A security review, and the fixes that matter.
We look at how your site handles logins, forms, uploads and personal data, then fix the risks we find and explain what is left. No website can be made unhackable, so we report plainly rather than selling you a promise nobody can keep.
Reviewed September 20, 2026. Prices are quoted per project; nothing on this page is a published price list.
The short answer
We check, we fix, and we tell you what we could not fix.
Small business sites get attacked by automation, not by people targeting you: credential stuffing, form spam, exposed backups, vulnerable plugins on sites that use them. Most of that is closable with boring, durable work.
What we check
- Forms: what they accept, where they send it, whether they can be abused to spam you.
- Logins and admin areas: password storage, session handling, brute-force limits.
- Data: what personal information you collect, where it goes, and what you are allowed to keep.
- Dependencies: anything third-party loading into your pages, and what it can do.
- Backups and recovery: whether you could actually restore the site if it broke.
What we fix first
Highest impact for the least risk: transport security and headers, form abuse controls, removing what you do not need, and making sure the person who owns the domain can recover access without a support ticket to a company that no longer answers.
Trade-offs we will say out loud
Security controls cost convenience. A stricter policy can break an embedded widget; a stricter login can annoy you. We tell you what each fix costs you in day-to-day use before we apply it, and we never describe a site as unhackable.
Questions
What happens if you find something serious?
You hear it immediately, plainly, with the risk and the fix, before we write anything else up. If it is urgent — live exposure of personal data or credentials — we tell you the same hour and agree what to do next rather than waiting for a report document.
Is a static website more secure than WordPress?
It has fewer moving parts, which means fewer ways in: no database, no plugin updates, no admin login on the public site. That removes whole classes of attack, but it does not make a site safe by itself — hosting, domain, email and any third-party script still need care.
How do you price a project?
With one fixed price, agreed in writing before anything starts. The quote sets out the scope, the revision allowance and the delivery date. There is no hourly meter running while we work, and no retainer afterwards.
Who owns the finished website?
You do. The code, the domain, the hosting account and the email addresses are registered in your name, not ours. If we disappeared tomorrow, your website would not notice.
How long does it take?
Simple sites take days. Larger builds depend on their scope, and every quote includes an expected delivery date. Revisions inside the agreed scope are part of the deal, not an extra.
Tell us what you need. Send a few rough lines and we will come back with a scope, a fixed price and a delivery date in writing.
Start a projectRelated: 24 short answers about working with us · what a website costs in 2026 · three demo builds you can open.