Website Security & Performance
for Shopify

Every app you install is another party with access to your store. We audit what's actually running, keep checkout fast, and tell you what's safe to keep.

See pricing
Built for Shopify stores

Every app is a door.
We check who's behind it.

Shopify handles the hosting. It doesn't audit the apps you installed two years ago and forgot about, or the theme code nobody's touched since launch.

Shopify App Audit

Every installed app reviewed: active, abandoned, vulnerable, or quietly slowing down your store. Redundant tracking pixels and scripts included.

Speed, SEO & GEO Audits

We run technical audits on load speed, SEO health, and GEO readiness: the Core Web Vitals, crawlability, and structured data checks Shopify's own tools don't run for you.

Monthly Development

Your monthly audit report tracks the important KPI's for your store including traffic, orders, threats stopped, load times and tracking over 12-months of data. You can watch how your store develops. We write out what it means and what's worth doing next, in plain language.

Backup & Restore, Done Right

Shopify backup and restore is trickier to get right than it looks. We work directly with the Shopify API to get your data out, backed up, and restored properly when you need it.


Caught

Real problems, found on real sites
we monitored and audited.

Found

A manual audit of a recruitment company's website uncovered directory listing enabled on the WordPress uploads folder. Anyone who went to domainname.com/wp-content/uploads could browse and download every file inside it, no login required. Sitting there in plain sight: roughly four years of job applicants' CVs, complete with names, contact details, and work histories, quietly exposed the entire time and no-one at the company was aware it was happening.

Fixed

The client disabled directory listing immediately after being notified, and a follow-up check confirmed the CVs were no longer publicly reachable. To close the underlying cause rather than just the symptom, the recommended fix was to move the uploads folder outside the public web root entirely and redirect the site's Gravity Forms submissions to a non-public storage location. This prevented the same exposure from quietly reopening down the line.

Found

A weak admin password gave an attacker a way in. They used it to launch a DDoS attack, flooding the server with traffic in an attempt to take the site down entirely (a tactic more often aimed at large government and brand sites, here landing on a much smaller target). On top of the flood of traffic, they quietly added malicious code to fraudulently verify the site through Google Search Console, opening the door to further abuse of the site's search presence.

Fixed

Cloudflare's DDoS protection was already limiting some of the traffic, but we tightened the rules further and had the WAF block the attacker outright. We forced 2FA on every admin account so a guessed password alone could never get this far again, removed the malicious Search Console code, and swept the rest of the site for anything else they might have left behind. Confirmed clean just in time for Christmas dinner.

Found

Many SEO plugins generate an author-sitemap.xml file by default, sitting at yourdomain.com/author-sitemap.xml. WordPress itself already exposes a user's login via the author archive link, but the plugin's sitemap turns that into a clean, indexable list, no digging required. Instead of showing the friendly display name set on the account, it lists the actual login username. For a bot running automated login attempts, that's half the puzzle solved before it's even started. This issue has been seen everywhere from landing pages, to enterprise sites. It's a default behaviour sitting quietly on a huge share of WordPress sites running a popular SEO plugin, including ones that have never been touched by a developer who'd think to look for it.

Fixed

Every site under WebEnsure management gets this sitemap removed, unless there is a real need for it. In which case we fix the setup. The real login is removed from public view, so the author sitemap stops handing attackers a head start on guessing logins.

Found

A WooCommerce store built on a ready-made theme, previously migrated from Magento, kept corrupting its own product data — prices, images, and descriptions reset themselves every time a new product was added. Deactivating plugins and switching themes made no difference; the fault sat in the database itself, likely left over from the original migration.

Fixed

Rather than patch a database that couldn't be trusted, we rebuilt the store from a clean install, importing products fresh and carrying over WooCommerce, theme, and permalink settings carefully enough that search rankings didn't take a hit. The rebuild took longer than a repair would have, but it's the only way the site was going to hold up long-term.

Found

A small site kept reinfecting itself with spam links hidden inside its content which was invisible to logged-in users, appearing only at random for visitors, specifically to dodge both admins and malware scanners. Core files, plugins, and the WAF were all already up to date, which ruled out the obvious causes.

Fixed

We restored a clean backup, fully replaced core files, and ran a file-integrity scan against the official WordPress repository to catch anything hidden elsewhere. A custom detection plugin was added to catch and hide any reappearance immediately, and the WAF rules were tightened further. It never came back.

Found

A large company asked us to look into security issues across several aging WordPress sites. Beyond heavy bot traffic and spam, the sites were slow, hard to maintain, and running on a five-year-old theme with dependencies nobody could safely update without breaking the site.

Fixed

We audited each site, identified which outdated plugins and theme dependencies were actually blocking safe updates, and worked with the client's junior development team to bring their process up to a maintainable standard: code review, staging tests, and a clear decision-maker for anything risky. Recommended a cadence of frequent, smaller audits over the infrequent, high-risk approach that had let the problems build up in the first place.


Pricing

One plan for Shopify.
Everything included.

Large Plan

  • Full security monitoring
  • Monthly audit report
  • Uptime monitoring
  • Performance optimisation
  • SEO health tracking
  • Priority response
  • Extended audit reporting
  • Hourly backups & verification
  • Advanced integration configuration
  • Critical support
  • GEO health tracking
  • Monthly detailed speed auditing
  • Semantic markup yearly audit
  • Structured data yearly audit
€120 (per month)


Why WebEnsure

Human where it matters.
Automated where it makes sense.

Automated tools are great at catching predictable issues, but not so great at judgement calls. We validate everything and act before it breaks anything.

Transparency

Each month our customers are well informed about what's been happening on their site. We tell you exactly what the bots have been up to, what we've been up to and what we recommend next.

Longevity

We get to know your site better over time. The longer we work together, the more effectively we protect and improve your site. Your site gets better with age.

AI tools, human judgement

We use AI extensively, but we validate everything. The market is being flooded with "cheap" automated-only solutions nobody checks. We're the human oversight layer that makes the output actually trustworthy.

Platform-agnostic

WordPress, Laravel, Drupal, Lovable.dev, HTML, or something we haven't heard of yet; we manage it. WebEnsure is built around your site, not around a platform we resell.

Problems don't reach you

We are all about proactive security. Issues are best caught and resolved before you even know they exist. Proactive, not reactive, is the only model that gives you peace of mind.

Fully-managed, invisibly

Security patches, CMS updates, backup verification, uptime monitoring, performance tracking. All the nerdy stuff. Handled for you. Your website just works.

Your website deserves someone obsessed with it.

Website management as it should be.