Add-on or standalone

Attack Surface Assessment

A focused look at your website and web applications from an attacker's perspective — scanning for OWASP vulnerabilities, misconfigurations, and publicly exposed weaknesses that could be exploited without ever touching your internal network.

What attackers see when they look at your business online.

Your website, booking form, customer portal, or e-commerce checkout is often the first thing an attacker examines. These public-facing applications can contain vulnerabilities that give an attacker a foothold into your business — without a password, without phishing anyone, and without you ever knowing.

The Attack Surface Assessment scans your web presence using the OWASP (Open Web Application Security Project) framework — the industry-standard checklist for web application security — and looks for the most common and dangerous classes of vulnerability.

Up to 3 domains included. This covers your primary domain plus up to 2 additional domains or web applications. Each domain can include its associated subdomains and web pages — the surface area adds up quickly, which is why scope is set at 3 domains rather than an arbitrary page count.

Why this matters for small businesses

Attackers don't manually target small businesses — automated scanners look for known weaknesses across millions of sites simultaneously. If your website has a vulnerability, it will be found. The question is whether you find it first.

Even simple sites can have serious issues

A basic WordPress site with a contact form, a WooCommerce store, or an online scheduling system can have serious vulnerabilities. Plugin versions, form handling, and login pages are common weak points — and they're exactly what we check.

Passive scanning only

Our assessment is non-destructive. We scan and probe — we don't exploit. We will never cause downtime, delete data, or disrupt your site.

What we check.

OWASP Top 10Injection, broken authentication, sensitive data exposure, access control issues, security misconfigurations, XSS, and the full OWASP Top 10 (2021) framework.
SSL/TLS configurationCertificate validity and expiry, protocol versions (TLS 1.0/1.1 flagged), cipher strength, HSTS enforcement.
Security headersFull analysis of Content Security Policy, X-Frame-Options, HSTS, referrer policy, and other protective HTTP headers.
Exposed admin interfacesLogin pages, admin panels, and management interfaces that are publicly accessible without additional protection.
CMS & plugin vulnerabilitiesWordPress, Joomla, Drupal core versions and all installed plugins checked against known CVE databases via WPScan.
Information disclosureServer banners, verbose error messages, directory listings, and exposed files that provide useful intelligence to attackers.
Domain & DNSSubdomain enumeration and validation, dangling DNS records, domain hijacking risks.
Domain scopeUp to 3 domains, each including associated subdomains and web pages in scope.
Plain-language reportEvery finding explained clearly, rated by severity, with a concrete remediation step and the specific OWASP category referenced.
Results walkthroughA video call to walk through every finding and discuss which issues to prioritize.

Scope boundaries.

How this differs from the Security Assessment: The Security Assessment includes a basic web awareness check — SSL grade, platform identification, admin panel reachability. The Attack Surface Assessment goes significantly deeper: full OWASP testing, WPScan CVE analysis, complete header analysis, form testing, and detailed subdomain analysis. They're additive, not redundant.

How the assessment works.

Non-destructive, passive scanning that doesn't interrupt your site or applications.

01

Scope and authorization

We confirm which domains and applications are in scope, and you provide written authorization. We never scan anything outside of what's agreed.

02

Scanning and analysis

We run automated scanning tools against your web properties and manually review findings to eliminate false positives and add business context.

03

Report and review

Plain-language report delivered within 48 hours, followed by a video call to walk through every finding and prioritize next steps.

Often paired with.

Simple, transparent pricing.

Standalone
$400
up to 3 domains
  • Up to 3 domains with subdomains
  • OWASP Top 10 + full configuration checks
  • Plain-language report
  • Results walkthrough call

Need more than 3 domains? Contact us for a custom quote.

See what attackers see.

Find out what your website and web applications are exposing before someone exploits it.

Get started →