01Work 02Solutions 03Process 04Demos 05Pricing 06Book a call
CypherSecurity · by MDI LABS
WordPress security audit · $49 flat · 24–48h

A WordPress security audit that shows you what is actually exposed

We run a public, read-only check of your site — WordPress version age, HTTPS/login exposure, exposed endpoints, redirect behavior — and send a prioritized fix list. No access needed. No plugins to install. You keep the report.

Why an audit first

The cheap insurance before a problem costs revenue.

WordPress runs a large share of the web, and most of it is silently behind on security. The sites that get compromised are rarely the ones that were watching — they're the ones where the core went past its patch window, the login stayed on plain HTTP, or an endpoint that should be private stayed public.

You do not need to wait for a Google warning or a host suspension to know where you stand. A 24–48h read-only audit names the specific gaps, rates their severity, and gives you a plain-language fix list — so the decision is about priorities, not panic.

Core & patches

WordPress age

Is your core past the maintained window or fully end-of-life? Known patch history matters.

Transport & login

HTTPS exposure

Does HTTP reach the login page? Mixed content? Certificate problems?

Attack surface

Exposed endpoints

XML-RPC, CLI/health paths, server header leaks, redirect chains.

What we check

Read-only, public, non-destructive — what a normal visitor's browser sees.

Our scanner makes ordinary public requests and reads what the server returns. It never logs in, never posts, never fuzzes, and never touches private hosts. Everything on the list is a verifiable signal:

  • WordPress version + age verdict — past maintained window (>2.5y) or end-of-life (>4y) gets flagged with the patch risk explained
  • HTTP → HTTPS redirect — a missing redirect means login and forms can still be served over cleartext
  • TLS certificate validity — misconfiguration means browser warnings before you even engage
  • Mixed content / forms over HTTP — real "your login page is over plain HTTP" findings
  • XML-RPC + exposed CLI/health endpoints — common brute-force and persistence vectors
  • Server header leaks + redirect chain + page weight — information disclosure and mobile speed signals

Each finding ships with a severity rating and a what to do about it. If you act on the fix list yourself, great. If you want it done, the same page points to scoped cleanup and hardening packages.

How it works

Three steps. No access, no plugins, no scare tactics.

1
Pay $49Secure Stripe checkout. No subscription, no hidden fees.
2
Confirm the URLShort intake — the exact site to audit (2 minutes).
3
Get the reportPrioritized fix list in 24–48h, delivered to your inbox. You keep it regardless of next steps.

Found something urgent in the report? Emergency WordPress cleanup targets a 48-hour turnaround after deposit and intake — see the CypherSecurity hub for packages.

Know where your site stands.

$49, 24–48h, report is yours to keep. If you'd rather go straight to a full cleanup or hardening, compare packages on the hub.