External security review
for your website

We check your website from the outside for exposed files, data and security weaknesses, then tell you exactly what to fix.

  • 01 Main host + up to 5 web subdomains
  • 02 Automated checks + human review
  • 03 Up to 25 public URLs reviewed
  • 04 One re-check within 30 days
  • 05 1 business day delivery
Deliverables

What the report contains

Each finding states what was requested, what the site returned, why it matters, how to fix it and what must change for the issue to be closed.

View detailed example report
FINDING 01 / 06HIGH PRIORITY

Project files are accessible without authentication

Files included in the production deployment disclose exact dependency versions, build structure and source-level information that are not required by website visitors.

EVIDENCE GET /package-lock.json → 200 OK GET /assets/app.js.map → 200 OK Example report format. Evidence in a client report contains the actual host, response details and review time.
WHY IT MATTERS

The files help an attacker identify components, versions, internal paths and suitable known vulnerabilities.

RECOMMENDED FIX

Exclude these files from the production build or deny public access at the web-server level, then verify that both paths return 404 or 403.

Scope

Checks included and excluded

The base package covers the submitted host and up to five reachable web subdomains selected by relevance, with a total limit of 25 public URLs. Other discovered hosts are listed but not reviewed in depth.

WHAT WE REVIEW
  • Files and backupsCommon .env, Git, config copies, SQL/ZIP archives, debug and access/error log paths
  • Build artifactsComposer/npm manifests, source maps, README files, import/export files and deployment metadata
  • Service scriptsTest, installer, health, status and diagnostic pages that should not be public
  • Public data APIsREST/JSON endpoints, media and document listings, exports and endpoints related to forms
  • SubdomainsReachable admin, mail, CRM, connector, staging and other web services found for the domain
  • HTTPS and sessionsCertificates, HTTP redirects, HSTS, mixed content and cookie Secure, SameSite and Domain scope
  • Visible componentsCMS, plugins, frameworks and dependencies correlated with publicly known vulnerabilities
  • Browser data flowSecurity headers, third-party scripts, public forms, CORS signals and exposed document metadata
WHAT WE DO NOT DO
  • No loginWe do not enter admin or customer areas
  • No active attacksNo injection, brute force, fuzzing, malicious uploads or exploit attempts
  • No form submissionsWe do not create test leads, accounts or other records on the website
  • No load testingNo DoS, stress testing or high-volume requests
  • No private systemsNo source code, database, server, cloud storage or files outside the public web surface
  • No absolute inventoryExternally undiscoverable subdomains and randomly named private files cannot be ruled out
  • Not certificationNot a pentest or compliance attestation
Process

How the review is completed

01

Submit the website

Enter one public website and the email for the order.

02

Review the public surface

We enumerate reachable hosts, check public paths and endpoints, then manually verify relevant responses.

03

Receive the report

Get confirmed findings, checked-but-not-found items and remediation steps within 1 business day.

Price and limits

Fixed scope and one-time price

The $99 launch package covers one submitted domain, up to five reachable web subdomains and up to 25 public URLs in total. It does not create a subscription.

$99one-time
$199 regular
  • Main host + up to 5 web subdomains
  • Up to 25 public pages and endpoints
  • Delivery within 1 business day
  • Human-verified findings
  • Web report + downloadable PDF
  • One re-check within 30 days
  • Full money-back guarantee
Review method

What human review adds to automated checks

Automated checks find hosts, paths and technical signals. A TUNDRÄ specialist opens the relevant responses, determines what is actually exposed and records only findings supported by evidence.

AUTOMATED CHECKS

Collect the public surface

  • Find reachable web subdomains and public endpoints
  • Check common file, log, backup and configuration paths
  • Collect TLS, redirect, header, cookie and version signals
HUMAN REVIEW

Verify what the response contains

  • Distinguish real files and data from custom 404 pages
  • Inspect exposed metadata without downloading bulk personal data
  • Record affected URLs, evidence, impact and a specific fix
FAQ

Questions before ordering

What kinds of exposure do you look for?

Common examples are forgotten logs and import files, backup or configuration copies, dependency manifests, source maps, test and installer scripts, publicly listed documents, REST endpoints returning data without authentication, exposed admin or service subdomains, incorrect HTTPS redirects and overly broad session cookies.

Is this a penetration test?

No. This is a non-intrusive review of the public web surface. We identify and verify externally observable exposure, but do not log in, submit attack payloads or exploit vulnerabilities. It is not a substitute for an authenticated pentest.

Can this review damage my website?

The review uses low-rate DNS, TLS, HTTP HEAD/GET/OPTIONS requests and passive inspection. It excludes brute force, load testing, form submissions, file uploads and exploitation, and starts after payment.

What happens if you find something serious?

We document the evidence, explain the likely impact and give you a prioritized remediation path. We do not publish findings or contact third parties without your permission.

Does the report prove my website is secure?

No. The report describes the reviewed public surface, confirmed findings, important checks that returned no result and the limitations of an external review at a specific time. It cannot inspect your database, server filesystem or private systems.

How does the money-back guarantee work?

If you are not satisfied with the completed review, request a refund within 7 days of delivery and we will return the full $99 payment.

Can TUNDRÄ fix the findings?

Yes. Your report can be turned into a ready-to-start TUNDRÄ development backlog. Remediation is quoted separately and never required to receive the report.

Order an external website security review

Main host, up to five reachable web subdomains and 25 public URLs. Confirmed findings, remediation steps, web/PDF report and one re-check within 30 days.

ORDER DETAILS

Start your external review

Enter the website and checkout email. The review starts after payment.

TUNDRÄ External Website Security Review$99