Public exposure
- Public admin/API exposure
- Source maps
- Backup, config and database files
- Directory listing
- Debug/public metadata
- WordPress/WooCommerce exposure signals
Security Snapshot reviews your approved public app, API, WooCommerce and Stripe/webhook surface for exposure, weak controls and risky routes — then gives you evidence-backed findings, practical fixes, limitations and retest proof.
VaultDevLabs
Security Snapshot Report
Approved public scope
Approved public app/API surface only
Evidence pack
Screenshots, headers, responses, route notes and findings
Recommended fixes
Practical fix guidance and next steps
Retest proof
Optional before/after proof summary
Built for
Dense, practical checks across the approved public app/API surface, with limitations kept explicit.
A static preview of the client-ready structure: findings, positive controls, limitations, practical fixes and retest proof.
Security Snapshot Report
Public sample structure
No-login V2 review
Findings
7
High
2
Medium
3
Low
2
Example findings
Webhook boundary
Review finding
HighInvalid-signature requests returned a controlled rejection response.
Evidence included in full report
Security headers
Recommended fix
MediumCore headers were present except one browser isolation control.
Fix guidance included
Public route hints
Limitation
LowNo OpenAPI file was provided, so route coverage used approved static hints only.
Scope limitation noted
Fixed-fee scope
Prices are shown ex VAT. Review work starts only after written scope and authorisation are confirmed.
Know obvious public exposure fast
£495
First 10 customers or launch-window fixed-scope review for one approved public surface.
Evidence pack for fixes and handoff
£895
Core fixed-fee offer after the launch window, built for owners, agencies and technical teams.
Prove later fixes actually worked
£195
A focused fix-verification pass when changes land outside the included retest window.
Apply selected fixes safely
£1,500
Two-day minimum for tightly scoped remediation after findings are clear.
Catch regression and new exposure
£295/mo
One managed rerun per month with a human-reviewed delta report. Three-month minimum.
Authorised scope, non-destructive checks and clear written boundaries.
Authorised scope only
Non-destructive by design
No credential attacks
No data exfiltration
No hidden changes
Written approval for credentialed testing
Concise answers about scope, access, retest proof and what sits outside the default review.
No for the default review. Security Snapshot can start without passwords and checks the approved public attack surface only.
No. It is an authorised, evidence-backed security review for common public app/API exposure and delivery-ready reporting. It is not a CREST/CHECK pentest or a guarantee that every issue has been found.
The no-login review does not fully test IDOR, role bypass, logged-in business logic, user/admin permission boundaries, brute force, stress, denial-of-service, persistence, or exploitation outside written scope.
Yes, as a separate credentialed V3 review with written approval, test accounts, agreed boundaries and a clear permission to test.
Yes. The report gives practical recommended fixes. Implementation can be quoted separately after the evidence and risk are clear.
Yes. The retest package includes fix verification and a before/after proof summary for agreed findings.
Yes. Security Snapshot can review approved Stripe webhook exposure, invalid-signature behaviour and related WooCommerce or SaaS payment routes.
Yes. WooCommerce public exposure, payment route signals, webhook behaviour and supporting security posture can be reviewed within the agreed public scope.
Start with an authorised no-login external review. You get evidence-backed findings, practical fixes, limitations and retest proof without pretending this is a full pentest.
Security Snapshot is an authorised external security review. It is not a penetration test, Cyber Essentials assessment, PCI ASV scan, legal opinion or certification. Findings reflect the agreed scope and test window only. Security improvements reduce risk; they do not guarantee the absence of compromise.
Authorised testing only. No destructive actions. No credential attacks.