Due Diligence Audits
for Digital Agencies

An independent security review of your delivered projects. Findings come to you. Your client relationship stays yours.

Request an audit
What the audit covers

There are good reasons
not to check your own homework

We audit your project from the ground up: DNS, hosting, application layer, and any backend integrations.

Solve it First

Security and auditing are all about tackling issues head on. Proactive security puts everyone ahead of the curve. Bigger clients often need third-party audits for compliance, acquisitions or just for peace of mind. By working with us, we'll find and fix the issues proactively.

Confidential by Design

All findings are reported directly to you under a signed NDA. You manage the customer relationship and remediation timeline.

Actionable Reporting

All findings are prioritized with time estimates. Written so you can hand to your developers or fix yourself.


Caught

Real problems, found on real sites
we monitored and audited.

Found

A manual audit of a recruitment company's website uncovered directory listing enabled on the WordPress uploads folder. Anyone who went to domainname.com/wp-content/uploads could browse and download every file inside it, no login required. Sitting there in plain sight: roughly four years of job applicants' CVs, complete with names, contact details, and work histories, quietly exposed the entire time and no-one at the company was aware it was happening.

Fixed

The client disabled directory listing immediately after being notified, and a follow-up check confirmed the CVs were no longer publicly reachable. To close the underlying cause rather than just the symptom, the recommended fix was to move the uploads folder outside the public web root entirely and redirect the site's Gravity Forms submissions to a non-public storage location. This prevented the same exposure from quietly reopening down the line.

Found

A weak admin password gave an attacker a way in. They used it to launch a DDoS attack, flooding the server with traffic in an attempt to take the site down entirely (a tactic more often aimed at large government and brand sites, here landing on a much smaller target). On top of the flood of traffic, they quietly added malicious code to fraudulently verify the site through Google Search Console, opening the door to further abuse of the site's search presence.

Fixed

Cloudflare's DDoS protection was already limiting some of the traffic, but we tightened the rules further and had the WAF block the attacker outright. We forced 2FA on every admin account so a guessed password alone could never get this far again, removed the malicious Search Console code, and swept the rest of the site for anything else they might have left behind. Confirmed clean just in time for Christmas dinner.

Found

Many SEO plugins generate an author-sitemap.xml file by default, sitting at yourdomain.com/author-sitemap.xml. WordPress itself already exposes a user's login via the author archive link, but the plugin's sitemap turns that into a clean, indexable list, no digging required. Instead of showing the friendly display name set on the account, it lists the actual login username. For a bot running automated login attempts, that's half the puzzle solved before it's even started. This issue has been seen everywhere from landing pages, to enterprise sites. It's a default behaviour sitting quietly on a huge share of WordPress sites running a popular SEO plugin, including ones that have never been touched by a developer who'd think to look for it.

Fixed

Every site under WebEnsure management gets this sitemap removed, unless there is a real need for it. In which case we fix the setup. The real login is removed from public view, so the author sitemap stops handing attackers a head start on guessing logins.

Found

A WooCommerce store built on a ready-made theme, previously migrated from Magento, kept corrupting its own product data — prices, images, and descriptions reset themselves every time a new product was added. Deactivating plugins and switching themes made no difference; the fault sat in the database itself, likely left over from the original migration.

Fixed

Rather than patch a database that couldn't be trusted, we rebuilt the store from a clean install, importing products fresh and carrying over WooCommerce, theme, and permalink settings carefully enough that search rankings didn't take a hit. The rebuild took longer than a repair would have, but it's the only way the site was going to hold up long-term.

Found

A small site kept reinfecting itself with spam links hidden inside its content which was invisible to logged-in users, appearing only at random for visitors, specifically to dodge both admins and malware scanners. Core files, plugins, and the WAF were all already up to date, which ruled out the obvious causes.

Fixed

We restored a clean backup, fully replaced core files, and ran a file-integrity scan against the official WordPress repository to catch anything hidden elsewhere. A custom detection plugin was added to catch and hide any reappearance immediately, and the WAF rules were tightened further. It never came back.

Found

A large company asked us to look into security issues across several aging WordPress sites. Beyond heavy bot traffic and spam, the sites were slow, hard to maintain, and running on a five-year-old theme with dependencies nobody could safely update without breaking the site.

Fixed

We audited each site, identified which outdated plugins and theme dependencies were actually blocking safe updates, and worked with the client's junior development team to bring their process up to a maintainable standard: code review, staging tests, and a clear decision-maker for anything risky. Recommended a cadence of frequent, smaller audits over the infrequent, high-risk approach that had let the problems build up in the first place.


Pricing

Request a Quote

Pricing is based on audit scope and complexity.

  • Signed NDA before any work begins
  • Quote returned within one working day
  • Audit delivered within an agreed timeframe
  • Findings report in English or Finnish
  • No contact with your client at any stage
  • No ongoing commitment

Get in touch with a brief description of the project and we'll come back with a clear number within one working day.



Why WebEnsure

Human where it matters.
Automated where it makes sense.

Automated tools are great at catching predictable issues, but not so great at judgement calls. We validate everything and act before it breaks anything.

Transparency

Each month our customers are well informed about what's been happening on their site. We tell you exactly what the bots have been up to, what we've been up to and what we recommend next.

Longevity

We get to know your site better over time. The longer we work together, the more effectively we protect and improve your site. Your site gets better with age.

AI tools, human judgement

We use AI extensively, but we validate everything. The market is being flooded with "cheap" automated-only solutions nobody checks. We're the human oversight layer that makes the output actually trustworthy.

Platform-agnostic

WordPress, Laravel, Drupal, Lovable.dev, HTML, or something we haven't heard of yet; we manage it. WebEnsure is built around your site, not around a platform we resell.

Problems don't reach you

We are all about proactive security. Issues are best caught and resolved before you even know they exist. Proactive, not reactive, is the only model that gives you peace of mind.

Fully-managed, invisibly

Security patches, CMS updates, backup verification, uptime monitoring, performance tracking. All the nerdy stuff. Handled for you. Your website just works.

Your website deserves someone obsessed with it.

Website management as it should be.