Red Queen Security
Services  /  Website Security Review
Service — No. 01 Scanning · SSL/TLS · Headers · Dependencies

Website Security Review

Your website is the looking-glass the whole world sees you through — and the first door an attacker tries.

Comprehensive vulnerability scanning and analysis of your entire web presence — your site, its certificates, its headers, and every third-party script riding along. We find and prioritize the security gaps so you can fix them before an attacker ever finds them.

The method

How a scan works

Our scanner crawls every public endpoint — pages, certificates, headers, and third-party scripts — and surfaces each weakness it finds, ranked by severity. This is an illustration of how that process unfolds against a sample site.

redqueen-scan tweedale.example.com
0%
Crawling · 0/8 endpoints
GET /
GET /about
TLS :443 handshake
GET /search?q=
GET /contact
GET /wp-content/plugins/contact-form-pro
GET /wp-admin
GET /sitemap.xml
Findings · 0
HIGH CVSS 7.4
Weak TLS configuration
TLS 1.0/1.1 enabled · 3DES (SWEET32) · no HSTS
CRITICAL CVSS 9.3
Reflected XSS in site search
q= reflected unescaped · CWE-79
HIGH CVSS 9.8
Outdated plugin · known CVEs
contact-form-pro 3.1.4 · CVE-2024-10271

Why it matters

43%

of cyberattacks target small businesses specifically

39s

between automated attacks on an average internet-facing host

60%

of small companies close within 6 months of a breach

Sources — Verizon DBIR · University of Maryland · U.S. National Cyber Security Alliance

What's included

Every crack, found first

A full sweep of your public web surface — delivered as a prioritized, plain-language report your team can act on, not a raw scanner dump.

01

Vulnerability scanning

Automated and hands-on testing of your site and stack for known weaknesses — injection flaws, exposed admin panels, outdated software, and misconfigurations that scanners alone miss.

02

SSL/TLS & encryption

We check your certificates, protocol versions, and cipher configuration — and flag expired certs, weak ciphers, and mixed-content warnings that quietly erode trust.

03

Security headers

CSP, HSTS, X-Frame-Options and the rest — the quiet browser-level defenses that stop clickjacking, content injection, and downgrade attacks. We tell you exactly what to set.

04

Third-party & dependency risk

Every plugin, library, and embedded script is a door someone else built. We inventory them, check for known vulnerabilities, and flag what's abandoned or over-trusted.

How it works

A review in three moves

Week 1

Map & crawl

We map your full web surface — pages, subdomains, endpoints, and assets — so nothing public is left untested. No agents, no downtime.

Week 1–2

Scan & verify

Automated scanning backed by manual verification — so you get real, confirmed findings, not a wall of false positives to wade through.

Week 2

Report & remediate

A working session to walk the findings together. We help you fix the critical items on the call and leave a clear roadmap for the rest.

The report

A report you can act on

You walk away with a prioritized findings report, a remediation roadmap, and a one-page summary for leadership — every gap ranked by real risk, with the exact fix beside it.

p. 04
03 — Findings overview
3 findings
Critical1
High2
Med / Low0
p. 02
02 — Severity matrix
Level Description CVSS
Critical Immediate exploitation likely; severe impact 9.0+
High Exploitable; significant data or access risk 7–8.9
Medium Conditional risk; harder to exploit 4–6.9
Low Limited impact; best-practice gap 0.1–3.9
Info Hardening recommendation, no direct risk
Red Queen Security
Confidential report

Website
Security
Review

Prepared for Tweedale & Co.
Engagement RQS-2026-0418
Date 18 April 2026
Three findings · one critical

Common questions

Straight answers about scanning, downtime, and what we touch.

Will scanning slow down or take my site offline?

No. We use non-intrusive, rate-limited testing tuned to your environment, and schedule anything heavier for off-peak hours. Your visitors won't notice a thing.

Do you test production or a staging copy?

Your call. We can test production safely, or work against a staging mirror if you prefer. We agree the scope and rules of engagement in writing before anything starts.

What if you find something critical mid-scan?

We don't wait for the report. Anything actively dangerous gets flagged to you immediately, with a clear explanation and the fastest safe path to shut it down.

Get started

Find the cracks before they do

Book a free 30-minute consultation. We'll talk through your site and where a security review would help most — no obligation.

Non-intrusive — no downtime for your site
Prioritized report within 1–2 weeks
Plain language, ranked by real risk