Here's Every Price We Charge.
And Why You Can't Buy Most Of Them Today.

Most pricing pages are a menu — pick a tier, put your card in, off you go. This one isn’t, on purpose. None of these numbers mean anything until somebody has actually looked at your site.

So there is one door in. It’s free, it takes about a minute, and it doesn’t ask for a card.

A single green-lit turnstile standing alone in an otherwise open, unobstructed dark hall

Why You Can't
Skip The Queue.

People try. Genuinely. Someone reads the Optimisation page, decides that’s the one they want, and asks to pay for it today. We say no.

Every stage on this ladder is built on the one underneath it.

1 · The free scan shows what your site looks like from the outside — the exact view an attacker gets in their first minute.

2 · The Deep Audit takes that view inside, with your permission and your credentials, and works out precisely how someone would get in.

3 · The Optimisation closes those specific holes, then attacks them again to check they stayed closed.

4 · Overwatch watches those exact surfaces from then on, so it knows what normal looks like on your site and can spot the thing that shouldn’t have moved.

Skip a rung and the next one is guesswork. An Optimisation without an audit underneath it is a bloke applying patches he hasn’t verified, to holes he hasn’t confirmed, on a site he hasn’t read. That’s the web guy who clicks “update all” and tells you it’s handled. We’re not selling a more expensive version of him.

Dave calls it the custody chain, and it isn’t a sales sequence — it’s a paper trail. Each stage signs off what the next one is built on. Dates. Findings. What was there before, what changed, who touched it, what it looked like after.

So the AI-Era Diligence is earned, not bought. There is no price on this page for one — you walk the chain and it’s yours. Buy a rung out of sequence and there’s a hole in the chain, which is exactly the thing you’d be trying to avoid.

A steep flight of steps rising away, the lowest treads lit green and each higher one dimmer

The Whole Ladder,
Priced In The Open.

Free Scan. Deep Audit. Optimisation. Overwatch. And Rescue, if you’re already in trouble. One entry point, strict order, and every number here is what you’d actually pay — not a “from” that doubles on the phone.

Free Scan — $0. No card, no credentials, no obligation. It is the only way in, and it is how your tier gets scoped. The three rungs below are what comes after it.

Four metal rods of increasing height in a row on a plinth, each capped with a green light

Deep Audit

Exactly how they would get in.
$ 485 one-off · small site
  • Every line of PHP read for meaning — plugins, themes, custom code, wp-config, .htaccess. Not pattern-matched. Read.
  • Your site attacked on a sandbox clone — the audit itself changes nothing on production.
  • Long-chain exploit analysis — A plus B plus C equals full takeover, written out explicitly.
  • A seven-model Council cross-checking the work. Different makers, different blind spots.
  • Every finding handed to a fresh AI session whose only job is to prove it wrong.
  • Compromise-detection suite — the checks that answer “is someone in here right now”.
  • A 9-page attack-vector report in English, walked through with you finding by finding.
Start Here

Optimisation

Those holes closed, then attacked again to be sure.
$ 985 one-off, from · small site
  • Off-site patching pipeline — cloned to a hardened sandbox, fixed there, attacked there, deployed only when our own swarm cannot break it.
  • Every confirmed finding fixed — plugins, themes, custom code, wp-config, .htaccess.
  • Database sanitisation — hidden admin accounts removed, SEO spam stripped, backdoors killed.
  • Credential burn-down — admins, salts, API keys, application passwords, session tokens. All rotated.
  • A deep hardening pass at code level.
  • Your CSS and JavaScript moved to update-immune territory, so a plugin update cannot wipe your styling any more.
  • Four-way pre-ship gate plus a visual pixel-diff gate. Four agreement points, or the patch does not ship.
  • The two-week reinfection watch — the Clean Bill Guarantee.

Overwatch

Someone still watching next Tuesday.
$ 360 per month · small site
  • Daily file-integrity monitoring against a site we verified clean ourselves — so a change actually means something.
  • Weekly rotating AI deep scans. An intruder cannot model what is being watched, because it moves.
  • Monthly automated pentest sweep — short, unannounced, timing jittered.
  • Quarterly deep pentest sweep — full attack-surface enumeration and multi-step exploit chains.
  • Plugin-update verification gate. Every vendor patch tested in staging before it touches your live site.
  • Holding-page auto-redirect if anything gets through. No DNS change, your SSL stays valid, the bleeding stops in minutes.
  • A $250 fix pool that refills itself — the moment it drops to $50 it tops straight back to $250, not next billing cycle.
  • Pre-written breach-notification templates for your solicitor to review before anything goes out.
  • An evidence log for every incident — entry point and blast radius. Not a list of deleted files. Not a green tick.
  • Your AI-Era Diligence renewed monthly, and a direct line to us. Maya picks up.

Bigger Site?
The Bigger Numbers Are Right Here.

A long aisle of archive shelving receding into the distance under green strip lighting

Those are small-site prices — a sole trader, a single location, a few dozen pages. Most people reading this sit right there.

A bigger site is simply more code to read. More plugins. More custom work. More places for something to hide. So the price moves with the reading, not with what we think you can pay.

Which bracket you are in comes out of the free scan, and you are told before anything starts. Nobody discovers their bracket on an invoice.

Medium site — $985. Large site — $1,985.

Flat, per bracket. Same work, more of it, because there is more code to read. Tier is scoped on three things, not just plugin count: how many plugins, how many pages, and how complex the build is.

$985 holds for a normally-aged small site — a year or two old, plugins roughly current, nobody neglecting it.

A four-year-old site with stale plugins and bolt-on customisations is different work. Touch one cog and the whole thing goes with it. Here is where the extra hours actually go: on a neglected site the custom CSS and JavaScript is almost always living in folders that get wiped on every plugin update. Before a single update can land safely we have to extract every snippet, catalogue what each one does, re-apply each piece somewhere update-proof, pixel-diff against the baseline, and then update. On a fresh site that is minutes. On a four-year-old mess it can be a full extra day on its own.

So bigger and more complex builds are not a tier number here. They are scoped and quoted individually off what the audit actually finds — in writing, before you commit to anything. Never buried, never discovered halfway through, never sprung on you in an invoice.

Medium site — $497 a month. Large site — $797 a month.

Flat, per bracket. More site means more surface to watch, more files to fingerprint, more updates to test before they land. Your bracket comes out of the free scan, so you know it long before anyone asks you for anything.

Portals, dashboards, e-commerce platforms, booking and LMS systems, membership sites, heavy custom functionality. Those behave more like web apps than websites.

They get a bespoke quote after we have reviewed them — not a tier number lifted off a page. We would rather look first and tell you the truth than publish a figure that was never going to hold.

No. Website Rescues is not GST-registered, so every figure on this page is the price you pay. No tax line waiting at the end, no adjustment on the invoice.

A car bonnet propped fully open with a green work lamp lighting the engine bay beneath it

The Free Scan Is
The Only Door In.

The mechanic doesn’t give you a free look under the bonnet. We do, because the front of the funnel should actually help someone, not just collect an email address. Here’s what runs:

  • External fingerprint — exactly what an attacker sees of you in their first minute.
  • CVE cross-reference — Wordfence Intelligence, cross-checked against the WordPress.org release data. If a hole is in the public catalogue, the attackers have it too.
  • Two questions, not one. Wordfence answers “has a hole been published against the exact version you’re running?” WordPress.org answers “how many releases behind is that version?” A plugin four releases back carries every quiet fix in those four releases, and nobody has to publish a thing for that to bite you.
  • Visible malware sweep.
  • Multi-IP cloaking detection — 15 separate Australian IPs plus a VPN pool of roughly 1,300 exit addresses and a proxy layer, all hitting your site from different vantage points. Some infections show clean to one visitor and serve poison to another.
  • A PDF with your top 3 to 5 critical findings, walked through conversationally. Not the raw dump — a raw report is an attacker’s shopping list, and we’re not publishing yours.
  • Owner notification. If somebody else runs a scan on your site through us, you get a copy.
  • Two scans per domain per 12 weeks, so nobody uses the free tier as a reconnaissance service.

What it can’t tell you: whether someone is already living inside. An external scan sees the front of the house. It can tell you the back window is unlatched. It cannot tell you who is in the kitchen. That’s the next rung.

Vulnerability data: Wordfence Intelligence. Release data: WordPress.org.

“Yeah, But Is This
Expensive?”

Let’s have the actual conversation instead of dancing around it. What you’re thinking is: four hundred and eighty-five bucks to be told my website’s got problems? Fair. Let’s take it apart.

The mechanic. A Perth mechanic charges about $130 an hour to work on your ute. Nobody argues — it’s skilled work and you’d rather not do it yourself. The Deep Audit is $485, once, for the thing that carries your bookings, your enquiries, your reputation and every customer detail you’ve ever collected.

And the attacker isn’t a genius. The real threat isn’t the most powerful model — it’s the jailbroken one. An off-the-shelf model with its safety catches pulled out, running exploits that were published months ago, is entirely enough to flatten a WordPress site. What used to protect you was skill: knowing how to chain three boring little holes into one full takeover took a person who’d done it before. The model does the chaining now, at scale, all night, for almost nothing. Different battlefield. So we built the answer to that.

The most expensive thing on this page is the option that costs nothing today. And you don’t have to take our word for any of it — the first rung is free and it doesn’t want your card. Run it, read what comes back, then decide whether $485 sounds expensive.

A car raised high on a two-post workshop hoist, its underbody lit by a green work lamp

The Two Weeks
Everybody Else Skips.

A clean site isn’t a moment. It’s a fortnight that survived.

A skilled compromise doesn’t sit in one file you can delete. It’s resident. Backdoors that reinstall themselves. A dormant cron job that quietly rewrites the payload three days later. Code whose entire job is to bring the infection back once the cleaner has packed up and invoiced. So a scan that comes back green on the afternoon of the fix proves almost nothing.

The real test is what your site does over the next two weeks. Which is why, after every Optimisation and every Rescue, we don’t call it done — we turn the testing tempo up. There are two ways that fortnight can go, and both of them end well for you.

A dark floor of undisturbed dust under a single steady green lamp

1 · Nothing Stirs
For Fourteen Days.

That is your clean bill. Earned across fourteen days of intensified scanning, not claimed on the afternoon of the fix.

And when the fortnight comes back clear, the elevated watch settles straight down into Overwatch. So it never stops.

A single fresh footprint pressed into the dust, picked out by a green lamp

2 · Something
Wakes Up.

Then it just told us where it was hiding. We go back in, close it, and the clock restarts. Free.

That is what the Clean Bill Guarantee actually is. Not a sentence in a terms page — fourteen days of us still looking. The cleaner who is gone by Friday can’t tell you the difference between “clean” and “quiet”. We can, because we are still watching when the resident code wakes up.

A shop roller shutter half down at night with red emergency light spilling underneath

Already Hacked?
Different Door.

If you’re already hacked you don’t need a ladder. You need the bleeding to stop.

The holding page is free. Always. No card, no contract, no strings. Tell us the URL and give us access, and one rule drops onto your web root so every page on your site redirects to a holding page on our server. Visitors see “under maintenance” with a contact form that emails enquiries straight to your inbox, so you don’t lose the leads while you’re down. No DNS change. Your SSL stays valid. Your URL stays live. Fifteen minutes, and you never pay for that part.

Rescue — from $1,485. That’s the work that comes after: everything in the Deep Audit and the Optimisation, run on a live compromise. Full compromise removal — web shells, rogue admin accounts, injected database rows, backdoored cron jobs, payment skimmers — taken out on a clone, verified, then deployed clean. Entry-point diagnosis: not just what got planted, but how they got in and how far they reached. Delete the payload without finding the door and they walk back in next week. Credential burn-down on everything they could have copied. And the two-week reinfection watch.

$1,485 is the floor, not a bracket. No emergency loading, no panic premium, no tripled price because you rang us in a state. Some compromises aren’t one compromise — multiple intrusions chained on top of each other, or different intruders who arrived months apart — and that gets quoted up front, in a real number, off what the audit actually finds. Before we start. Never sprung on you in an invoice while your site is still down.

Rescue includes the full hardening pass and counts as your Optimisation stage toward the AI-Era Diligence. You don’t do the work twice.

One separate number so it can’t surprise you later: if the compromise wrecked your site’s appearance and you want the look and content rebuilt afterwards, that’s ordinary development work at $150/hr. Optional, quoted before it starts, and a different job from the security work above.

What You Actually
Live With, Day To Day.

The threats are the reason you’d start. This is what it’s actually like once you’re on the other side of it.

A sealed crate clamped on an impact-test rig, attacked before it is allowed to ship

Your site stops going down from updates — every plugin update staged off-site and attacked before it ships. If it doesn’t survive, it doesn’t land. No more Saturday-morning panics because a vendor pushed something on a Friday.

A glass reservoir of green liquid kept topped up to its level line by a steady drip

No surprise developer bills — the $250 auto-replenishing fix pool covers the moments when an update breaks something or a plugin gets flagged. One predictable monthly number, and most months it’s barely touched.

A desk telephone in its cradle on a dark counter, lit green and still in service

Your Google Ads keeps running — the site doesn’t get flagged, Chrome doesn’t slap a red warning over your domain, the Ads account doesn’t get suspended, and the phone keeps ringing.

A darkened bedroom at night with one small steady green indicator light on a shelf

You sleep — the one every tradie undervalues right up until it’s gone. And if anything does get through, the holding page swaps in within minutes, so your customers’ machines don’t get touched and your reputation stays yours.

One thing we won’t dress up: the insurer renewal gets easier because you have a continuous-monitoring answer and timestamps to back it. We can’t tell you what your insurer, or anyone else, will make of that. We can tell you it goes better than “I didn’t know.”

How You Earn It.
And How You Lose It.

It isn’t a photograph of one good afternoon. It’s a live document — dated today, valid as of today, maintained for exactly as long as the chain of custody holds.

The certificate is the cover page. The logs are the proof. Anyone can issue a piece of paper. Anyone can sell you a sticker with a shield on it. What makes this one weigh something is that every claim on it is backed by timestamped logs: every update applied, every scan that ran, every alert that fired and what happened next, every patch tested off-site before it went live.

  • Deep Audit — $485. The diagnosis.
  • Optimisation — from $985. The work. Or Rescue from $1,485 on the hacked path — it includes the hardening and counts the same.
  • Overwatch — $360/month. The maintenance.

Skip a stage and there’s no certificate. Let Overwatch lapse and it revokes itself. That’s not us being difficult — it’s the entire reason it means anything. A badge that can’t break isn’t evidence, it’s decoration.

What it is, and what it isn’t. It attests to what we did and when we did it. That’s a fact about our own service, and we can evidence every line of it. It is not a legal document, and we’re not going to tell you what a court, an insurer or a regulator will make of it — that is their call, not ours. Nobody can guarantee you’ll never be hit either. Anyone selling you a “hack-proof” website is either lying or hasn’t understood the threat.

Here’s what we will stand behind instead. When something gets in, you’ll know in minutes rather than months. There’ll be a clean backup to rebuild from. There’ll be an evidence trail instead of a shrug. And you won’t find out from an angry customer’s solicitor.

That isn’t a smaller promise. It’s the only one that’s true.

A tall stack of plain logbooks with a single unmarked brass disc resting on top
One small green cube alone at the centre of a dark table under a soft overhead light

In A Nutshell.

Every price we charge is on this page. No menu on a call, no quote that lands like a punch.

Most of them you can’t buy today, on purpose — each stage is built on the one underneath it.

Free Scan $0 · Deep Audit $485 · Optimisation from $985 · Overwatch $360/month · Rescue from $1,485. Bigger site, bigger number — and that number is on this page too, one click away.

We’re not GST-registered, so every figure you just read is the price.

There’s one way in. It’s free, it takes about a minute, and it doesn’t ask for a card. Run it, read what comes back, then decide whether any of these numbers sound expensive.

Security badge: Fighting AI with AI, cross-referenced against known attack database

Every Price, In One Place.
One Way In.

Free Scan — $0. What an attacker sees in their first minute.
Deep Audit — $485. Exactly how they’d get in.
Optimisation — from $985. Those holes closed, then attacked again to be sure.
Overwatch — $360/month. Someone still watching next Tuesday.
Rescue — from $1,485. When it’s already happened. Holding page free, always.

Those are small-site prices, and the bigger brackets are on this page too — one click, no form, no “contact us”. We’re not GST-registered, so every figure is the price.

Skip one and the rest don’t hold. That’s why there’s only one button on this page. You’ve now read every number we’d ever ask you for — nothing on this ladder can ambush you. All that’s left is finding out which rung you’re actually on, and that part costs nothing.

Already hacked? The free holding page stops the bleeding in fifteen minutes — no card, no strings. Maya picks up 24/7. Ask her anything.