Frequently asked questions
Straight answers before you provide access or authorize testing.
These questions cover the engagement model shared across services. Service pages contain additional questions specific to audits, malware response, server reviews, penetration testing, and ongoing care.
Never send credentials, private keys, backup archives, or confidential source code through this website.
- Testing
- Authorized and manually validated
- Production
- Constraints agreed before active work
- Access
- Temporary and least privilege
- Credentials
- Never submitted through this website
Choosing a service
Audit, incident response, penetration testing, or ongoing care?
| Your situation | Starting point |
|---|---|
| You want to find weaknesses before an incident | WordPress security audit |
| You run a WooCommerce store and need the store-specific review | WooCommerce security audit |
| The site is redirecting, infected, suspended, or repeatedly compromised | Malware removal and hardening |
| You need host-level review of Linux, SSH, web server, PHP, or isolation | Linux web server security audit |
| You need adversarial testing of custom behavior, roles, or APIs | WordPress penetration testing |
| Cloudflare sits in front of the site and nobody owns its configuration | Cloudflare security management |
| You already have a baseline and need continuing oversight | Managed WordPress security |
Common questions
Questions about this engagement
Is this an automated scan?
No. Tooling is used where it improves coverage, but every reported vulnerability is manually reviewed before it appears as a confirmed finding.
Will testing affect production availability?
Production constraints and testing windows are agreed before active testing. Destructive testing is not performed unless separately and explicitly authorized.
What access will you need?
It depends on the objective. Work may begin externally. Credentialed review uses a named, temporary, least-privilege account arranged after scoping.
Can you fix findings as well as report them?
Yes, where agreed. Remediation can also be delivered as guidance for your developers, host, or administrators.
How are credentials exchanged?
Never through this website or ordinary email. A secure exchange method is agreed after the scope and engagement terms are in place.
Do you guarantee that a site will never be hacked?
No responsible assessment can guarantee future security. The work documents observed risk, improves controls within scope, and identifies unresolved dependencies.
Can you work under an NDA?
Yes. An NDA can be completed before detailed scoping when required.
Do you test sites without authorization?
No. Active testing requires written authorization from the system owner or an authorized representative.
What does retesting cover?
Retesting verifies the specific agreed remediation. It is not a new full assessment unless that wider work is separately scoped.
What should the first inquiry include?
Provide the domain, service or concern, relevant deadlines, business impact, and a non-sensitive environment summary. Do not include passwords, keys, backups, or confidential source code.