Cybersecurity / hardening
Your application has accumulated security debt: old plugins, exposed APIs and secrets in code. I deliver an audit with a prioritized hardening plan and fixes in auth, headers, dependencies and server. This is not theater pentesting: I identify real business risks and fix them or give you the plan. Ideal before a launch, client audit or after an incident.
- Ideal for
- Companies with web applications in production that need to reduce risk before a launch, client audit or after a security incident.
- Typical timeline
- An audit with basic hardening is completed in 2 to 3 weeks; projects with deep remediation may extend to 4–5 weeks.
Benefits
- Review of authentication, roles, permissions and attack surfaces
- Hardening of HTTP headers, CORS, CSP and TLS/SSL configuration
- Audit and update of dependencies with known vulnerabilities
- Review of secrets, environment variables and credential management
- Analysis of exposed APIs, rate limiting and input validation
- Prioritized report with quick wins, roadmap and post-fix verification
Frequently asked questions
Is this a pentest or a code audit?
It is a practical OWASP Top 10-oriented audit: I review code, configuration, dependencies and attack surface. I do not simulate advanced network attacks, but I identify and fix real vulnerabilities.
Do you fix vulnerabilities or only report them?
Both depending on agreed scope. I always deliver a prioritized report; in most projects I also implement quick wins and critical fixes directly.
Does it include WordPress and plugin security?
Yes. I review outdated core, plugins and themes, file permissions, wp-config, unnecessary admin users and server configuration. I propose hardening without breaking functionality.