Frequently Asked Questions

Answers to common questions about our website audit and basic pentesting services.

Is this a full penetration test?

No. This is a basic website audit and light pentesting review focused on common issues, misconfigurations, and public exposure. It is not a full enterprise penetration test.

Do you need my login?

Usually no. Most basic audits are performed from the outside, like a public visitor would see your website. Authenticated testing is available as part of the Audit + Basic Pentest package upon request.

Will this break my website?

The audit uses non-destructive methods. We do not attempt destructive exploitation, denial-of-service testing, or anything that could disrupt your website.

What do I get?

You receive a plain-English report with risk-ranked findings and a raw data package containing the actual scan outputs from the tools used.

Can my developer fix the issues?

Yes. The report is designed so your developer, IT provider, or hosting company can understand and act on the findings.

Do you work on WordPress?

Yes. WordPress sites are a strong fit for this service. We check version exposure, plugin/theme risks, and common WordPress-specific issues.

Do you guarantee my site is secure?

No audit can guarantee that. The goal is to identify visible risks and give you practical next steps to improve your website's security posture.

What tools do you use?

We use professional-grade open-source tools such as Nuclei, nmap, SSLyze, testssl.sh, WPScan, WhatWeb, Katana, httpx, and others depending on your website platform and the package selected.

How long does it take?

Basic audits are delivered in 2–3 business days. Audit + Basic Pentest in 3–5 business days. Multi-site audits in 5–10 business days.

Is the raw data safe to share?

The raw data contains technical scan results. We recommend storing it securely and only sharing it with your developer or IT provider. The data is point-in-time and should not be considered a guarantee of security.

Get My Website Audit