This is a sample Expert report: a realistic example, not a real customer's site. Every finding is written exactly as you'd receive it.  See pricing  ·  Back to AegorIQ
Overview · Website Compliance & Security Report
⬇ PDF

1 · Overview

Snapshot: what we saw
Sample Dental Care · sampledental.com.au

Your site is served securely over HTTPS, publishes a privacy policy. The full assessment (across security, privacy, Australian consumer law and performance) follows below, with every check we ran listed at the end.

AegorIQ TrustScore™
4-Pillar Website Security & Compliance Framework
40Security55Privacy70Compliance100Performance52TRUSTSCORE/ 100
Needs Attention
Address soon
1
Critical
10
Attention
19
Passing
6
For reference
About AegorIQ TrustScore™: Higher is better. 100 = no issues found. Your score is calculated from four pillars: Security (35%), Privacy (25%), Compliance (25%), and Performance (15%). We don't publish an industry average, because we don't have one we could stand behind, and a number we can't show the working for is exactly what we tell you not to trust. We found 1 critical and 10 needs-attention items. Prioritise: Outdated or vulnerable WordPress components; No DMARC record. Your email domain can be spoofed; Missing security headers (3 of 5). Each is explained below with what to do next.
What this report is, and isn’t

Every finding comes from a real check on your live website. Each is explained in plain English: what it is, why it’s needed, the risk if it’s left, and what to do. Where a matter is a legal judgement we flag it for professional review rather than ruling on it. This is a website health check, not a penetration test, and it’s advisory only: not legal advice.

2 · Security

🛡 Security
40/ 100
Pillar summary

Security covers the technical defences that keep attackers out and your visitors’ data safe in transit: encryption, security headers, known software vulnerabilities and public exposure.

1 critical3 attention2 passing1 awareness
CriticalOutdated or vulnerable WordPress components
What it is

Your site runs WordPress and the core version we detected is several releases out of date. One active plugin also matches a published vulnerability. Out-of-date components are the most common way small-business sites are compromised.

Components flagged
  • WordPress core 6.3.8 → update to 7.0.2
  • A page-builder plugin at 3.27.4, matches CVE-2024-5533
Why it matters, the risk if you don’t

Most hacked sites are broken into through a known, already-patched flaw that nobody got around to updating, automated bots find these within days. For a practice holding patient information, that is both a data-breach risk and a downtime risk.

What to do
  • Back up the site (files and database) before making changes
  • Update core first, then plugins, then themes
  • Turn on automatic security updates where each plugin offers it
Step-by-step fix
  1. Take a full backup, or ask your host to take one.
  2. In WordPress admin, open Dashboard → Updates and update core.
  3. Update all plugins and the active theme, then re-test your booking form and contact page.
AttentionNo DMARC record. Your email domain can be spoofed
What it is

Your domain has no DMARC record, so nothing stops someone sending email that appears to come from your address.

Why it matters, the risk if you don’t

Email impersonation is one of the most common and costly frauds hitting small businesses: a spoofed invoice or "please update your bank details" message sent to your own patients, in your name.

What to do
  • Ask your email or IT provider to publish SPF, DKIM and DMARC together
  • Start DMARC in monitor mode (p=none), then tighten once your legitimate mail passes
AttentionMissing security headers (3 of 5)
What it is

Your site is missing 3 of the 5 security headers we check: Content-Security-Policy, X-Frame-Options and Referrer-Policy. You already have the other two.

Why it matters, the risk if you don’t

These headers tell browsers how to defend your visitors against clickjacking and content injection. Missing them makes it easier for an attacker to frame your site or inject malicious code.

What to do
  • Add X-Frame-Options: SAMEORIGIN
  • Add a Content-Security-Policy in report-only mode first
  • Add Referrer-Policy: strict-origin-when-cross-origin
🔧 For your web person
X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin
Set these response headers at your server or CDN. On most hosts this is one configuration file.
AttentionDNSSEC is not enabled
What it is

Your domain does not have DNSSEC enabled. DNSSEC signs your DNS records so they cannot be forged.

Why it matters, the risk if you don’t

Without it, a DNS-spoofing attacker can send your patients to a look-alike site without ever touching your server.

What to do
  • Ask your DNS host or registrar to enable DNSSEC (usually a toggle plus one record
PassingValid SSL certificate (HTTPS)
What it is

Your site is served over HTTPS with a valid certificate, so information travels encrypted.

You’ve done this right

Nice work), this is the foundation of a trustworthy site, and visitors see the padlock rather than a "Not secure" warning.

Best practice

Make sure the certificate auto-renews before expiry.

PassingNot flagged on Google Safe Browsing
What it is

Your site is not on Google's blacklist for malware or phishing.

You’ve done this right

You've done this right (a clean record means patients never hit a red "dangerous site" warning.

For your awarenessDomain expiry) a quick one to confirm yourself
What it is

Australian domain policy (auDA) means expiry dates are deliberately not published for any .au domain, so no tool can look this up, ours included.

Why it matters, the risk if you don’t

A lapsed domain takes your website and your email offline at once, and the name can then be registered by someone else.

Worth checking
  • Log in to your registrar and check the renewal date
  • Turn on auto-renew while you are there

3 · Privacy

🔐 Privacy
55/ 100
Pillar summary

Privacy covers whether you handle personal information lawfully and openly: a findable, adequate privacy policy, and clarity about what you collect and why. It’s the transparency customers look for before trusting you with their details, and what the Privacy Act requires of the businesses it covers.

2 attention1 passing1 awareness
AttentionThird-party tracking is not disclosed in your privacy policy
What it is

We detected third-party tracking on your site (Google Analytics and a Meta pixel). We read your privacy policy and it does not mention tracking, pixels or analytics anywhere.

Why it matters, the risk if you don’t

In its June 2026 determinations against Medmate and Monash IVF, the OAIC found that running a third-party pixel without naming it in the privacy policy breaches the Australian Privacy Principles, and a generic "we use cookies" line was not specific enough to count.

What to do
  • Name the specific tools in your privacy policy (APP 1.3)
  • Add a short notice at the point of collection (APP 5)
  • Ask whoever runs your marketing which pixels are live and whether you still need them
AttentionA sign-up form collects details without a consent option
What it is

Your newsletter form collects email addresses with no consent checkbox and no link to your privacy policy at the point of collection.

Why it matters, the risk if you don’t

Under the Spam Act, consent to marketing has to be a clear, active choice, consent collected without one can make the whole list unlawfully collected, not just one address.

What to do
  • Add an unticked "I agree to receive updates" checkbox
  • Link your privacy policy beside the form
PassingPrivacy Policy found and linked
What it is

A privacy policy is published and linked in your footer, so it appears on every page.

You’ve done this right

You've done this right. A findable policy is the baseline a careful patient looks for before handing over their details.

For your awarenessThe Privacy Act applies to your business
What it is

Health-service providers are covered by the Privacy Act regardless of annual turnover.

Why it matters, the risk if you don’t

This is based on the industry and turnover you told us. It is not legal advice.

4 · Compliance

⚖️ Compliance
70/ 100
Pillar summary

Compliance covers your obligations to customers under Australian law: your terms, refund rights, ABN and contact details. These are the signals a legitimate, trustworthy Australian business is expected to show, and the ones customers and regulators look for.

2 attention2 passing
AttentionABN not visible
What it is

We could not find your ABN on your homepage, contact or about pages.

Why it matters, the risk if you don’t

Patients and partners look for an ABN to confirm a business is genuinely registered; if it isn't where they look, it can quietly cost you enquiries.

What to do
  • Add your ABN to the website footer or contact page
  • Include your legal entity name alongside it
AttentionNo Terms & Conditions found
What it is

We could not find terms and conditions anywhere on the site, though you offer online booking.

Why it matters, the risk if you don’t

Published terms are what you point to if a dispute arises about a booking, cancellation or payment plan.

What to do
  • Publish a short terms page covering bookings, cancellations and payment
  • Link it in your footer
PassingContact details visible
What it is

Your homepage shows a phone number, an email address and a contact page.

You’ve done this right

You've done this right (visible contact details are the first thing people check to confirm a business is real and reachable.

PassingBusiness address visible
What it is

Your practice address is clearly shown on the site.

You’ve done this right

You've done this right), a visible address is a strong local-trust signal.

5 · Performance

⚡ Performance
100/ 100
Pillar summary

Performance covers whether your site actually works for the people who visit, its speed, mobile-friendliness, working links and how current it looks. These are the quiet things that cost you customers and search ranking when they slip.

3 passing
PassingNo broken links found
What it is

We checked 42 links across your site and all of them resolved.

You’ve done this right

You've done this right (no dead ends for patients, and none for search engines.

PassingMobile-friendly viewport configured
What it is

Your pages set a mobile viewport, so they display correctly on phones.

You’ve done this right

You've done this right), most of your patients will visit on a phone.

PassingContent looks current
What it is

We found no signs of stale or placeholder content.

You’ve done this right

You've done this right (a current-looking site reassures people the practice is active.

6 · AI Readiness

🤖 AI Readiness
4/ 6 signals
Pillar summary

How ready your site is for AI assistants (ChatGPT, Perplexity, Google) to discover and understand your business. Informational, it doesn’t affect your score.

ReadyAI assistants are allowed to read your site
What it is

The major AI crawlers are permitted in your robots.txt.

You’ve done this right

✅ You've done this right) an AI answering a patient's question can actually reach your site.

ReadyYour content is readable without JavaScript
What it is

Your page content is present in the initial HTML.

You’ve done this right

✅ You've done this right (AI crawlers and search engines can read it directly.

ReadyYou have clear preview & summary metadata
What it is

Your pages carry a meta description and social-preview tags.

You’ve done this right

✅ You've done this right) you control the one-line summary AI and social platforms show.

OpportunityNo structured data for AI to read
What it is

Your site does not publish Schema.org structured data) the machine-readable summary AI assistants use to understand a business.

Why it matters, the risk if you don’t

Without it, an assistant has to guess what you do and where you are, which is how practices get described inaccurately or left out.

Worth checking
  • Add LocalBusiness / Dentist structured data with your name, address, phone and opening hours
🏅 Tip) turn your progress into a visible trust signal

Lift your website trust score to 80 or higher with no outstanding critical issues, and you’ll earn the AegorIQ Reviewed badge, a dated, independent mark you can display on your website, linking to a verification page anyone can check. It’s the same work you’re already doing to secure and improve your site, turned into something your customers can actually see.

How this helps how AI represents you. AI assistants increasingly describe a business by drawing on what independent, third-party sources say about it. Your badge links to a verification page on AegorIQ (an external page stating that your website was independently reviewed and what that review found) which gives these systems a credible, citable signal to draw on.

How this helps your search visibility. Your verification page includes a genuine link back to your website from AegorIQ. A relevant third-party link is a recognised trust signal that can support your search visibility over time. And the badge on your own site reassures visitors, stronger trust tends to improve engagement, which search engines reward.

8 · Deep Scans

🔎 Deeper security scans
What this section covers

The Deep Scan probes for the exposures a determined attacker looks for: leaked files and secrets, weak encryption, and subdomain or port exposure.

3 attention11 passing
AttentionAnyone can browse your website's folders
What it is

2 folders on your site show a full file listing to anyone who visits them, instead of a normal page. That lets a stranger browse and download every file in those folders: including things never meant to be found by looking.

Folders that are publicly listable
  • /uploads/2024/
  • /backups/
Why it matters, the risk if you don’t

Open directory listings routinely expose backups, spreadsheets, invoices and draft files that owners assumed were private because nothing linked to them. "Not linked" is not the same as "not public".

What to do
  • Turn off automatic directory listing on your web server
  • Add an empty index file to sensitive folders as a stop-gap
  • Move anything genuinely private out of the public web folder entirely
Step-by-step fix
  1. Ask your host to disable directory indexing (on Apache this is "Options -Indexes"; most hosts have a one-click setting).
  2. Check each listed folder in a private browser window to confirm it now returns a normal page or a 403.
  3. Move any backups or spreadsheets out of the public web folder entirely. They should not be reachable at all.
AttentionWordPress XML-RPC is enabled
What it is

Your site has xmlrpc.php enabled. It is a legacy WordPress feature that lets an attacker attempt many password guesses in a single request, and it can be abused to help overwhelm your site.

Why it matters, the risk if you don’t

XML-RPC turns a slow password-guessing attack into a fast one, and has been used to knock small sites offline. If you don't use the Jetpack app or remote publishing, you almost certainly don't need it.

What to do
  • Confirm nothing you rely on uses XML-RPC (the Jetpack app and some remote-publishing tools do)
  • Disable it (a security plugin can switch it off, or your host can block access to /xmlrpc.php
  • If you do need it, restrict access to known IP addresses only
Step-by-step fix
  1. Check whether you use the Jetpack mobile app or publish remotely) if not, you don't need XML-RPC.
  2. Install a security plugin (Wordfence or iThemes) and switch XML-RPC off, or ask your host to block /xmlrpc.php.
  3. Confirm by visiting yourdomain.com.au/xmlrpc.php. You should get a 403, not "XML-RPC server accepts POST requests only".
AttentionYour server still accepts an outdated encryption protocol
What it is

Your server still allows TLS 1.0/1.1 connections alongside modern ones. These older protocols have known weaknesses and are no longer considered safe.

Why it matters, the risk if you don’t

Modern browsers won't use them, so removing them breaks nothing for real visitors, but leaving them enabled keeps a weakness available to anyone deliberately looking for one, and it fails most security questionnaires.

What to do
  • Ask your host or CDN to disable TLS 1.0 and 1.1 and require TLS 1.2 or higher
PassingExposed sensitive files
What it is

We probed for private configuration, admin and repository files being downloadable from your site and found none.

You’ve done this right

You've done this right, these are the files attackers scan for daily, and they often contain database passwords.

PassingDirectory listing on other folders
What it is

Aside from the two folders flagged above, no other folder on your site exposes a browsable file listing.

You’ve done this right

The rest of your site behaves correctly, visitors get a normal page, not an index of your files.

PassingLeaked API keys & secrets in your code
What it is

We scanned the code your site sends to every visitor's browser for exposed passwords and access keys, and found none.

You’ve done this right

You've done this right, a leaked key in front-end code can hand someone access to a connected service.

PassingExposed backup & config files
What it is

We checked the common locations where a full site backup or configuration file is accidentally left downloadable. Nothing was reachable.

You’ve done this right

You've done this right, a downloadable backup often includes your database password.

PassingPayment-skimming surface (script integrity)
What it is

We reviewed the third-party scripts your pages load. Nothing is loading in a way that would let a hacked script quietly read what customers type.

You’ve done this right

You've done this right (this is the attack that hit British Airways and Ticketmaster.

PassingInsecure cookies
What it is

The cookies your site sets carry the Secure and HttpOnly flags where expected.

You’ve done this right

You've done this right), it stops a logged-in session being hijacked or read by injected scripts.

PassingSubdomain takeover risk
What it is

We checked your DNS records for subdomains pointing at services that are no longer claimed. None were found.

You’ve done this right

You've done this right. An abandoned subdomain can be claimed by someone else and used to phish your patients from your own web address.

PassingExposed non-production subdomains
What it is

We looked for test, staging or development sites publicly reachable on your domain and found none.

You’ve done this right

You've done this right, staging sites are usually far less protected than the real one.

PassingExposed service ports
What it is

A safe, limited check of common administrative ports found nothing open to the public internet.

You’ve done this right

You've done this right (open admin ports are a direct route in.

PassingMixed content
What it is

Every resource on your secure pages loads over HTTPS), nothing is being pulled in insecurely.

You’ve done this right

You've done this right, mixed content quietly breaks the padlock your patients rely on.

PassingAdvanced email security (MTA-STS & TLS-RPT)
What it is

Your domain publishes MTA-STS and TLS reporting records, so mail to you is required to travel encrypted and you're told when it doesn't.

You’ve done this right

You've done this right (this is a step beyond what most small businesses have.

9 · Expert Review & Roadmap

👤 Reviewed by a specialist12 August 2026
AegorIQ specialist · Cybersecurity Specialist, AegorIQ · reviewed 12 August 2026
🗺 Remediation Roadmap Pro

Your Prioritised Action Plan

ActionPrioritySuggested timing
Update WordPress core, plugins and themes (back up first)Fix firstAs soon as you can
Publish SPF, DKIM and DMARC records for your domainFix firstAs soon as you can
Name your analytics and advertising tools in your privacy policyFix soonRecommended
Add the three missing security headersFix soonRecommended
Add your ABN to your website footerFix soonRecommended
Turn off directory listing on the two exposed foldersFix soonRecommended
Enable DNSSEC with your DNS providerOptionalWhen convenient (no rush
Add a consent checkbox and privacy link to your sign-up formOptionalWhen convenient) no rush
📋 Compliance Action Plan Pro

Legal Obligations & Deadlines

Privacy policy, disclose your tracking
Name the specific analytics and advertising tools running on your site, and add a short notice at the point of collection. The OAIC's 2026 determinations make clear a generic "we use cookies" line is not enough.
Automated decision-making disclosure
From 10 December 2026, businesses using automated decision-making must say so in their privacy policy. You told us you don't, no action needed now, but revisit if that changes.

7 · Conclusion

📊 Report Summary
This report was prepared on 12 August 2026 and reflects the security state of sampledental.com.au at time of scan. Findings should be reviewed periodically as your site and its tools change over time.
✔ What to prioritise
  1. Outdated or vulnerable WordPress components. Back up the site (files and database) before making changes
  2. No DMARC record. Your email domain can be spoofed. Ask your email or IT provider to publish SPF, DKIM and DMARC together
  3. Missing security headers (3 of 5). Add X-Frame-Options: SAMEORIGIN
Every check we ran

Below is every check included in your report: not just the ones that found something. A check that passed is a real result, and so is one we couldn't complete. We'd rather show you the whole list than let silence do the talking.

19 checked with no issue · 9 need attention · 3 for your awareness · 0 not tested · 5 not applicable to your site

Policies
Does the Privacy Act apply to you?
The Privacy Act applies to your business
For your awareness
Credit & financial information rules (Part IIIA)
You didn't tell us you collect financial or credit information, so the credit-reporting rules don't arise.
Not applicable
Customer accounts — do you hold customer logins?
Your site doesn't appear to offer customer accounts, so the obligations that come with holding login credentials don't arise.
Not applicable
Automated decision-making disclosure (from 10 Dec 2026)
You told us you don't use automated decision-making, so the new APP 1.7 disclosure rule doesn't arise.
Not applicable
Privacy policy — present and reachable
Checked, no issue
Privacy policy — what's inside it
We could not find a privacy policy to read — see the row above — so there was nothing to review here.
Not applicable
Refund wording vs Australian Consumer Law
Checked, no issue
Terms & Conditions published
No Terms & Conditions found
Needs attention
Shipping & delivery policy
You don't appear to sell physical goods, so a shipping policy isn't expected.
Not applicable
Business identity
ABN / ACN shown on your site
ABN not visible
Needs attention
Contact details visible
Checked, no issue
Business address / location shown
Checked, no issue
Sign-up consent (Spam Act)
A sign-up form collects details without a consent option
Needs attention
Email & domain
Email spoofing protection (SPF, DKIM, DMARC)
No DMARC record. Your email domain can be spoofed
Needs attention
Duplicate SPF / DMARC records
Checked, no issue
Registrar transfer lock
Checked, no issue
DNSSEC
DNSSEC is not enabled
Needs attention
Domain expiry
Domain expiry) a quick one to confirm yourself
For your awareness
Security
SSL certificate & HTTPS
Checked, no issue
Security headers (5 checked)
Missing security headers (3 of 5)
Needs attention
Malware & phishing blacklist
Checked, no issue
Known software vulnerabilities (WordPress)
Outdated or vulnerable WordPress components
Needs attention
Public exposure (CORS, exposed usernames)
Checked, no issue
Payment handling
Checked, no issue
Tracking
Trackers & analytics detected
Third-party tracking is not disclosed in your privacy policy
Needs attention
Cookie consent notice
Checked, no issue
Performance
Broken links
Checked, no issue
Mobile-friendly
Checked, no issue
Content freshness (is the site looking current?)
Checked, no issue
AI Readiness
AI crawlers can reach your site
Checked, no issue
Content readable without JavaScript
Checked, no issue
Structured data (Schema.org) for AI
No structured data for AI to read
For your awareness
Machine-readable business identity
Checked, no issue
Preview & summary metadata
Checked, no issue
Navigable by AI agents
Checked, no issue
Deeper scans (Deep Scan and Expert)
Exposed files, secrets, directory listing, ports, subdomain takeover, TLS strength, admin sign-in exposure, accessibility
Anyone can browse your website's folders
Needs attention

Not tested means exactly that. We tried and could not complete it. It is neither a pass nor a problem, and we will never let it quietly become one.

We don’t monitor your website. We just don’t disappear.

Fix something and re-scan to confirm it’s gone, free for 90 days. And if a rule changes, or a vulnerability turns up in software we saw running on your site, we may drop you a line: a courtesy based on what we found at the time of this audit, not ongoing monitoring.

About the compliance findings in this report

This report is advisory only. It is not legal advice, and AegorIQ is not a law firm.

Where we comment on your privacy policy, your refund and returns terms, or your ABN disclosure, we are reporting what our automated checks found in the text you publish: for example, that a policy does not appear to say how someone makes a complaint, or that refund wording uses language that is often a problem under the Australian Consumer Law. We are not reading your documents the way a lawyer would, and we are not ruling on whether you comply with any law.

Whether a particular obligation applies to your business, and whether your wording satisfies it, depends on facts we cannot see and on judgement a scan cannot make. Before you rely on, change, or decide not to change a legal document, get advice from a qualified Australian legal practitioner. Treat what follows as a well-informed list of things worth asking them about. That is exactly what it is good for.

The security findings are a different matter: those are direct technical observations of your site's configuration, and you can act on them with confidence.

Scope & limitations
  • This is an automated compliance and security scan, not a penetration test. It does not attempt to exploit, break into, or actively test your systems.
  • No scan is guaranteed to be 100% accurate or complete. The absence of a finding is not a guarantee that no issue exists.
  • This is a point-in-time assessment of what was publicly accessible at the address scanned on the report date. Your site, its configuration, and the applicable laws can change at any time.
  • Findings rely in part on information you provided (such as industry and turnover); their accuracy depends on that being correct and current.
  • This report is advisory only and is not legal, financial, or professional advice. Verify anything with a qualified professional before you act, change, or decide not to change something.
  • AegorIQ is independent and is not affiliated with, endorsed by, or acting for any regulator (OAIC, ACCC, ASIC, auDA) or the ACNC.
  • To the maximum extent permitted by law, AegorIQ (WNMC Holdings Pty Ltd) is not liable for any compliance breach, security incident, loss, or damage arising before, during, or after this scan. Nothing in this report limits any rights you have under the Australian Consumer Law that cannot lawfully be excluded.
📸 A point-in-time snapshot, and you can re-scan it free. No automated scan is ever 100% complete, and both your website and the checks we run change over time. This report reflects what we could read on 12 August 2026. Your purchase includes free re-scans for 90 days, so after you make a change, or any time you want the latest read, re-scan and we'll give you a fresh, up-to-date result at no cost. If a finding doesn't look right to you, reply to your report email and we'll re-check it against your live site.
Want this for your own website?

Start with the free Scorecard. A real audit that tells you how many issues we found and where. Or go straight to the full report.

Get your free Scorecard See pricing