Websites for practices and small businesses, live in under 2 weeks. Get a quote →
marketing@eterni.tech Book a 15-minute call ↗ Toronto · Working with businesses across the US & Canada

Penetration testing · WordPress security · SecOps

We find the holes, then we fix them

Penetration testing, vulnerability fixes and WordPress security from a team that builds websites for a living. Most security reports end with a list of problems. Ours end with the problems fixed and re-tested.

Manual testing, done in-house Mapped to OWASP, rated with CVSS Fixed by developers, re-test included Fixed quote, NDA on request
The security loop: find, fix, verify, keep, then round again.
One sheet, four folds. Every finding goes all the way round.

How it works

Find, fix, verify, keep

Security firms test. Developers build. We do both, so a finding goes from discovered to closed without changing hands.

  1. Step 01

    Find

    Penetration testing and vulnerability assessment, manual and automated, against your live site or a staging copy.

  2. Step 02

    Fix

    Our developers patch, replace or rewrite whatever is vulnerable. You get fixes, not just a list of problems.

  3. Step 03

    Verify

    We re-test every finding after it’s fixed, and the report shows it closed.

  4. Step 04

    Keep

    Ongoing security operations: patching, access reviews and checks every month, so it stays closed.

The report

What a finding looks like

Every finding in our reports reads like this: what we found, where, why it matters, how it was fixed, and proof that it’s closed.

  • Rated with CVSS, so priorities aren’t a matter of opinion
  • Evidence and steps to reproduce for your developers
  • A plain-English summary for everyone else
F-04 High · CVSS 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Any customer can read and delete other customers’ form submissions

Where
A custom plugin’s AJAX actions: admin-ajax.php?action=get_submission&id=1043
What we found
The action checks that you’re signed in, but not that the submission is yours. Changing the number returns anyone’s submission, and a second action deletes it.
Why it matters
Names, emails and messages from every customer were readable by any account holder. A scanner wouldn’t catch this; it needs a person who tries it.
Fix applied
Ownership and capability checks added to both actions, nonces enforced, and IDs replaced with unguessable tokens. Tested on staging, then deployed.
Re-test
Not reproducible with any test account. Closed.

Example finding, written for this page. It isn’t from a client report.

Why developers who test

Scanners find, auditors report, we fix

Scanners and audits are useful. But a list of problems doesn’t make anyone safer until someone fixes them, and that’s usually where things stall.

What you getA scannerA report-only auditEternitech
Known vulnerabilities in plugins and softwareYesYesYes
Manual testing of logins, access control and business logicNoYesYes
Findings explained in plain English, ranked by riskNoYesYes
Fixes applied by developersNoNoYes
Every fix re-tested and the report updatedNoOften extraIncluded
Ongoing patching and checks afterwardsNoNoOptional retainer

What we test

Twelve places attackers look first

Coverage follows the OWASP Web Security Testing Guide and the OWASP Top 10, adjusted to what you actually run.

  1. Authentication, sessions and password reset flows
  2. Access control and privilege escalation
  3. Injection: SQL, cross-site scripting, template and header injection
  4. Plugin, theme and core vulnerabilities (known CVEs)
  5. REST API, XML-RPC and AJAX endpoint exposure
  6. User enumeration and information disclosure
  7. File upload handling and remote code execution paths
  8. Server-side request forgery (SSRF)
  9. Security headers, content security policy and TLS
  10. Server, PHP and web server configuration
  11. Backups, recovery and admin account hygiene
  12. Third-party scripts and tracking on sensitive pages

Hacked right now?

Don’t panic, don’t delete anything

Spam pages in Google, a strange redirect or a warning from your host: here’s what to do in the first hour, while we get started.

  1. 01

    Don’t delete anything yet

    Logs and changed files show how they got in. Without them, it often happens again.

  2. 02

    Change passwords from a clean device

    Hosting first, then WordPress admins, SFTP, the database and email.

  3. 03

    Copy the site as it is

    Files and database, infected or not. It’s evidence, and a fallback.

  4. 04

    Tell us what you’ve seen

    Screenshots, browser warnings, emails from your host. Message us and mark it urgent.

Start here

Request a security assessment

Tell us what you run and what worries you. We’ll reply with a scope, dates and a fixed price in writing, and you decide from there.

  • A reply from the people who’ll do the work
  • Scope, dates and a fixed price before anything starts
  • An NDA before we start, if you want one
  • Nothing is tested without written authorization

Urgent? Message us on WhatsApp ↗

How urgent is it?

Please don’t include passwords, keys or full findings. We use your details only to reply. Privacy

Questions

Straight answers

Anything else: marketing@eterni.tech

Do you do the penetration testing yourselves?

Yes. Testing is done in-house by our own team, by hand and with automated tools, and the same team fixes what it finds. Nothing is handed off.

Will testing break my website?

Testing is non-destructive by default, and anything risky is done on a staging copy or in an agreed window. We never run denial-of-service tests or touch data we don’t need to.

Do you only report problems, or fix them too?

We fix them. That’s the point of hiring developers who test: findings go straight to the people who can patch them, and every fix is re-tested before we call it closed.

What do you need from us?

Written authorization for the systems in scope, a contact for urgent findings, and, for deeper testing, a test account at each user level. We can also test from the outside with no access at all.

How long does an assessment take?

It depends on the scope. A typical WordPress site takes a few days to test properly; larger web apps take longer. You get the scope, dates and a fixed price in writing before we start.

My site has been hacked right now. What do I do?

Contact us straight away on WhatsApp or email and mark it urgent. Don’t delete anything yet: logs and changed files help us find how they got in, so it doesn’t happen again.

Is our information kept confidential?

Yes. Findings are shared only with the people you name, reports are sent securely, and we’re happy to sign an NDA before we start.

Do you work with healthcare practices?

Yes. We secure practice websites and test the parts that touch patients, like booking and intake forms. We don’t certify HIPAA compliance; we help keep patient data out of places it shouldn’t be, and we’re glad to work with your compliance lead.

Do you only work on WordPress?

WordPress is our specialty, but we test and secure custom web apps and other platforms too, including the servers they run on.

Next step

Find out what an attacker would find

Tell us what you run. We’ll reply with a scope, dates and a fixed price, and you decide from there.

Projects: marketing@eterni.tech Everything else: contact@eterni.tech