Everything in the Essentials audit
All 35 Essentials checks, in fullYour policies read and graded, business identity, email spoofing protection, domain security, site security, trackers, performance and AI readiness. See the full Essentials list on its own page — every line of it is included here.
A human being reads it
Expert review by a cybersecurity professionalThey read your specific site before you do, and tell you what actually needs your urgent attention and what can safely wait. No software can make that call.
Step-by-step fix for every issueNumbered instructions you can hand straight to your web developer.
Prioritised remediation planWhat to fix first, and what can safely wait — so you're not staring at a list of twenty things.
AI Readiness action planYour on-page AI Readiness score, plus the specific, prioritised steps to help AI assistants like ChatGPT and Perplexity find and recommend your business — including the off-site factors a scan alone can't fix.
Compliance obligations & deadlinesThe dated legal obligations that apply to your business, laid out so nothing sneaks up on you.
14 deeper scans Essentials doesn't run
Exposed sensitive filesAre private config files, admin pages or repository data sitting on your site for anyone to download? Attackers scan for these daily.
Directory listingCan a stranger browse and download every file in your folders — backups, spreadsheets, invoices — just by visiting the folder? "Not linked" isn't the same as "not public".
WordPress XML-RPC exposureFor WordPress sites — the legacy XML-RPC feature can let attackers try hundreds of passwords in a single request, and overload your site.
Leaked API keys & secrets in your codeAre your passwords or access keys visible in the code your site sends to every visitor's browser?
Exposed backup & config filesCan anyone download a full copy of your website — often including your database password?
Payment-skimming surface (third-party script integrity)Could a hacked third-party script steal card details at your checkout? This is the attack that hit British Airways and Ticketmaster.
Insecure cookiesCould someone hijack a logged-in customer's session?
Subdomain takeover riskCould someone claim an abandoned part of your domain and phish your customers from your own web address?
Exposed non-production subdomainsAre your test, staging or admin sites publicly visible? They're usually far less protected than your real site.
Exposed service portsAre there admin doors left open to the internet? A safe, limited check.
TLS / encryption strengthDoes your server still accept old, insecure connections that fail modern standards?
Mixed contentAre parts of your secure page loading insecurely — quietly breaking the padlock your customers rely on?
Advanced email security (MTA-STS & TLS-RPT)Is your email encrypted on its way to your customers, and are you told when it isn't?
Performance & SEO (Google Lighthouse)How fast is your site really, and can Google read it properly? Includes Core Web Vitals.