Security / Passive baseline
A website security audit of browser-facing protections.
The responses your site sends can reveal missing security headers or cookie settings that deserve a closer look. I use ZAP's passive baseline to identify warnings, then review what they mean for the agreed pages.
This is a starting-point review with relevant source-code findings and practical recommendations. It doesn't include active attacks and isn't a penetration test or proof that your site is secure.
Website security baseline
$500 USD
Authorized passive checks and reviewed findings for agreed URLs. Ownership or permission is required before scanning.
Request a security baselineMost audits take about two weeks after scope and access are confirmed.
What the baseline checks
ZAP observes HTTP responses and reports passive alerts. I review those alerts for relevance, explain the evidence, and look at the related source code where it helps identify a change.
A warning can point to a useful improvement, but its severity and confidence still need context. The report records both so your team can assess the recommendation.
- Ownership or authorization confirmed before the scan starts.
- Passive alerts, including browser security-header and cookie configuration warnings where applicable.
- A one-minute spider that may fetch linked pages, with reported alerts limited to agreed URLs.
- Reviewed risk, confidence, and evidence for relevant findings.
- Suggested mitigations and a prioritized developer task list.
What can a website security headers audit tell you?
Security headers tell the browser how to handle parts of a page's behavior. A passive review can flag a missing or questionable setting in the responses it observes. That gives us something specific to investigate in the site's configuration.
Headers alone don't establish whether an application is secure. This baseline doesn't assess account security or infrastructure, and it doesn't actively try to exploit the site.
We'll walk through the findings together. Re-testing is available after fixes, but a failed scan will be reported as incomplete, not as evidence that an issue is resolved. Read more about why website security matters.
Questions about the security baseline
How much does a website security audit cost?
This passive baseline is $500 USD for the agreed scope. We confirm the target URLs and your authorization before starting. A penetration test is a different service and isn't included in this price.
Does a passive scan make requests to my site?
Yes. Passive describes how ZAP analyzes the responses, not an absence of traffic. The baseline uses a one-minute spider that may fetch linked pages. Only alerts matching the agreed URLs enter your report; no active attacks are run.
Does a report with no alerts mean the site is secure?
No. It means the completed checks didn't report relevant alerts for the observed responses. Issues outside those checks or pages can still exist. A blocked or failed scan is incomplete, and I won't describe it as a pass.
Start with an authorized baseline.
Send me the site you own or have permission to scan, along with the pages you'd like reviewed. We'll confirm the scope before any checks begin.
Get a security baseline proposal