We have been developing PHP websites and web applications for businesses like yours since 2010. All our developers trained in secure coding and follow OWASP best practices.
Our website security check specialists are trained in both offensive ethical hacking and defensive hacking protection. We actively engage in an industry leading security program to stay up to date with the latest exploits.
Our in house development team is on hand to react to new security incidents, from both existing and new clients, as well as proactively scanning, analysing and protecting over 100 websites in our care.
great starting point to assess the security of your website
What's included?
Introductory Security Overview on your Website
System Overview
Server Overview
Software Version Review
Code Review
Security Assessment (Based on OWASP Top 10)
our most popular service where we thoroughly test your website's security to provide a comprehensive report
What's included?
Everything from our Security Review service
Automated Vulnerability Testing (Un-authenticated)
Manual Code Inspection for OWASP Top 10 Vulnerabilities
Detailed Vulnerability Report with Remediation Advice
evaluate your website's security with our pen test service
What's included?
Everything from our Vulnerability Assessment package
Introductory Scoping Meeting
Tailored Penetration Test (Authenticated and / or Un-Authenticated)
Detailed Assessment with Technical Report and Recommended Fixes
Post-Engagement Debrief
Hiscox Group Report 2018
Sitelock Annual Report 2022
U.S National Cyber Security Alliance
Why have website security checks done? Attackers frequently target websites to cause business disruption, as well as looking to access your business and your customers' sensitive data.
Bad actors are able to break into websites using a wide range of exploits and vulnerabilities, including MySQL Injection, Cross Site Scripting (XSS) attacks, Broken Access Control, Security Misconfiguration and Cryptographic Failure.
Your website is your company's global front door. By performing website security checks in the form of an audit, you will discover any security flaws before anyone else does.
Having a security audit carried out by a specialist team means you'll have expert support, tailored advice and can ensure operational safety.
Here are just a few reasons why you should prioritise security today.
Ensure your website's reliability and performance
Minimise disruption from website defacement or DDoS attacks
Protects your customers, staff and business
Secures sensitive and personal user information (PII)
Prevents unauthorised access
Fosters a culture of cyber security
Raises awareness of potential risks
Stops data breaches
Maintains trust
Upholds your company's reputation
Identify and fix vulnerabilities
Shields your company from cyber threats
Our vulnerability assessments are conducted by looking at the public facing parts of your website, along with your website's code and looking for vulnerabilities based on the technology your website is using, the way your code is written and common exploits for any software you are running.
Performing a web penetration test is a lot more in depth. We will work with you to define the scope (what websites and areas to test), then we will conduct a vulnerability assessment on those areas. From there, we will actively try to exploit any vulnerabilities we find to 'hack into' your site and either access areas or perform actions we shouldn't be able to.
Un-authenticated penetration tests (also known as black box testing) simulates an attack by an individual who has no valid user credentials and demonstrates what damage can be done from your public facing pages. This type of testing is useful to identify any vulnerabilities on pages such as your registration or login page, which is accessible to anyone on the web.
Authenticated penetration tests (also known as white box testing) simulates an attack by an individual who has already breached your external defenses or who has obtained user credentials, either by phishing or brute force 'guessing'. This type of testing is useful to identify what damage can be done from the inside; often more catastrophic as functionality could be less protected if successful authentication is assumed. We also test the possibilities of privilege escalation, where an attacker logs in as a low level user and is able to 'upgrade' their account status to a higher level admin to perform more functions.
All our security tests start with looking for the Open Web Application Security Project (OWASP) Top 10 vulnerabilities.
These are considered best practice and includes vulnerabilities such as broken authentication, security misconfigurations, code injections, cross site scripting (XSS) and cryptographic failures.
Further vulnerabilities and exploits are then discovered by our security developers based on their experience and discovery of the system as they perform the tests.
The Open Web Application Security Project, or OWASP, is an international non-profit organisation dedicated to making web application security better through education and collaboration.
Part of its core values is to be open and global, making all their materials available to everyone so anyone can improve their website's security.
The OWASP Top 10 reports on the 10 most critical security risks. It is a regularly updated report put together by a team of security experts, designed to raise awareness.
It is best practice in the security industry for these risks to be mitigated and protected against as a minimum on your website.
When you are ready to book one of our services, we will book a scoping call with you where we will go through some basic information about your company, your website and what you're looking to achieve.
We need to know things like how big your website is, what functionality it has, whether there's a user or admin area, does it have a database and how much third party software does it use?
Don't worry if you are not sure of anything - often we can find the information out by you showing us round the site on a screen share or letting us have a look at the code.
We have an NDA document available for us both to sign before the scoping call, to make sure your business is protected.
Our testing process happens over 5 key stages: