Public exposure
- Public admin/API exposure
- Source maps
- Backup, config and database files
- Directory listing
- Debug/public metadata
- WordPress/WooCommerce exposure signals
Security Snapshot reviews your approved public app, API, WooCommerce and Stripe/webhook surface for exposure, weak controls and risky routes — then gives you evidence-backed findings, practical fixes, limitations and retest proof.
VaultDevLabs
Security Snapshot Report
Approved public scope
Approved public app/API surface only
Evidence pack
Screenshots, headers, responses, route notes and findings
Recommended fixes
Practical fix guidance and next steps
Retest proof
Optional before/after proof summary
Built for
Authorised scope only
Human-reviewed findings
No-login V2 by default
Retest proof available
Choose your review
Same fixed-scope Security Snapshot system, routed by what you need reviewed.
For public websites, SaaS apps, admin dashboards and general web exposure.
View Website SnapshotFor WooCommerce stores, Stripe webhooks, checkout-adjacent exposure and payment-route confidence.
View WooCommerce ReviewFor public APIs, OpenAPI/Swagger, GraphQL, CORS, webhooks and route exposure.
View API ReviewDense, practical checks across the approved public app/API surface, with limitations kept explicit.
A static preview of the client-ready structure: findings, positive controls, limitations, practical fixes and retest proof.
Security Snapshot Report
Public sample structure
No-login V2 review
Findings
7
High
2
Medium
3
Low
2
Example findings
Webhook boundary
Review finding
HighInvalid-signature requests returned a controlled rejection response.
Evidence included in full report
Security headers
Recommended fix
MediumCore headers were present except one browser isolation control.
Fix guidance included
Public route hints
Limitation
LowNo OpenAPI file was provided, so route coverage used approved static hints only.
Scope limitation noted
Security Snapshot path
Fixed-fee scope
Three clear ways to start. Prices are shown ex VAT. Review work starts only after written scope and authorisation are confirmed.
Know obvious public exposure fast
£495
Launch offer
First 10 customers or launch-window fixed-scope review for one approved public surface.
Evidence pack for fixes and handoff
£895
Core fixed-fee offer after the launch window, built for owners, agencies and technical teams.
Prove fixes actually worked
£1,250
Review plus focused retest
For teams that already know they need the review and a later fix-verification pass after changes are deployed.
After your review
These are not needed to start. They become useful after the report shows what should be fixed, retested, or watched over time.
Apply selected fixes safely
From £1,500
Two-day minimum for tightly scoped remediation after findings are clear.
Catch regression and new exposure
£295/month
One managed rerun per month with a human-reviewed delta report. Three-month minimum.
After payment
The commercial flow stays separate from permission to test. Written scope still comes first.
Payment starts the commercial request and creates the order trail. It does not expand the approved testing scope.
You confirm the public URLs, APIs, webhook paths, route hints and written boundaries before review work starts.
The review stays non-destructive by default and records evidence, positive controls, limitations and recommended fixes.
You receive the client-ready report. Retest proof can compare before/after evidence once fixes are deployed.
Authorised scope, non-destructive checks and clear written boundaries.
Authorised scope only
Non-destructive by design
No credential attacks
No data exfiltration
No hidden changes
Written approval for credentialed testing
Concise answers about scope, access, retest proof and what sits outside the default review.
No for the default review. Security Snapshot can start without passwords and checks the approved public attack surface only.
No. It is an authorised, evidence-backed security review for common public app/API exposure and delivery-ready reporting. It is not a CREST/CHECK pentest or a guarantee that every issue has been found.
The no-login review does not fully test IDOR, role bypass, logged-in business logic, user/admin permission boundaries, brute force, stress, denial-of-service, persistence, or exploitation outside written scope.
Yes, as a separate credentialed V3 review with written approval, test accounts, agreed boundaries and a clear permission to test.
Yes. The report gives practical recommended fixes. Implementation can be quoted separately after the evidence and risk are clear.
Yes. The retest package includes fix verification and a before/after proof summary for agreed findings.
Yes. Security Snapshot can review approved Stripe webhook exposure, invalid-signature behaviour and related WooCommerce or SaaS payment routes.
Yes. WooCommerce public exposure, payment route signals, webhook behaviour and supporting security posture can be reviewed within the agreed public scope.
Start with an authorised no-login external review. You get evidence-backed findings, practical fixes, limitations and retest proof without pretending this is a full pentest.
Security Snapshot is an authorised external security review. It is not a penetration test, Cyber Essentials assessment, PCI ASV scan, legal opinion or certification. Findings reflect the agreed scope and test window only. Security improvements reduce risk; they do not guarantee the absence of compromise.
Authorised testing only. No destructive actions. No credential attacks.