GreyNod Labs logo

Cybersecurity service

WordPress Security Assessment

An authorised review of a WordPress site’s configuration, plugins, themes and access for security weaknesses.

WordPress sites are made up of core software, themes and plugins that need ongoing attention. A WordPress security assessment reviews how your site is set up and looks for weaknesses within the agreed scope.

Depending on the authorised scope, we combine manual testing and verification with automated tools such as Burp Suite, Nmap, Nuclei, OWASP ZAP, Nessus and SQLmap, and other suitable tools. Not every tool is used in every engagement.

Who it is for

  • Owners of WordPress and WooCommerce websites
  • Businesses that want an independent review of a site built by someone else

What is in scope

  • WordPress core, theme and plugin versions and configuration
  • User roles, login and access settings
  • Exposed functionality and common misconfigurations
  • Custom code, where it is part of the agreed scope

How we work

  1. Agree scope and authorisation. We confirm the site, environment and permitted techniques in writing before testing.
  2. Assess. We review the configuration and test the site manually and with suitable tools.
  3. Report. We deliver verified findings and remediation recommendations.

What you receive

  • A written report with verified findings and supporting evidence
  • Remediation recommendations you or your developer can act on

Limitations

  • The hosting provider’s infrastructure is out of scope unless separately authorised.
  • A security assessment reduces risk but cannot guarantee that every vulnerability will be found or that a system will remain secure.
  • Retesting is optional and can be agreed separately; it is not automatically included.

What we need from you

  • Written authorisation from the owner of every in-scope asset before testing starts
  • Access details agreed for the assessment, such as a staging copy or test accounts

Frequently asked questions

Can you also fix the issues?

Remediation guidance is part of the report. Applying fixes can be discussed separately.

Ready to talk about your project?

Tell us what you need and we will reply with next steps.

Request a Consultation