Find out how your systems actually hold up.
Web application, API, external network, WordPress-specific and cloud configuration testing, run by people who also build and host these systems. You get a written report with severity, evidence and fix steps, not just a list of alerts.
The problem
A clean scan doesn’t mean a system is safe.
Automated scanners are useful and we run them too, but they only catch what’s already known. They miss chained issues, flaws in your business logic, and the specific way your app handles data. That’s exactly where a real attacker looks first.
Most businesses ask for a test when a customer, an insurer or a partner asks for one. Then they get stuck on what’s actually in scope: the website, the API behind it, the server it sits on, or all three. Getting that scope right matters as much as the test itself.
If your site is already hacked, this isn’t the page you need yet. Go to hacked site repair first. Come back here once it’s clean, to check the fix holds under real pressure.
What we test
Testing that covers where the real risk sits.
Web application testing
Logins, sessions, form checks and access rules, tested by hand against the OWASP Top 10 and ASVS as reference checklists.
API testing
REST and GraphQL endpoints tested for broken access rules, data leaks, and the gaps a browser-based scan never shows.
External network testing
Your public-facing servers, probed the way an outside attacker would find them, from open ports to exposed admin panels.
WordPress-specific testing
Plugin and theme flaws, weak settings, exposed endpoints and access issues specific to WordPress, on sites we built and sites we didn’t.
Cloud configuration review
Storage buckets, access rules and permission settings checked against common setup mistakes that leave data open by accident.
Retest after fixes
Once you’ve applied fixes, we retest the specific findings and issue a letter confirming what’s closed.
Process
How a test runs.
Scoping and ground rules
We agree what’s in scope, what’s off limits, test windows, and how far we go if we find a way in. Usually a day or two.
Recon
We map the target: the tech in use, exposed pages, subdomains and anything else public before a single test begins.
Manual testing plus tools
Tools flag the obvious. Most of the work is done by hand: testing logic, chaining small issues, and trying what a scanner never thinks to try. If your ground rules allow it we go further to show real impact, and if not we stop at proving the issue exists.
Reporting
Every finding gets a severity rating, proof and clear fix steps, plus a plain-English summary for anyone without a technical background.
Retest
Once fixes are in, we check they’ve closed the gap and issue a retest letter you can share with whoever asked for the test.
What you get
A report you can actually act on.
You get a summary written for a business owner or a board, a technical section with clear steps to copy each issue for your developers, proof such as screenshots and requests, and a retest letter once fixes are confirmed. Nothing arrives as a raw scanner export.
- Plain-English summary, with overall risk and what to fix first.
- Technical findings with severity, proof and steps to reproduce each one.
- Fix guidance specific to your stack, not a generic checklist.
- A retest letter you can hand to a customer, insurer or auditor.
If the fix sits inside a WordPress site or app we already host, we can often apply it directly rather than just describing it. If you’re working through PCI DSS compliance, this testing covers the yearly penetration test most merchants and service providers need as part of that process.
FAQ
Questions we get asked
How is this different from a vulnerability scan?
A scanner checks for known issues and setup mistakes on its own, in minutes, and produces a long list with plenty of false alarms. A penetration test is a person actively trying to get in: chaining small issues together, testing your real business logic, and working out what an attacker could really do. We use scanning tools as one input, not as the whole test.
How long does a test take?
A single web application or API usually takes a few days of active testing. A larger scope, like an external network plus a web app plus a mobile API, runs longer. We’ll give you a real estimate once we know what’s in scope, and we always agree the testing window with you before we start.
Will testing break anything?
We agree ground rules before a single request goes near your systems: what’s in scope, what’s off limits, and how far we go if we find a way in. Testing that could break something only happens if you’ve clearly asked for it. Outside that, the risk is low but never zero, which is exactly why we agree it up front.
Should we test staging or production?
Either can work. Staging is lower risk if it’s a true copy of production, but a test only tells you what’s true for the system you tested. Production testing shows you the real, current attack surface, including anything staging doesn’t quite match. We’ll help you weigh that up for your setup.
What access do you need?
For most tests, none beyond the target’s public address, which matches what a real attacker sees. If you want a deeper, logged-in review, we’ll ask for a standard user account or two, and sometimes a read-only admin account, so we can test what’s reachable once someone’s logged in.
Do you retest after we fix things?
Yes. Once you’ve worked through the findings, we retest the specific issues we raised and confirm what’s actually closed. You get a short retest letter you can hand to a customer, an insurer or an auditor as evidence the fixes landed.
What standards do you test against?
We use the OWASP Top 10 and the OWASP Application Security Verification Standard as reference checklists for web and API testing, alongside our own experience of how real WordPress and custom builds get attacked. These are testing frameworks we work from, not certifications Maku holds, and we won’t claim otherwise.
Security
More Security services
-
PCI DSS compliance
Scoping, gap assessment and remediation to get you compliant and keep you there.
-
PCI consulting
Ongoing advice for merchants and service providers: SAQs, scope reduction, evidence, audits.
-
Application licensing
Licensing, implementation and support for security platforms, quoted and managed through one team.
Engage
Building something ambitious?
Send us a few honest paragraphs about what you’re building, who it’s for and when you need it live. We’ll reply with a straight answer.