Website Security Audit
We try to break into your site on purpose, by hand, the way a real attacker would: logins, permissions, forms, checkout. You get a list of what worked, ranked by severity, with the fix for each.
See audit levels →Hacklert continuously monitors public websites and compares what it finds against newly disclosed vulnerabilities. When we identify a match on your site, we'll email you — often before an attacker finds the same weakness.
The problem
The painful truth: the vast majority of successful website hacks exploit security flaws that were already publicly known — with a fix already available.
The problem? Nobody told the website owner in time. Your web developer isn't watching this. Your hosting provider isn't watching this. Nobody is — until it's too late.
Typical cost to recover a hacked small-business website — not counting lost sales, reputation damage, or customer trust.
Straight answers
A security email out of nowhere deserves suspicion. So here's exactly what we do, what we don't, and how to make it stop — no spin.
Our scanner visits sites the way Google's crawler does, and reads what they openly show: which software they run, which version of it, and which pages are left open.
Nothing was hacked and nothing leaked. If Google can see it, we can see it — and so can anyone hunting for an easy target.
We don't try passwords, upload anything, open your database, or run anything that could break your site. To confirm a problem we send one harmless request that answers yes or no.
All we keep is the public information above and the email address we wrote to.
Nothing in that email asks you for money, a password, or a download. It gives you the official ID of the problem. Look it up, compare it to the version you're running, and you'll know in two minutes whether we're right.
We'd rather you fix it yourself for free than pay us and still be unsure.
That's the whole business. Most people fix it and move on, which is fine. A few decide they don't want to be the one watching for this every day, and put their site on a care plan.
The alert is free either way, and always will be.
One day on the scanner
Attackers use software to find vulnerable sites within hours of a new hole going public. We work on the same clock they do.
Security holes are disclosed publicly every day. We collect the day's list, keep the ones affecting real websites, and turn them into checks.
A quick read of your public pages: which software and version you run, whether your certificate is healthy, and which pages are open that shouldn't be.
A version number alone is just a guess. One harmless test confirms the problem is real, so what lands in your inbox isn't a false alarm.
What's exposed, how serious it is, and the one thing to click or update. Written so you can act on it without calling anyone.
Sites on a care plan get checked twice a day, plus a warning when something changes: a new setting on your domain, a certificate about to expire, or your email and password turning up in a leaked database.
Care plans
One free alert tells you about today. A care plan covers you on the days you're not looking. Billed monthly — cancel whenever you like.
Extra sites past 25: $4/mo each · Pay yearly and two months are free.
Beyond monitoring
Monitoring shows what's visible from the outside. When you need to know how far someone could really get — or something has already gone wrong — we handle that too.
We try to break into your site on purpose, by hand, the way a real attacker would: logins, permissions, forms, checkout. You get a list of what worked, ranked by severity, with the fix for each.
See audit levels →We thoroughly scan your website’s files, database, and code to hunt down hidden malware, malicious scripts, and backdoor vulnerabilities.
See audit levels →We search known leaks and hacker dumps for email addresses and passwords tied to your domain, then tell you which accounts to change first.
See check levels →Already hacked? We find how they got in, remove the bad code and anything left to get back in, clean your database, and get you off Google's warning list.
Closing what shouldn't be open: exposed admin pages, old files, weak settings, unlimited login attempts, and missing two-step login.
Site defaced, sending visitors to spam, or emailing people on its own? We stop it, work out what happened, and write it up so it doesn't happen again.
Free · no card needed
Send us a website you own. We run the same daily check we'd run for a paying customer and send back what we find — including "nothing serious," if that's the answer.
Only send websites you own, or ones you're allowed to test. We confirm ownership before doing anything deeper.
Opt out
No hard feelings and nothing follows. Enter the address we wrote to, or your website, and you're off the list.
Privacy
Short version: public facts about a website, and one email address. That's the whole file.
| What we keep | Your website address, which software and version it shows publicly, what we found, when we looked, and the email we wrote to. |
|---|---|
| Where the email came from | Public domain records, a contact page on the site itself, or a general address like admin@ or info@ on your domain. |
| What we never collect | Passwords, customer information, your database, your files, or anything behind a login. |
| Who else sees it | Nobody. We don't sell, share or publish what we find, and we don't pass it to anyone else. |
| How long we keep it | 12 months for free alerts, then deleted. Deleted straight away if you ask. Care-plan records are kept while the plan runs. |
| Your rights | Ask for a copy, correct it, or have it deleted — email privacy@hacklert.com and you'll hear back within 48 hours. |