- Job title
- Customer Relations Manager
- Sector
- Law
- Organization type
- boutique agency
- Joined
- Oct 2024
- Message
- 380
We are an eight-person US-based e-commerce business selling custom kitchen products. We run on WordPress and an e-commerce plugin, with an annual turnover of around 420,000 dollars. Last month, a local cybersecurity consulting firm quoted us 2,500 dollars for a comprehensive penetration test and audit of our site. For a small business like ours, that is a substantial budget line item.
Before spending any money, we tested our site using free online site security check tools on the web. Curiously, while one tool gave us an A rating, another flagged our site as high risk due to an outdated plugin and missing security headers.
What do these free scanners actually detect, and what critical vulnerabilities do they miss entirely? How should we interpret conflicting results, and at what point does hiring a professional paid audit become inevitable?