Skip to content
WebShift Studios

Website Audits

Find out what your website is costing you.

A structured review of the site you already have: where it loses people, what's slow, what search engines can't see, and what's exposed. Written in plain language, ranked by impact, with a clear next step.

What you get

  • A written report with screenshots and plain explanations
  • Every finding ranked: what first, what can wait
  • Security findings rated Informational to Critical
  • A walkthrough call, then a plan you can act on with anyone

A security review is not a penetration test. Penetration testing is offered only as a separately scoped engagement with agreed targets, rules of engagement, and a written report.

Two ways in

The audit, or the audit with a security review.

Both are fixed scope. The security review is carried out by a cybersecurity professional and rates every finding so you know what matters.

Standard

Website Audit

Where your site is losing people, and what to do first.

A full review of design, mobile, performance, SEO, accessibility, conversion flow, and technical issues, written up in plain language with priorities.

Includes

  • Every area below except the security review
  • Findings ranked by impact
  • Screenshots and examples
  • A prioritised improvement plan

Deliverables

  • Written audit report
  • Priority list (what first, what can wait)
  • 30-minute walkthrough call

Fixed scope. Typically delivered within a week of access.

Request this audit

Stronger

Includes security review

Website Audit + Security Review

The full audit, plus a structured look at how exposed the site is.

Everything in the Website Audit, with a security review carried out by a cybersecurity professional: configuration, access, dependencies, data handling, and exposure, each finding rated Informational to Critical.

Includes

  • Everything in the Website Audit
  • Security findings rated by severity
  • Mitigation steps for each finding
  • Threat-model summary for the site's key flows

Deliverables

  • Written audit + security report
  • Severity-rated findings with fixes
  • 45-minute walkthrough call
  • Optional follow-up remediation quote

Fixed scope. Not a penetration test unless separately scoped.

Request this audit

What we look at

Eight areas. Real devices, real tools, plain findings.

Each area gets its own section in the report with examples, an impact rating, and the fix.

Design / UX

Does the site look current and guide people to the right action?

  • Hierarchy and calls to action
  • Consistency of components
  • Readability and spacing
  • Trust signals near decisions

Mobile responsiveness

Most visitors are on a phone. We check the site the way they see it.

  • Layout at real phone widths
  • Tap targets and forms
  • Navigation and menus
  • Images and text scaling

Performance

Load time, page weight, and what's slowing the first paint.

  • Core Web Vitals
  • Image and font weight
  • Render-blocking scripts
  • Hosting and caching

SEO

Whether search engines can find, read, and rank the pages that matter.

  • Titles, descriptions, headings
  • Indexing and sitemaps
  • Service and location pages
  • Structured data

Accessibility

Whether people using assistive tech, or just a bright screen, can use the site.

  • Contrast and text size
  • Keyboard navigation
  • Alt text and labels
  • Form errors and focus

Conversion / lead flow

How a visitor becomes an inquiry, a booking, or a sale, and where they drop off.

  • Forms and contact paths
  • Phone and booking access
  • Offer clarity
  • Tracking and attribution

Technical issues

The plumbing: errors, broken links, outdated platforms, and fragile setups.

  • Console and server errors
  • Broken links and redirects
  • Platform and plugin versions
  • DNS, email, and domain setup
+ Security

Security review

A structured review of exposure, configuration, and access, rated by severity.

  • TLS, headers, and transport
  • Authentication and admin exposure
  • Dependencies with known issues
  • Data handling and backups

The security review

Rated so you know what matters. Written so you don't need a translator.

WebShift is supported by a cybersecurity professional with hands-on experience in security operations, so security is a discipline we bring to the work, not a line on a proposal.

  • InformationalWorth knowing. No action needed.
  • LowFix when convenient.
  • MediumSchedule in the next few weeks.
  • HighAffects trust, data, or leads. Fix soon.
  • CriticalExposed now. Fix immediately.

A security review is not a penetration test. Penetration testing is offered only as a separately scoped engagement with agreed targets, rules of engagement, and a written report.

Experience behind the review

  • SOC / MSSP environments
  • Security monitoring
  • Alert triage
  • Incident escalation
  • Threat intelligence
  • Vulnerability management
  • Security automation
  • SOAR / SIEM
  • Threat modeling
  • Vulnerability mitigation
  • Penetration testing
  • Digital forensics
  • Network security

Certifications

  • CompTIA Security+
  • CompTIA A+
  • Google Mandiant Threat Intelligence & Attribution

How it works

From URL to plan in about a week.

  1. 01

    Access and goals

    You share the URL, what the site is for, and any known problems. Read-only access to analytics or the CMS helps but isn't required.

  2. 02

    Review

    We go through every area on real devices and with real tools, and rate each finding by impact.

  3. 03

    Report

    A written report with screenshots, plain-language explanations, and a priority list, delivered as a document and by email.

  4. 04

    Walkthrough

    A call to go through the findings, answer questions, and agree what to do next, with us or with whoever maintains the site.

Questions

Straight answers.

Is the security review a penetration test?

No. The security review is a structured assessment of configuration, exposure, dependencies, and access. A penetration test, with active exploitation attempts against agreed targets, is a separately scoped engagement with its own rules and report.

Do you need access to our site?

A public URL is enough for most of the audit. Read-only access to analytics, Search Console, or the CMS lets us go deeper on SEO, conversion, and technical findings.

Will you try to sell us a rebuild?

The report is the product. It tells you what to fix and in what order, whether you do it with us, with your current developer, or in-house. If a rebuild is the honest answer, we'll say so and explain why.

What if we don't have a website yet?

Then an audit isn't the right starting point. Start with a project estimate instead, or talk to us about WebShift Launch.

Want to know where you stand?

Send us the URL. We'll confirm scope and timing within one business day.