🚨 Hacked right now? Don’t read the rest of this page. → RESCUE — we stop the bleeding in 15 minutes. Free. No card.  ·  In a nutshell ↓

Is Someone Living In
Your Website Right Now?

Not “has it been defaced”. Defacement is the loud, stupid minority. The real question is quieter than that. Is there someone inside it, right now, behaving themselves? A site that loads perfectly. Ranks fine. Takes orders. And has a tenant.

Because a site that behaves normally is a site nobody investigates. So we built a path that looks. One certificate at the end of it. One operator on the hook the whole way. You start at stage one. Everybody does. It costs nothing.

A camp bed and sleeping bag set up in the aisle of a server room, lived in for weeks
A clipboard on a workbench holding a sheet of ten blank ruled lines under a green lamp

The Whole Ladder,
In Ten Lines.

  • Four stages. Skip one and the chain breaks. No certificate without all three paid stages current.
  • One way in: the free scan. You can’t buy stage three cold. Not because we won’t take your money. Because a fix built on a guess isn’t a fix.
  • Preventative path: Free Scan $0 → Deep Audit $485 → Optimisation $985 → Overwatch from $360/mo → Certified.
  • Hacked path: Free 15-minute holding page → Deep Audit $485 → Recovery from $1,485 → Overwatch from $360/mo → Certified.
  • After every fix, we turn the tempo up for a fortnight and watch for reinfection. That fortnight is the proof, not the invoice.
  • The Certificate of AI-Era Cyber Due Diligence is earned, not bought. Let Overwatch lapse and it revokes the day Overwatch ends.

✅ One operator. One bill. One throat to choke.

You can stop after any stage and still be better off than you started. Nothing moves to the next stage without you saying so.

You don’t have a CISO. You’ve got a business to run, a phone that rings, and a website somebody built for you a while back. The ladder exists so you never have to become a security expert to be defensible — you just have to start looking.

Why This Is A Path
And Not A Product.

A worn dirt track winding away through dark scrub at night

Here’s the thing about how WordPress security is normally sold. You get sold one item. A plugin. A scan. A once-off cleanup. Then everyone shakes hands and goes home.

That worked when the patch window was 63 days wide. It doesn’t work now.

63 days
How wide the patch window used to be. Every piece of advice you have ever been given about updates was built for that number.

Five hours
Median time from a WordPress vulnerability being disclosed to being exploited [Patchstack 2026].

Minus seven days
The mean — exploits running in the wild before the patch even ships [SecurityWeek 2026].

Read that again. Before the patch ships.

Which brings us to your web guy. He’s a good bloke. He logs in every so often, clicks “update all”, watches the spinner, and tells you it’s handled.

It isn’t handled. It was never handled. Clicking update is housekeeping. It isn’t security, and on a five-hour window it isn’t even fast.

⚠️ Patchstack say it plainly themselves.
“Regular plugin updates are no longer a viable defence.” Each stage below only makes sense because of the one before it. A scan tells you a door is unlocked. An audit tells you which doors, and what’s behind them. Optimisation locks them and then tries to kick them back in. Overwatch keeps them locked while the world invents new keys. Take a link out and the rest isn’t weaker — it’s unfounded.

The Real Threat Isn't The Most Powerful Model.
It's The Jailbroken One.

A cheap appliance on a bench with its safety interlock defeated by a bent paperclip

There’s a story going around that the danger is frontier AI. The big expensive models. The ones governments get briefed about.

Forget it. That’s not what’s coming for your plumbing business.

Here’s what actually is. A cheap, off-the-shelf model. Jailbroken by someone who isn’t clever. Rented for about the price of two coffees. Running exploits that are already public. Not zero-days. Not secrets. Published, catalogued, indexed holes that anyone can look up right now, for free.

Those exploits have been sitting in the open for years. So why does it matter this year? Because of the one thing that used to stand between them and you. Skill.

Knowing which three low-severity findings chain into one catastrophic one — that took a person who knew what they were doing. That was the barrier. That barrier is what kept the volume down.

The barrier is gone. The model does the chaining now. Cheaply. At scale. All night, every night, without getting bored, tired or discouraged. What used to need a skilled human needs a subscription and a prompt.

So the attacker isn’t a genius. That’s the point. It doesn’t have to be.

And this is where “I’m too small to be worth attacking” quietly stops working. You were right, for years. You weren’t worth a skilled human’s evening. Nobody was ever going to sit up until 2am for your booking form.

⚠️ But nothing selected you.
Something scanning everything simply arrived at your address, tried the handle, and wrote down what it found. Volume, not selection. Being small was never camouflage — it just meant nobody was checking. Which is why the four stages below start with looking, and why looking costs nothing.

A brass spyglass lying closed on a dark slate table under a green light

Stage 1 — Free Scan.
$0.

The reality check. Paste your URL. Sixty seconds. No signup, no credit card, no “book a discovery call with our solutions consultant”.

We fingerprint your site from the outside the exact way an attacker does in their first minute. Same order. Same tools.

What it looks at:

  • Outdated plugins and themes matched against CVE data from Wordfence Intelligence, cross-checked against the WordPress.org release data
  • Visible malware, spam injections, phishing redirects
  • SSL and security-header misconfigurations
  • WordPress version, open ports, xmlrpc.php exposure
  • Google Safe Browsing, Norton and McAfee blacklist status

Two different questions get asked of every component. Has somebody published a hole against the exact version you’re running? And how many releases behind is that version? A plugin four releases back is carrying every quiet fix in those four releases — and nobody has to publish anything for that to matter.

✅ No login. No card. No obligation.

Maya walks the results with you in live chat. What each finding means, what it’s worth to an attacker, what to do next. No pressure, and no way to skip ahead.

Now here’s what it can’t do. It can’t see inside your code. Nothing external can. The back door isn’t on the front page. It’s in the plugin. In the theme. In wp-config.php. Plenty of compromised sites look completely fine from the street — that’s the whole point of them.

A green tick from any external scanner means “recognised nothing”. It does not mean “nothing there”. Clean-to-a-scanner is the floor. It is not the finish line.

Why this can’t be where it ends → Because you’ve now got a list of eight outdated plugins and no idea which one is currently being lived in. A finding is not a diagnosis. To know whether anything is actually resident, someone has to read the code — and that’s stage two.

(Full scanner stack detail on /free-scan.)

Stage 2 — Deep Audit.
$485.

Stage one looked at the outside. Stage two reads the inside. Every line.

And then it does the thing nobody else will do for a small business: we run the actual attack. Their tools. Their chains. Their patience.

On a sandbox clone of your site. Never on your live one. Your customers never see a flicker.

A bench magnifier positioned low over an open blank ledger, throwing a bright circle on the page

What you get:

SAST, static analysis — every line of code read carefully, without running it. Plugins, theme, custom code, wp-config.php, .htaccess. Which means the backdoor that only wakes up on the 14th of the month gets found sitting still.

DAST, dynamic analysis — the live attack surface probed the way an attacker probes it. On the clone.

Long-chain exploit analysis — A plus B plus C equals credential theft. Three findings that are all “low” on their own and catastrophic in sequence. Single-tool scanners miss this entirely, because they grade findings one at a time.

The full stack, in parallel — an autonomous AI pentester, an in-house multi-step exploit-chain analyser, an adversarial AI auditor whose only job is to disprove our own findings, and a three-agent audit framework. Twenty findings means twenty deep-dives running at once.

A branded PDF report — nine pages. Severity-grouped. Plain-English chain narratives. Signed and dated.

Maya walks you through every finding — what it is, what it can do, what we’re going to do about it. For as long as you need.

First hash on the certificate chain — the audit is where the custody chain starts.

✅ On a sandbox clone. Never on your live site.

Why this can’t be where it ends: a nine-page report of everything wrong with your website is, on its own, the worst thing we could hand you. You now know. You’re now on notice. And nothing is fixed. (You can’t book the audit cold, and we won’t take the booking. It runs after your scan, because the scan is what tells us how to scope it.)

Stage 3 — Optimisation.
$985.

Stage two found it. Stage three fixes it, hardens the things it didn’t find, and proves the patch survives attack before anything touches your live site.

Your code is pulled to our hardened review box. Every confirmed finding fixed. The database sanitised, hidden admin accounts removed, SEO spam stripped, backdoors killed. Credentials reset, because if someone’s been resident they have your logins — changing the password on the front door while they’re sitting in the lounge room is theatre. Then the hardening pass, and two gates: the patched clone is re-attacked by all four frameworks and all four must come back clean, and a pixel-diff against baseline on desktop and mobile, because a hardened site is no good to you if the homepage now looks like a ransom note.

The two weeks after the fix. That’s the actual proof.

Here’s the thing about a skilled compromise. It doesn’t sit in one file you can delete. It’s resident. Backdoors that reinstall themselves. A dormant cron job that quietly rewrites the payload four days later. Code whose entire job is to bring the infection back once the cleaner’s gone home.

So a green scan on the afternoon of the fix proves almost nothing. It proves the cleaner left. That’s the cleaner we’re not.

After we ship a fix, we turn the testing tempo up for the fortnight that follows. Nothing stirs in fourteen days — that’s your clean bill, earned across a fortnight, not claimed on day one. Something wakes up — good. It just showed us where it was hiding. We go back in, close it, and the clock restarts. Free.

✅ That elevated watch is what the Clean Bill Guarantee actually is.

Not a sentence in a terms page. Fourteen days of us not taking your word for it, and not asking you to take ours. Eleven-page report, FAILED-TO-BREAK stamped on every remediated finding, certificate hash updated. Then the fortnight ends — and the internet doesn’t. That’s stage four.

A thick steel plate bolted flush over an opening in a concrete wall

The Hacked Path — When
Stage 3 Becomes Recovery.

If you’re already compromised, the shape is the same. The middle stage is just bigger.

1 · Free 15-minute holding page. No charge, no card, no contract. Maya triggers it the moment you hit /rescue or ring. A single .htaccess rule drops onto your web root and redirects every page to a holding page on our server. Visitors see “under maintenance” and a contact form that emails leads straight to your inbox. No DNS change. SSL stays valid. Your URL stays live. Your phone keeps ringing.

2 · The $485 Deep Audit. We map the actual breach. Not the theoretical attack surface — the real entry point, and the blast radius behind it. What they touched. What they could reach. What they took. You get an evidence log. Not a list of files we deleted. Not a green tick.

3 · Recovery, from $1,485. Clean, restore, and pro-hardening — all included. On the hacked path the hardening lives inside Recovery. It is not a separate $985 line. Then the part that matters most on a site that’s actually been lived in: the two-week elevated-tempo reinfection watch.

4 · Overwatch, from $360/mo. Same as the preventative path. The fortnight’s watch settles into it.

✅ The bleeding stops while we work. You pay nothing for that part, ever.

Why this can’t be where it ends: a site that’s been broken into once is a site that’s on a list. They came back to sweep it — for wallets, saved logins, API keys, session tokens. That sweep is scheduled, not opportunistic. Cleaning the site doesn’t take you off the list. It just makes the next visit disappointing. (Full hacked-path detail on /rescue.)

A loaded tool trolley wheeled up to a damaged doorway in a dark building
A rooftop anemometer turning steadily against a black night sky

Stage 4 — Overwatch.
From $360 A Month.

(Site-size dependent. S/M/L tiers on /pricing.)

Everything up to here was a point in time. This is the part that runs. And it’s a different job to scanning. A scanner asks “do I recognise anything bad?” Overwatch asks a better question: “did something mundane move that had no business moving?”

An off-schedule file change. An admin account nobody created. A cron job nobody scheduled. Outbound traffic to somewhere with no reason to hear from you. That’s how you catch residency. Not by recognising the malware. By noticing the tenant.

Running 24/7:

  • File integrity monitoring
  • Honeypot trap network
  • Uptime and reputation monitoring
  • Plugin/theme CVE watch — Wordfence Intelligence, cross-checked against the WordPress.org release data
  • Traffic anomaly detection
  • Database integrity checks
  • Backup verification — because a backup nobody has ever restored isn’t a backup, it’s a folder
  • Patch velocity tracking
  • Monthly automated pentest sweep — short, jittered, unannounced
  • Quarterly deep pentest sweep on a sandbox clone — timing jittered and never published, including to you. An attacker doesn’t book in. Neither do we.

✅ $250 active fix budget every month.

The second we find something, we move — we don’t email you a quote and wait. The pool tops back up automatically when it drops to $50. Minutes from detection to containment. Around the clock. You pay us, it’s taken care of. That’s the entire arrangement.

Four minutes. Not four weeks.

We know what that number is because we went and got it. We built a real website and deliberately left it un-updated and un-hardened — the exact state most people are in the day they first ring us. Not carelessness. A test target. You cannot find out whether your gear catches a live intruder by testing it on a clean site.

It got infected. Found the moment it went live, precisely as predicted. Then we switched Overwatch on. It flagged the intruder in about four minutes.

Four minutes. Not four weeks. Not “we’ll mention it in the monthly report”. A quiet tenant on a site that looked completely normal, surfaced before the kettle boiled. That’s not a brochure claim. That’s our own tooling, checked against a real infection, in the same conditions you’ll be in.

Silent fix deployment. The only thing worse than being hacked is being told you were hacked by the company you pay not to let it happen. So we fix it. You sleep. It appears in the monthly report with the evidence log attached. Every customer-touching change still goes through the visual pre-ship gate first.

(Full module breakdown and S/M/L pricing on /overwatch.)

The Certificate. Why All Three
Paid Stages, No Exceptions.

The Certificate of AI-Era Cyber Due Diligence is not a product. There’s no button that buys it. You earn it by completing — and currently maintaining — all three paid stages:

1 · $485 Deep Audit — the first hash on the chain.

2 · $985 Optimisation — or Recovery from $1,485 on the hacked path. Recovery includes the hardening, so it counts the same.

3 · Overwatch from $360/mo — and it must remain current.

Skip a stage and you don’t get one. Lapse Overwatch and it revokes the day Overwatch ends.

People ask why we’re rigid about this. Here’s why. A certificate that can be bought without the chain behind it is worth precisely nothing to the insurer, the tribunal or the client’s procurement team — which means it’s worth nothing to you, on the one day you actually need it.

The value isn’t the paper. It’s that the paper can’t be obtained any other way.

✅ Dated. Hashed. Signed.

With a live verification badge on your site anyone can click to confirm status in real time. And behind the cover page: timestamped logs. Every plugin update applied. Every alert that fired and how it was resolved. Every patch attacked off-site before it went anywhere near live. The cover page is paper. The logs are the proof.

The internals of a three-lever lock with all three levers thrown at once

The Part Nobody Else
Will Say Out Loud.

What we can’t promise.

We can’t make your website hack-proof. Nobody can. There’s no lock that can’t be picked and no site that can’t be probed. Anyone selling you a “hack-proof” website is either lying to you or doesn’t understand what they’re up against.

We can’t promise the lawsuit gets dropped, the insurer pays out, or the regulator files your breach under “no further action”. Those are decisions made by other people, and any vendor who tells you otherwise is telling you a story.

We can’t sell you a feeling of safety. Half this industry runs on exactly that. We’re not selling you that feeling.

So here’s what we will stand behind. All four of these, every time.

✓ You’ll know in minutes, not months.

✓ There’ll be a clean backup to rebuild from — one that’s been verified, not just created.

✓ There’ll be an evidence trail: how they got in, and how far they could reach. Not a shrug and an invoice.

✓ And you won’t find out from an angry customer’s solicitor.

That’s not a smaller promise than “you’ll never get hit”. It’s the only one that’s true.

✅ We don’t promise outcomes. We hand you the strongest possible position.

When something does happen, you’ll be in a far better position than almost anyone else it happens to. Documented. Defensible. Evidence-backed. Years of receipts, timestamped, sitting behind a certificate anyone can verify. Nobody else hands you the receipts.

A single microphone on a stand in a bare empty room lit green
A single brass key lying alone on dark slate under a soft green light

In A
Nutshell.

  • The risk isn’t defacement. It’s a quiet tenant on a site that loads perfectly normally.
  • You don’t get selected. You get found — by something cheap, automated and relentless.
  • We run one path, in order: look, then read the code, then fix it, then never stop watching.
  • You can’t skip a stage and you can’t buy one cold. The certificate is earned through the chain.
  • It starts with one URL, sixty seconds and no credit card.

✅ It starts with one URL, sixty seconds and no credit card.

You don’t have to decide anything else today. You just have to look.

Your move. The path starts at stage one. It always does. One URL, sixty seconds, zero dollars, no card.

Maya’s on live chat 24/7, bottom-right of every page. And if your site is on fire right now, don’t start at stage one — hit RESCUE and we’re moving inside 15 minutes.

P.S. If you take one thing off this page, take this. A green tick from a security scanner means “recognised nothing”. It does not mean “nothing there”. The question was never “have I been defaced”. It’s “is someone living in it right now — and would I know?”

Why You, Specifically, Are A
Sitting Duck This Week.

A lone waterbird sitting motionless on flat black water at night under a hard red light

You weren’t chosen. That’s the bit worth sitting with for a second. Nobody looked at your business, weighed it up, and decided you were worth an evening’s work. Something automated went past, tried the handle, and the handle turned.

And the thing trying handles doesn’t have to be clever any more. It’s cheap. It’s rented. It’s running exploits that are already published, already catalogued, already sitting in a list anyone can read over breakfast. Finding them was never the hard part. Knowing which three to chain was the hard part. That’s the part that used to need a person.

So now it just runs. All night. Every night. Across every site it can reach, in whatever order it finds them. It doesn’t get bored at 2am. It doesn’t skip you because you’re a two-ute plumbing business. It knows one thing about you: your plugin is three versions behind. That’s the entire conversation.

Now add the timing, because this is the part almost nobody has been told. The day you switched HTTPS on, your domain was published to a public list. Certificate Transparency. It’s mandatory — it’s how the padlock works — and it’s readable in real time by anyone. Automated scanners read that list and probe brand-new sites within seconds.

Which means the loudest announcement your website ever makes goes out on the exact day it’s least finished. Default settings. Temp passwords. Nothing hardened yet. The doors still open because the builder hasn’t left. They know you’re there, and they know you’re not done.

⚠️ Small was never camouflage.
It only ever meant nobody was checking. The real threat isn’t the most powerful model — it’s the jailbroken one, and it has already been past your address. The only open question is whether anybody has looked at what it found.