixed-scope engagement at $299, bought once for one website. It is not part of any monthly plan, and no maintenance plan is needed to order it. A real report names the website it covers.

Reporting period

A point-in-time review carried out across three business days in a sample month. A check is a snapshot, not continuous coverage: every finding describes the website as it stood on the review dates.

Example website

www.example-sample-site.com - a fictional public-facing business website on a standard CMS, reviewed within the authorized scope. No real customer website is described here.

Checks performed

What the fixed-scope review covered: the public website plus the account-level basics the owner authorized. Nothing was modified, and nothing was exploited.

  • Software currency: CMS core, theme, and plugin versions against published releases.
  • Access control: administrator login exposure, rate limiting, and two-factor availability.
  • Transport security: HTTPS enforcement, certificate validity, and mixed-content assets.
  • Hygiene: security response headers, version disclosure, form abuse protection, and unused plugins.

Issues detected

Eight findings in this sample: one high, three medium, four low or informational. Severity describes exposure, not proof that anything has been compromised.

  • High - Software updates: the CMS core is three minor versions behind and a published fix is available.
  • Medium - Access control, transport, and backups: the admin login has no rate limiting or two-factor, one page loads a mixed-content asset over plain HTTP, and no verified off-site backup schedule was detected.
  • Low - Hygiene: security response headers are unset, the software version is disclosed in the page source, the contact form has no abuse protection, and two inactive plugins remain installed.

Updates performed

None, by design. A security check is a review, not remediation: no update, configuration change, or file modification is made to your website during the check. Every fix listed under recommendations is quoted and approved before any work begins.

Technical work performed

None on the live website. The work in this engagement is analysis and reporting: reviewing the publicly reachable surfaces, confirming each finding by hand so nothing is reported on the strength of an automated scan alone, and writing it up in language you can act on or hand to whoever maintains the site.

Included versus separately purchased

The check has a fixed price and a fixed scope. Fixing what it finds is separate work, quoted after you have the report and have decided what you want done.

Included in the $299 check

  • Review of the publicly reachable website across software currency, access control, transport security, and hygiene.
  • Findings graded by severity, each confirmed by hand rather than reported straight out of a scanner.
  • This written report in plain language, with a prioritized list of recommended next steps.
  • One follow-up conversation to walk through the findings and answer questions.

Purchased separately, never assumed

  • Applying the fixes: updates, hardening, and configuration changes are quoted after the report.
  • Ongoing monitoring and monthly updates, which are what a Website Care plan covers.
  • Penetration testing, code audits, compliance certification, and incident response for an already-compromised website.

Recommended next steps

In priority order. Each one says what to do, not merely what is wrong.

  • Apply the pending CMS core and plugin updates on a staging copy, verify them there, then publish.
  • Add login rate limiting and two-factor authentication for every administrator account.
  • Force HTTPS site-wide and replace the remaining mixed-content asset.
  • Establish a daily, verified, off-site backup and run a restore test against it.
  • Set baseline security response headers and remove the two inactive plugins.

Unresolved risks

What remains open at the end of the check. A check that closed nothing still tells you exactly where you stand.

  • Every finding above is unresolved. The check fixes nothing, so the website's exposure is unchanged until the recommendations are carried out.
  • Database contents, application source code, and anything beyond the authorized review scope was neither reviewed nor cleared.

Limitations of this report

This is a point-in-time review of a public-facing website. It is not a penetration test, not destructive testing, not a compliance certification or audit, not incident response, and not a guarantee that a website can never be compromised. Findings describe what was observable on the review dates, and anything not observable is reported as unknown rather than assumed safe.