Hacked right now? The bleeding stops in 15 minutes. Free. · In a nutshell ↓
Your Site Scanned Clean The Day It Was Fixed.
That Proves Almost Nothing.
Stage 3 — Optimisation & Remediation. $985. For Australian small-business sites that have already been through the $485 Deep Audit.
The fix is the easy half. Anybody with a screwdriver can patch a hole. The hard half is finding out, over the next fortnight, whether something you couldn’t see was waiting for the cleaner to leave.
That’s the half we do. And it’s the half nobody else sells.
The Real Threat Isn't The Cleverest Model.
It's The Cheapest One.
People picture a genius in a hoodie. Forget that. Nobody needs a clever attacker to take apart a neglected WordPress site. They need a cheap one that never sleeps. Here is the actual chain.
1 · The holes were never secret
Every serious WordPress vulnerability gets published, catalogued and given a number, in public, so the people running that software can go and patch it. That is how the industry has always worked. The list is open to everybody — including them.
2 · Chaining them was the real barrier
Knowing that this outdated plugin, plus that loose file permission, plus that one forgotten admin account, adds up to somebody standing inside your site. Working out the order. Trying it, failing, trying the next one. That took a person with real skill, real time and real patience. It was the only thing that was ever protecting you.
3 · And that barrier is gone
A cheap, jailbroken, off-the-shelf model does the chaining now. Badly, sometimes — doesn’t matter. It does it for almost nothing, against thousands of sites at once, all night, and it never gets bored and never decides your business is too small to bother with.
4 · So it’s volume, not selection
Nobody chose you. Something automated swept everything with a domain name, found a version number it recognised, and started working. Being small isn’t what saves you from that. Being small is what made you cheap to try.
That shift is why “we ran a scan and it came back green” is a much thinner statement than it used to be.
You Can't Buy This One Cold.
On Purpose.
There is no “add to cart” on this page. There never will be. Optimisation is Stage 3, and you get here in one order, every time.
- The free scan. What a stranger can see from outside your site today. No card, no credentials, about ten minutes.
- The $485 Deep Audit. What is actually there — with your credentials, in your files. It names the full scope, and your Optimisation price with it.
- Optimisation, $985. Fixes exactly that list, then has to defend the fix against a record of what the site looked like before anyone touched it.
That is not an upsell ladder. It is a chain of custody. Every stage establishes the facts the next stage is built on.
Skip a link and the chain breaks. Not “less ideal”. Breaks. Because a fixer who can’t tell you what the site looked like the day before he arrived is guessing about what he changed — and a guess is not evidence.
We don’t fix blind. That is the whole reason the ladder exists.
The Cleaner Who's
Gone By Friday
You know how this normally goes. Something’s wrong. You ring a bloke. He logs in, clicks “update all”, deletes a few files that looked dodgy, installs a plugin with a shield icon on it. He runs a scan. It comes back green. He sends the invoice. He’s gone by Friday. And for about eleven days, everything is fine.
Here is what he never checked. A serious compromise isn’t a file. It’s a tenant — someone living in the building. And a tenant who has been there a while doesn’t keep everything in one room.
WHAT A GREEN TICK SAYS
✓ “The scanner recognised nothing this afternoon.”
WHAT A GREEN TICK DOES NOT SAY
✗ “There is nothing there.”
✗ “Nobody is still living in the building.”
✗ “Everything was actually reachable and actually tested.”
Those are wildly different sentences, and the entire cheap end of this industry is built on you not noticing the difference. On the afternoon of the fix, of course the scanner comes back green. Nothing is moving.
Three things a Friday scan will not find
A second backdoor in a folder nobody opens, whose only job is to put the first one back. A scheduled task sitting quietly in the database doing nothing at all, waiting for a date that hasn’t arrived yet. Code that checks whether anyone is watching before it does a single interesting thing.
Turns out “quiet” and “clean” look identical for about a fortnight. That isn’t a coincidence. That’s the design.
We Don't Leave On Friday.
We Turn The Volume Up For Fourteen Days.
Here is the bit that makes this page different from every other remediation page in Australia. The day we finish the work is the day the real test starts.
We don’t scan you once, wave the green tick around and disappear. The moment the fix goes live we turn the testing tempo up — and hold it there for a fortnight, watching for exactly one thing. Did anything survive, and try to come back?
Why fourteen days and not fourteen minutes. Because that is the window the quiet stuff works in. A dormant task doesn’t fire on demand; it fires on its schedule. A reinstaller doesn’t announce itself while the lights are on; it waits for the site to go back to normal. You cannot catch that with one scan on the day. You catch it by still being there after everyone is supposed to have gone home.
There are only two ways this ends, and you win both of them.
- Nothing stirs for fourteen days. That is a clean bill earned across a fortnight, not claimed on the day the invoice went out. Fourteen days of deliberately looking for a comeback, and no comeback. It has a date range on it. You can hand it to somebody.
- Something wakes up. Good — read that again, it isn’t a typo. It has just told us where it was hiding, while we are still watching, still holding your baseline, still under the same engagement. We close it, the fourteen days restart from zero, and you don’t pay again.
✅ That is the Clean Bill Guarantee.
Anyone can hand you a green tick on the day. We hand you fourteen days of nothing happening — and we go back to work for free if that is not what we get. It isn’t a goodwill gesture. It’s structural: the same automated pipeline that built the fix re-tests the fix, so running it again costs us, not you.
Now the honest part, because you will hear the opposite everywhere else. A clean fortnight does not mean you will never be broken into again. Nobody can sell you that, and anyone who does is either lying or doesn’t understand what they are up against. New holes get published every week, and yours is a live website on the open internet, not a safe. What a clean fortnight means is this: on the day we handed the site back, there was nothing left inside it that was trying to get back in. That is a real statement about a real date, and it is checkable. It isn’t a smaller promise — it is the only one that is true.
Nothing Touches Your Live Site
Until It Has Already Survived
The whole job runs off-site. Your production site never sees a half-fixed state — not for a minute. Here is the pipeline, start to finish.
- Clone. Your site is mirrored, files and database, into a sandboxed scan machine on encrypted disk [CIS sandbox isolation guidance]. Nothing we do next can reach your customers.
- Fix. Every confirmed finding from your $485 Deep Audit gets patched in the clone. Plugins. Themes. Custom code. wp-config.php. .htaccess. Database. The lot.
- Attack. Our four frameworks turn around and try to break what we just built. Properly. Like they mean it.
- Loop. One of them gets through? Back to the bench. Re-patch, re-attack, again and again, until all four come back clean.
- Visual gate. Pixel-diff against the pre-fix baseline, desktop and mobile. Anything that moved is flagged automatically — no human squinting at a monitor at midnight deciding it is probably fine.
- Ship. Only what survived both gates goes live. A page that broke visually gets re-engineered to match, or reverted and queued for another route in.
- Watch. Fourteen days, tempo up. You know this bit already.
Hardening a site is easy if you don’t care what it looks like afterwards — turn enough things off and nothing gets in, including your customers. So your site should look exactly like your site the morning after. That isn’t a bonus feature. That’s the job.
No 11pm white screens. No dead checkout on a Saturday. No frantic call from you asking what happened to the booking form. We broke it in the sandbox so your customers never had to.
The Fix Doesn't Ship
Because We Say It's Done
It ships because four independent attackers couldn’t beat it.
Autonomous AI pentester — spawns parallel sub-agents, one per attack path, so it hits twenty surfaces at once instead of walking through them one at a time the way a human would
Exploit-chain analyser — built in-house. Maps how three “minor” findings combine into a takeover: A plus B plus C equals somebody in your admin panel, written in plain English so you can read how an attacker would walk through your site, not just what was found
Adversarial AI auditor — its only job is to attack every fix and try to break it before it ships. Anti-rationalisation charter. No rubber-stamping, including of us
Three-agent verification framework — auditor probes, target executes, judge scores. It audits the agent stack itself, because who checks the checkers is a fair question
All four have to come back clean. One finds a way through and the patch does not ship. The pentester on its own can run for hours against a single clone — that is one framework, on one target, in one pass. Multiply it by four frameworks, then by every re-run after every re-patch, and the verifying dwarfs the fixing.
Most of what you are buying is the part that tries to prove us wrong.
What The $985 Actually Buys.
And What Moves The Number.
Two jobs, one engagement. Seal what the Deep Audit found. Harden against the paths we would come back through tomorrow.
- Every confirmed audit finding fixed at code level in the clone.
- Plugins and themes pulled current, compatibility-tested before anything ships.
- Unused plugins removed from the filesystem — not deactivated, removed. A deactivated plugin’s code is still sitting on the disk, and plenty of holes don’t care whether you ticked the box.
- User audit — dormant admins, ghost editors, that “temporary” account from the developer who left in 2019.
- Database sanitisation — orphan tables, bloated transients, over-privileged MySQL users, stale session rows.
- Every secret turned over — admin passwords, WordPress salts, application passwords, API keys, session tokens. If somebody had a copy, that copy is now worthless.
- wp-config.php and .htaccess hardened — file editing off, salts regenerated, uploads can’t execute code, which kills the single most common way a small business gets owned.
- Security headers set properly — HSTS, CSP with nonces, X-Frame-Options, Referrer-Policy, Permissions-Policy.
- Login hardening — rate limits, progressive lockout, URL obfuscation, 2FA on every admin.
- REST API scoped, XML-RPC off unless you actually use it, and source maps stripped from your production JavaScript so nobody gets to read your code like a book.
- Custom CSS and JS moved to update-immune territory, so your customisation stops getting wiped every time a plugin updates.
- Hardening persisted where an attacker can’t switch it off from the admin panel, even if they get in.
We don’t publish exactly where those last two live. Same rule that runs through everything we do: publish the mechanism, publish the bypass. The people we are keeping out are reading this page too. You don’t need the recipe. You need the result.
The exact list varies, and we are not going to pretend otherwise. A tidy five-plugin brochure site is different work to a fifteen-year-old WordPress carrying a custom membership plugin from a developer who vanished. The audit names your scope before you pay a cent of Optimisation money.
$985
Flat. Quoted off your audit findings, before you book anything.
A mechanic in Perth charges $130 an hour [ServiceCost AU 2026]. A plumber, more. A sparkie on a night call, roughly double. Nobody argues — you hand over the keys and you pay it.
$985 is roughly eight hours of senior engineering applied to every layer of the thing your customers, your suppliers and your bank details all touch. Less than a day of spanner-and-ute work, for the machine that is the shop.
“And then you’ll come back with a bigger number, won’t you.” No — and here is the mechanism that stops it, not just the reassurance. The free scan counts your plugins and fingerprints your hosting. The $485 Deep Audit names the full scope. You see the price before you spend a cent of Optimisation money. Always. Every time.
WHAT $200 BUYS
✗ Applied patches, and best wishes.
WHAT $985 BUYS
✓ Patches that four independent frameworks attacked before a single byte went near your live site — then a fortnight of watching.
That gap is the entire price difference. It isn’t margin. It’s the verification loop.
Three things move the number, and all three get named up front.
- Size. A standard small-business site — up to about twenty plugins — is $985 flat. Most sole traders land here. Bigger and more complex builds are scoped and quoted individually off your audit findings, in writing, before you commit to anything.
- Age. This is where the real hours go. On an older site your custom CSS and JavaScript are almost certainly sitting in folders that get overwritten every time a plugin or theme updates — so the moment an update lands your customisation is wiped, the layout shifts, and your developer bills you to put it back. Then it happens again next month. Before a single update can land we extract every snippet, catalogue what each one does, re-apply it to update-immune territory, pixel-diff against the baseline, and only then run the update. On a clean modern build that is minutes. On a neglected four-year-old site it can be a full extra day on its own. You pay once, or you pay your own developer forever.
- Hosting. The one nobody else mentions. Some hosts simply will not run the tooling hardening needs — low memory ceilings, locked-down filesystems, no SSH, restricted PHP modules, blocked outbound connections. When that happens we stand the staging up on our own infrastructure, use tooling that actually runs in your environment, and engineer the monitoring to fit what the hosting permits. And if your hosting is genuinely too restrictive to harden to a standard we would stand behind, we will tell you that instead of taking your money.
WooCommerce — the honest exception. We audit Woo sites and we monitor Woo sites, but we do not run Optimisation on them ourselves. Remediation applies code-level changes, and on a live commerce stack those can interact unpredictably with cart logic, payment hooks, tax rules and orders that are mid-transaction while we are working. Your own Woo developer applies the findings on your own staging, and we re-verify their work through the same four-framework gate. You still get the chain of custody. We just don’t drive the screwdriver through your checkout.
Why This Can't Be
Where It Ends
Remember day fifteen? Here it is.
Hardening is a moment — a very good moment, verified four ways and watched for a fortnight. But a moment. Monitoring is forever, and the threat you are actually facing is a forever problem.
Here is what is still true the day after we hand your site back.
1 · New holes get published every week
In plugins you already have installed. That doesn’t pause because you just paid someone.
2 · You’re still on the public list
The same list every automated scanner reads. Being fixed doesn’t take you off it.
3 · Somebody still updates something
At some point. And somebody still gets a password wrong.
Nothing about the fix stops the world from carrying on. So the fortnight watch doesn’t get switched off at the end of day fourteen — it gets turned down to cruising speed and left running. That is Overwatch, from $360 a month. Same eyes, same baseline, same evidence trail. It just never stops.
And here is the distinction that costs people everything. A scanner asks: do I recognise anything bad? Monitoring asks: did something move that had no business moving? An off-schedule file change. An admin account nobody created. A scheduled task that isn’t in the schedule. Traffic going somewhere you have never heard of. An edit to a file that hasn’t legitimately changed in three years.
You don’t catch a quiet tenant by recognising them. You catch them because the floorboard creaked.
We know it works because we watched it happen. We built a website and deliberately left it un-updated and un-hardened — exactly the state most people are in the day they first call us. Not carelessness: a test target. We didn’t write the malware and we didn’t stage the break-in; we left the door open and waited. It got found and broken into, right on cue, exactly as we said it would. Then we switched Overwatch on, and it surfaced the intruder in four minutes — on a site that looked completely normal.
✅ And it is what earns you the AI-Era Diligence certificate.
An optimised site under active Overwatch earns AI-Era Diligence. Dated. Hashed. Signed. Renewed monthly. You can’t buy it — you earn it by going up the chain: scan, audit, fix, watch, keep watching.
It attests to what we did and what we found, on a date, on Australian soil. It is verifiable evidence. It is not a legal document and it is not a guarantee — we can never make your site impossible to break into, and anyone promising that is lying. What we can hand you is a documented record that you took the defensive steps that were actually available to you.
In A Nutshell
The whole thing, in one place:
- A scan that comes back green on the day of the fix proves almost nothing — it means the scanner recognised nothing, not that nothing is there.
- Optimisation fixes every confirmed finding off-site, on a clone. Your live site is never the workbench.
- Every fix is attacked four different ways before it ships. One framework gets through and the patch doesn’t go out.
- We check your site still looks like your site — a fix that breaks your checkout isn’t a fix.
- Then we watch hard for fourteen days. Nothing stirs, that’s your clean bill — earned, not claimed. Something stirs, we fix it again free and restart the clock.
- $985, quoted from your audit findings up front. Never a surprise.
And it doesn’t end on day fifteen — that’s the day it starts to matter.
✅ You can’t buy this one cold — and we wouldn’t sell it to you cold.
It is scoped by the $485 Deep Audit, and everyone — everyone — starts with the free scan. No card, no credentials, about ten minutes.
The fix is the easy half. The fortnight afterwards is the half that proves it.
Vulnerability data comes from Wordfence Intelligence and WordPress.org release data.
Already Audited?
Book Your Optimisation.
Your scope and your number are already written down in your Deep Audit report. Talk to Maya and book the Optimisation off your own findings. She is our AI team member, she picks up immediately, and she is awake at 2am. Ask her anything — scope, timing, what the “+” would be on your site. If it needs Dave’s eyes, she books him.
Haven’t been audited yet? Book the Deep Audit — $485. Optimisation is scoped from what it finds. We don’t fix blind, and we won’t take $985 off you to guess. Not sure where you are? Start with the free scan.
