Your site is served securely over HTTPS, publishes a privacy policy. The full assessment (across security, privacy, Australian consumer law and performance) follows below, with every check we ran listed at the end.
Every finding comes from a real check on your live website. Each is explained in plain English: what it is, why it’s needed, the risk if it’s left, and what to do. Where a matter is a legal judgement we flag it for professional review rather than ruling on it. This is a website health check, not a penetration test, and it’s advisory only: not legal advice.
Security covers the technical defences that keep attackers out and your visitors’ data safe in transit: encryption, security headers, known software vulnerabilities and public exposure.
Your site runs WordPress and the core version we detected is several releases out of date. One active plugin also matches a published vulnerability. Out-of-date components are the most common way small-business sites are compromised.
Most hacked sites are broken into through a known, already-patched flaw that nobody got around to updating, automated bots find these within days. For a practice holding patient information, that is both a data-breach risk and a downtime risk.
Your domain has no DMARC record, so nothing stops someone sending email that appears to come from your address.
Email impersonation is one of the most common and costly frauds hitting small businesses: a spoofed invoice or "please update your bank details" message sent to your own patients, in your name.
Your site is missing 3 of the 5 security headers we check: Content-Security-Policy, X-Frame-Options and Referrer-Policy. You already have the other two.
These headers tell browsers how to defend your visitors against clickjacking and content injection. Missing them makes it easier for an attacker to frame your site or inject malicious code.
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-originYour domain does not have DNSSEC enabled. DNSSEC signs your DNS records so they cannot be forged.
Without it, a DNS-spoofing attacker can send your patients to a look-alike site without ever touching your server.
Your site is served over HTTPS with a valid certificate, so information travels encrypted.
Nice work), this is the foundation of a trustworthy site, and visitors see the padlock rather than a "Not secure" warning.
Make sure the certificate auto-renews before expiry.
Your site is not on Google's blacklist for malware or phishing.
You've done this right (a clean record means patients never hit a red "dangerous site" warning.
Australian domain policy (auDA) means expiry dates are deliberately not published for any .au domain, so no tool can look this up, ours included.
A lapsed domain takes your website and your email offline at once, and the name can then be registered by someone else.
Privacy covers whether you handle personal information lawfully and openly: a findable, adequate privacy policy, and clarity about what you collect and why. It’s the transparency customers look for before trusting you with their details, and what the Privacy Act requires of the businesses it covers.
We detected third-party tracking on your site (Google Analytics and a Meta pixel). We read your privacy policy and it does not mention tracking, pixels or analytics anywhere.
In its June 2026 determinations against Medmate and Monash IVF, the OAIC found that running a third-party pixel without naming it in the privacy policy breaches the Australian Privacy Principles, and a generic "we use cookies" line was not specific enough to count.
Your newsletter form collects email addresses with no consent checkbox and no link to your privacy policy at the point of collection.
Under the Spam Act, consent to marketing has to be a clear, active choice, consent collected without one can make the whole list unlawfully collected, not just one address.
A privacy policy is published and linked in your footer, so it appears on every page.
You've done this right. A findable policy is the baseline a careful patient looks for before handing over their details.
Health-service providers are covered by the Privacy Act regardless of annual turnover.
This is based on the industry and turnover you told us. It is not legal advice.
Compliance covers your obligations to customers under Australian law: your terms, refund rights, ABN and contact details. These are the signals a legitimate, trustworthy Australian business is expected to show, and the ones customers and regulators look for.
We could not find your ABN on your homepage, contact or about pages.
Patients and partners look for an ABN to confirm a business is genuinely registered; if it isn't where they look, it can quietly cost you enquiries.
We could not find terms and conditions anywhere on the site, though you offer online booking.
Published terms are what you point to if a dispute arises about a booking, cancellation or payment plan.
Your homepage shows a phone number, an email address and a contact page.
You've done this right (visible contact details are the first thing people check to confirm a business is real and reachable.
Your practice address is clearly shown on the site.
You've done this right), a visible address is a strong local-trust signal.
Performance covers whether your site actually works for the people who visit, its speed, mobile-friendliness, working links and how current it looks. These are the quiet things that cost you customers and search ranking when they slip.
We checked 42 links across your site and all of them resolved.
You've done this right (no dead ends for patients, and none for search engines.
Your pages set a mobile viewport, so they display correctly on phones.
You've done this right), most of your patients will visit on a phone.
We found no signs of stale or placeholder content.
You've done this right (a current-looking site reassures people the practice is active.
How ready your site is for AI assistants (ChatGPT, Perplexity, Google) to discover and understand your business. Informational, it doesn’t affect your score.
The major AI crawlers are permitted in your robots.txt.
✅ You've done this right) an AI answering a patient's question can actually reach your site.
Your page content is present in the initial HTML.
✅ You've done this right (AI crawlers and search engines can read it directly.
Your pages carry a meta description and social-preview tags.
✅ You've done this right) you control the one-line summary AI and social platforms show.
Your site does not publish Schema.org structured data) the machine-readable summary AI assistants use to understand a business.
Without it, an assistant has to guess what you do and where you are, which is how practices get described inaccurately or left out.
Lift your website trust score to 80 or higher with no outstanding critical issues, and you’ll earn the AegorIQ Reviewed badge, a dated, independent mark you can display on your website, linking to a verification page anyone can check. It’s the same work you’re already doing to secure and improve your site, turned into something your customers can actually see.
How this helps how AI represents you. AI assistants increasingly describe a business by drawing on what independent, third-party sources say about it. Your badge links to a verification page on AegorIQ (an external page stating that your website was independently reviewed and what that review found) which gives these systems a credible, citable signal to draw on.
How this helps your search visibility. Your verification page includes a genuine link back to your website from AegorIQ. A relevant third-party link is a recognised trust signal that can support your search visibility over time. And the badge on your own site reassures visitors, stronger trust tends to improve engagement, which search engines reward.
The Deep Scan probes for the exposures a determined attacker looks for: leaked files and secrets, weak encryption, and subdomain or port exposure.
2 folders on your site show a full file listing to anyone who visits them, instead of a normal page. That lets a stranger browse and download every file in those folders: including things never meant to be found by looking.
Open directory listings routinely expose backups, spreadsheets, invoices and draft files that owners assumed were private because nothing linked to them. "Not linked" is not the same as "not public".
Your site has xmlrpc.php enabled. It is a legacy WordPress feature that lets an attacker attempt many password guesses in a single request, and it can be abused to help overwhelm your site.
XML-RPC turns a slow password-guessing attack into a fast one, and has been used to knock small sites offline. If you don't use the Jetpack app or remote publishing, you almost certainly don't need it.
Your server still allows TLS 1.0/1.1 connections alongside modern ones. These older protocols have known weaknesses and are no longer considered safe.
Modern browsers won't use them, so removing them breaks nothing for real visitors, but leaving them enabled keeps a weakness available to anyone deliberately looking for one, and it fails most security questionnaires.
We probed for private configuration, admin and repository files being downloadable from your site and found none.
You've done this right, these are the files attackers scan for daily, and they often contain database passwords.
Aside from the two folders flagged above, no other folder on your site exposes a browsable file listing.
The rest of your site behaves correctly, visitors get a normal page, not an index of your files.
We scanned the code your site sends to every visitor's browser for exposed passwords and access keys, and found none.
You've done this right, a leaked key in front-end code can hand someone access to a connected service.
We checked the common locations where a full site backup or configuration file is accidentally left downloadable. Nothing was reachable.
You've done this right, a downloadable backup often includes your database password.
We reviewed the third-party scripts your pages load. Nothing is loading in a way that would let a hacked script quietly read what customers type.
You've done this right (this is the attack that hit British Airways and Ticketmaster.
The cookies your site sets carry the Secure and HttpOnly flags where expected.
You've done this right), it stops a logged-in session being hijacked or read by injected scripts.
We checked your DNS records for subdomains pointing at services that are no longer claimed. None were found.
You've done this right. An abandoned subdomain can be claimed by someone else and used to phish your patients from your own web address.
We looked for test, staging or development sites publicly reachable on your domain and found none.
You've done this right, staging sites are usually far less protected than the real one.
A safe, limited check of common administrative ports found nothing open to the public internet.
You've done this right (open admin ports are a direct route in.
Every resource on your secure pages loads over HTTPS), nothing is being pulled in insecurely.
You've done this right, mixed content quietly breaks the padlock your patients rely on.
Your domain publishes MTA-STS and TLS reporting records, so mail to you is required to travel encrypted and you're told when it doesn't.
You've done this right (this is a step beyond what most small businesses have.
| Action | Priority | Suggested timing |
|---|---|---|
| Update WordPress core, plugins and themes (back up first) | Fix first | As soon as you can |
| Publish SPF, DKIM and DMARC records for your domain | Fix first | As soon as you can |
| Name your analytics and advertising tools in your privacy policy | Fix soon | Recommended |
| Add the three missing security headers | Fix soon | Recommended |
| Add your ABN to your website footer | Fix soon | Recommended |
| Turn off directory listing on the two exposed folders | Fix soon | Recommended |
| Enable DNSSEC with your DNS provider | Optional | When convenient (no rush |
| Add a consent checkbox and privacy link to your sign-up form | Optional | When convenient) no rush |
Below is every check included in your report: not just the ones that found something. A check that passed is a real result, and so is one we couldn't complete. We'd rather show you the whole list than let silence do the talking.
19 checked with no issue ·
9 need attention ·
3 for your awareness ·
0 not tested ·
5 not applicable to your site
Not tested means exactly that. We tried and could not complete it. It is neither a pass nor a problem, and we will never let it quietly become one.
Fix something and re-scan to confirm it’s gone, free for 90 days. And if a rule changes, or a vulnerability turns up in software we saw running on your site, we may drop you a line: a courtesy based on what we found at the time of this audit, not ongoing monitoring.
This report is advisory only. It is not legal advice, and AegorIQ is not a law firm.
Where we comment on your privacy policy, your refund and returns terms, or your ABN disclosure, we are reporting what our automated checks found in the text you publish: for example, that a policy does not appear to say how someone makes a complaint, or that refund wording uses language that is often a problem under the Australian Consumer Law. We are not reading your documents the way a lawyer would, and we are not ruling on whether you comply with any law.
Whether a particular obligation applies to your business, and whether your wording satisfies it, depends on facts we cannot see and on judgement a scan cannot make. Before you rely on, change, or decide not to change a legal document, get advice from a qualified Australian legal practitioner. Treat what follows as a well-informed list of things worth asking them about. That is exactly what it is good for.
The security findings are a different matter: those are direct technical observations of your site's configuration, and you can act on them with confidence.
Start with the free Scorecard. A real audit that tells you how many issues we found and where. Or go straight to the full report.
Get your free Scorecard See pricing