Security audit & hardening · From Udupi, across India

Find the weak spots before someone else does

We find the gaps a bot would find on your website or web app, close each one and test it again, whoever built the site. A few months after the fixes, our Udupi studio checks again that every gap has stayed shut.

Demo screen with made-up data.
Fixed, not listed
each problem closed, then tested again
Permission first
nothing is tested without your written go-ahead
Plain-English report
what was open, what changed, what is left
WordPress or custom
including sites and apps others built

In short

What is a website security audit?

A website security audit is a careful check of a site's files, logins, software, forms and settings to find the gaps an attacker could use to get in. Whirl Designs, a studio in Udupi, runs these audits in person around Udupi and Mangaluru and remotely anywhere in India, fixes each problem it finds, tests the site again and hands over a plain-English report of what changed.

Updated · Whirl Designs, Udupi

Start here

Which kind of security check do you need?

Security checks come in three sizes. A scanner is quick and shallow, a penetration test is deep and formal, and most business websites need the one in between.

An automated scan

Best for: A first look at a simple one-page site

  • Runs in minutes and lists old versions, missing headers and certificate problems
  • Cannot tell which warnings matter and which are noise
  • Finds problems but fixes none of them

An audit with fixes

Best for: Business sites, shops and web apps you depend on

  • Covers what scanners miss: forgotten accounts, risky settings, weak forms
  • Every problem fixed on your site, then tested again
  • A plain-English report you keep

A penetration test (VAPT)

Best for: When a regulator, tender or client contract asks for one

  • VAPT means vulnerability assessment and penetration testing: testers try to break in, within agreed rules
  • Some government sites and tenders ask for an auditor on the approved list of CERT-In, the Indian government's cyber security agency
  • The report proves the risk; fixing it is a separate job

The middle one is what we do. Whirl Designs is not on CERT-In's list, so if you need the third, we will tell you to hire a listed firm, and we can fix what their report finds.

Our work

The closest security work we can show

There is no client security audit we can show yet, so this page names no client, and every finding in the report at the top is invented for the demo. The clearest real example is a problem on our own website, which we wrote up in public.

Bots found the newsletter form on whirldesigns.com, and the list grew to 306 subscribers without one real person among them. Three changes closed it: a signed token, a code our page adds to the form, which a bot posting straight to the form does not have; limits on how often one source can sign up; and double opt-in, so nobody joins until they click the link in a confirmation email. Every form we check for you gets tried against the same kind of attack.

  • ERP Sutra: sign-in, user roles, the audit log and backup solved once in a shared platform layer, and a restore from backup that has actually been tried, not assumed
  • Facet: access controlled down to single actions, so each role can do its own job and nothing more
  • Jayalaxmi Jewellers: staff permissions set task by task (capability-based) in the retail ERP the shop bills from

Closest projects

What you get

Six places every audit looks

These are the gaps bots try first on every site they reach. Each audit covers all six, and the report says so even when a place turns out clean.

  1. Files anyone can downloadOld backups, database copies, zip files of the site and settings files left where a browser can reach them. Bots guess these addresses on every domain, so we try the same ones, plus folders that list their own contents.
  2. Login pagesAdmin and staff logins open to the whole internet, endless password tries, default usernames, shared accounts and old staff accounts that still work. Each person ends up with their own login and only the access their work needs, repeated tries are limited, and 2-step login (a code on the phone as well as the password) goes on wherever the platform allows.
  3. Software with known holesThe CMS (the system you edit the site in, such as WordPress), its plugins and themes, JavaScript libraries, outside scripts such as chat widgets or old tracking code, and the server's PHP version, all checked against public lists of known security bugs. Anything out of date is updated, and anything nobody uses is taken out.
  4. Forms and uploadsEnquiry, sign-up, search and upload forms. Can a bot flood them? Can someone type code into a box and have your site run it? Can an uploaded photo turn out to be a program? Each form gets the protection it needs.
  5. Headers and HTTPSHTTPS on every page, a certificate set up correctly, cookies marked secure, and the security headers that tell browsers not to let other sites show your pages inside theirs or load scripts you never approved.
  6. Who holds the keysHosting, domain, email and admin accounts: who can log in, which former staff or developers still can, and whether the accounts that could take the whole site down have 2-step login, with every account moved into your business's name. The email domain is checked too: its SPF, DKIM and DMARC records are the settings that stop strangers sending mail that looks like yours.

How it runs

How an audit runs

You hear about the most serious problems in the first few days, not in a report at the very end.

  1. Scope and written permission

    Together we agree which sites, subdomains and systems are checked and which tests are allowed, and you sign off in writing. Testing a site without its owner's permission is something we never do, so this step always comes first.

  2. The outside view

    First comes the view a bot has, with no password: common file addresses, login pages, software versions, headers, certificates and forgotten subdomains. These checks are light, about what a few visitors would cause. Tools do the slow part; a person reads every result and throws out the false alarms.

  3. The inside view

    Next comes a look from inside, with a separate account you create for us and delete when we finish, never your own password: plugins, user accounts, file permissions, server settings, signs the site is already hacked, and what each form does with what people type. Web apps are also worked through against the OWASP Top 10, a widely used list of the most common web app weaknesses.

  4. Findings, most serious first

    You get a report in plain English: where each problem is, why it matters, how serious it is and how we would fix it. Something critical, like a backup anyone can download, is reported the same day and closed as soon as you agree.

  5. Fix, then scan again

    A full backup comes first, and we check that it restores. Risky fixes and heavy tests, such as many login attempts in a row, are tried on a copy of the site or at a quiet hour you choose. Then every check runs again, and the second report shows each problem closed and lists anything left for you to decide.

  6. A return check

    Sites drift: a new plugin, a new staff login, a zip file uploaded just for now. So the checks run again later, and your team keeps a short list of things never to do on the live site.

Not a fit

When an audit is not the right step

Some sites need something else first, and you should hear that before any testing starts.

  • Your site runs on a hosted builder such as Wix, Google Sites or a Shopify store with no extra apps. The platform patches its own servers and software, so 2-step login on every account and removing people who no longer need access covers most of the risk.
  • You want a report that says the site is completely secure. Nobody honest can sign that. An audit closes the gaps known today, and our report says plainly what risk is left.
  • The site is being rebuilt in the next month or two. Close only the urgent gaps now, such as an open backup file or a default password, and build the new site with these checks from the first day.

5.0 on Google — read our reviews

Questions

Questions about website security audits

How long does a website security audit take?

For a typical business website, the checks take two to four working days, and most fixes are done within the following week. A web app with customer logins, payments or file uploads often takes two to three weeks, because every role and form has to be tried. More subdomains, more user roles or a site that has already been hacked all make the job longer.

How do I know if my website has been hacked?

Common signs are a Google warning next to your site in search, strange pages under your domain, visitors sent to other sites, admin users you never created, or your host suspending the account. Some attacks show nothing for weeks. If you see a sign, do not delete files yet: we keep a copy to learn how the attacker got in, clean the site or restore a clean backup, then close that way in.

Is WordPress safe for a business website?

Yes, when it is kept up to date and set up with care. Break-ins usually come through an old plugin or theme, a weak admin password or a login with no limit on tries, not through WordPress itself. Hardening a WordPress site means closing exactly those: fewer plugins, updates on time, 2-step login, files that visitors cannot change and no backups left on the server.

Why would anyone attack a small business website?

Usually nobody picks you. Bots scan every site they can reach, trying the same common file addresses and passwords, and they use whatever opens: to send spam from your server, hide scam pages on your domain or copy your customer list. Being small makes a site less interesting to a person, not harder for a bot to find.

Does the padlock in the browser mean my website is secure?

No. The padlock only means the connection between a visitor's browser and your site is encrypted, so nobody along the way can read it. It says nothing about an old plugin, a weak admin password or a backup file sitting on the server. A site can show the padlock and still be wide open, which is why the audit looks far beyond the certificate.

How often should a small business website be checked?

A full check about every three months suits most business websites, plus one after any big change, such as a redesign, a new plugin, a new payment option or someone with admin access leaving. Between full checks, a monthly outside scan catches the simple slips, like a backup file left in a public folder.

How is a security audit different from website maintenance?

An audit is a one-time deep check that finds and fixes the gaps on your site. Maintenance is the routine care that follows: updates, backups and monitoring, so the site does not drift back. Many sites need the audit once and a maintenance plan after it. We do both, and the audit report tells you whether you need the second.

Can we meet you to go through the report?

Yes. You can go through the findings with us at our studio in Udupi, or we can come to your place of work in Manipal, Karkala, Kundapura, Mangaluru or Udupi itself, with whoever looks after your website in the room. The testing is done remotely, so businesses elsewhere in India or abroad get the same audit, with the walk-through on a video call.

Worth reading first

WEB & E-COMMERCE

Engineering you can build on.

Clean, documented, tested code on a modern, proven stack — the foundation that keeps your security audit & hardening fast and dependable for years.

OWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess controlOWASPSSL/TLSSecurity headersWAFAccess control
index.html
<meta name="description" content="..."> <script type="application/ld+json"> // structured data for rich results ✓ Lighthouse 98 · Core Web Vitals green

Ready when you are

Let's build something that lasts.

Name the sites or web apps you want checked and what each one is built on, and you will get an audit plan in writing: the checks we will run, the access we need and how long it will take.

50+
projects shipped for local & global clients_
100%
of the code is yours to keep_
9
real, live projects on our work page — from our Udupi studio_
Whirl Designs assistantAnswers from this site · not a person
Ask about what the studio builds, how a project runs, or what would suit your business. I answer from this site, and I can pass you to the team any time.
WhatsApp us