Authorized penetration testing

WordPress Penetration Testing: authorized, evidence-led attack simulation.

A penetration test goes beyond configuration review by exercising an agreed application scope under written authorization. It is suited to custom plugins, themes, APIs, roles, workflows, WooCommerce features, and business logic where exploitability must be demonstrated safely. Testing follows the OWASP Web Security Testing Guide and is performed by an OSCP- and CompTIA PenTest+-certified tester.

Never send credentials, private keys, backup archives, or confidential source code through this website.

Best for
Custom code, authenticated workflows, integrations, and assurance requirements
Authorization
Written scope, exclusions, contacts, and testing window required
Testing
Manual adversarial validation supported by appropriate tooling
Output
Reproducible evidence, impact, remediation guidance, and retesting
Typical fee
$450–$1,500 by scope · 5–10 business days · OSCP-certified tester

Testing scope

What can be assessed

Authentication and sessions

Login, recovery, MFA, session lifecycle, remember-me behavior, rate controls, and account-state transitions.

Authorization and roles

Horizontal and vertical privilege boundaries across administrators, editors, customers, members, vendors, and custom roles.

Custom components

Approved custom plugins, themes, AJAX actions, REST endpoints, shortcodes, uploads, and server-side handlers.

Business logic

Workflow manipulation, price or entitlement changes, state transitions, replay, sequencing, and abuse of intended functionality.

Input and data handling

Injection, cross-site scripting, request forgery, upload handling, sensitive data exposure, and unsafe error behavior.

Integrations and APIs

Defined third-party callbacks, webhooks, API authentication, data boundaries, and failure handling.

Methodology

OWASP-aligned testing, CVSS-scored findings, a named tester

Buyers compare penetration tests on method as much as on findings. This is the method.

Test cases are drawn from the OWASP Web Security Testing Guide (WSTG) and organized around the OWASP Top 10, then extended with WordPress-specific classes: capability and nonce checks on AJAX and REST handlers, role boundaries across custom roles, WooCommerce order and coupon logic, upload handling, and the interaction between plugins that were never designed to run together. Each confirmed finding is scored with CVSS v3.1, mapped to the relevant CWE, and written so a developer can reproduce it from the report alone.

Testing is performed personally by G. Schad, who holds the Offensive Security Certified Professional (OSCP), CompTIA PenTest+, and CompTIA CASP+ certifications. Tooling supports coverage; every reported issue is manually validated, and scanner output is never presented as a confirmed vulnerability.

Typical use cases

Where a penetration test earns its fee

WooCommerce penetration testing

Checkout, coupon, cart, refund, subscription, and account flows tested for price manipulation, entitlement bypass, and order-data exposure — the store-specific counterpart of the WooCommerce audit.

Custom plugin or theme review

Security review of code you commissioned or built: AJAX and REST handlers, shortcodes, uploads, options screens, and integrations, with access-assisted source review where it shortens the path to a finding.

Membership and LMS platforms

Role and content-entitlement boundaries across members, instructors, and administrators, plus the payment and enrolment logic that sits on top of WordPress.

Assurance for a client, insurer, or acquirer

A dated, scoped test with reproducible evidence and a retest record that answers a third party’s security question without a compliance certificate being implied.

Rules of engagement

Controlled testing protects the production system

  • Written authorization and named system owners
  • Explicit in-scope hosts, paths, roles, accounts, and integrations
  • Testing window, rate expectations, and emergency contacts
  • Prohibited actions and sensitive-data handling rules
  • Production, staging, or hybrid testing decision
  • Evidence sanitization, retention, and secure deletion terms
  • A defined process for critical findings discovered during testing

Audit or penetration test

Choose based on the question you need answered

EngagementPrimary questionTypical emphasis
Security auditAre WordPress and its operating controls configured safely?Broad coverage of configuration, extensions, accounts, exposure, and recovery.
Penetration testCan an attacker exploit the defined application behavior?Depth on custom functionality, roles, workflows, APIs, and demonstrated attack paths.

Reporting

Evidence is written for remediation and retesting

Each confirmed finding identifies the affected functionality, preconditions, sanitized reproduction evidence, realistic impact, and a remediation direction. Findings are discussed before finalization when context may change severity or ownership.

After agreed fixes are available, the affected behavior is retested and the status is recorded. A retest verifies the specific remediation; it is not presented as a new full penetration test unless separately scoped.

Common questions

Questions about this engagement

Can you test a production WordPress site?

Yes, when production testing is appropriate and explicitly authorized. Rate, timing, accounts, prohibited actions, monitoring, and escalation procedures are agreed first.

Do you test third-party plugins?

Installed components can be assessed in the context of the site. Broad research against third-party products or infrastructure not owned by the client requires separate authorization and scope.

Is source-code review included?

Not automatically. Targeted access-assisted review can be included when source is available and the objective warrants it.

Will you provide a compliance certificate?

The report documents the agreed work and observed results. It does not by itself certify compliance with a framework unless that mapping is explicitly included in scope.

How much does a WordPress penetration test cost?

Typically $450–$1,500 according to scope, over 5–10 business days. The range follows the breadth of in-scope functionality, roles, APIs, production constraints, and reporting depth; the written proposal fixes the fee for the agreed scope. For comparison, a general web application penetration test from a firm usually starts several times higher — the focus on WordPress and WooCommerce is what keeps this range realistic.

Which methodology and standards do you follow?

The OWASP Web Security Testing Guide and OWASP Top 10 provide the test cases; findings are scored with CVSS v3.1 and mapped to CWE identifiers. Rules of engagement follow the written-authorization, scope, and evidence-handling practice described on this page. The tester holds OSCP, PenTest+, and CASP+.

Can you test a WooCommerce store or a custom plugin specifically?

Yes. WooCommerce checkout, coupon, and account logic, and custom plugins or themes with their AJAX and REST handlers, are the most common scopes. Test orders, test accounts, and rate limits are agreed so live customers are never affected.