Curiosity Site audits · Plain English · No scanners
For website owners, editors, and small teams

A plain-English audit of your website.
Five deliverables. Five business days.

A single human-written audit covering security, privacy, performance, accessibility, and design. No noisy scanners. No fearmongering. Just a clear list of what is wrong, what it would cost to fix, and what to do next.

£499 flatNo retainer. International invoicing on request.
Turnaround, 5 business days.
Payment, 50 percent kickoff and 50 percent on delivery.

What you receive

01

Written audit

Eight to fifteen pages, severity-sorted, every finding includes a one-line fix.

02

Site-wide review

Extends beyond the homepage to the standard attack surface: login, REST API, sitemap, feed, common WordPress paths, and a sample of internal pages.

03

Live demo

One representative page rebuilt to show how the recommendations land, with your brand and advertisers preserved.

04

Slide deck

A short presentation of the audit and the proposal, ready to share with your team or the people who pay for the work.

05

Walk-through call

45 minutes. I take you through every finding, answer questions, and help you prioritise.

What I check

SecurityCMS version disclosure, REST API enumeration, XML-RPC, login brute-force protection, admin path exposure, third-party script supply chain, OAuth tokens, full security-header pass.
PrivacyTrackers loaded before consent, cookies set on first visit, leaked emails in public content, RSS or sitemap information disclosure.
PerformancePage weight, third-party origin count, render-blocking assets, image lazy-loading, font loading strategy, estimated Lighthouse score.
AccessibilityWCAG 2.1 AA contrast, viewport zoom, heading order, image alt coverage, focus visibility, skip link, keyboard navigation.
DesignTypography hierarchy, layout consistency, mobile breakpoints, ad placement quality, social preview cards, broken shortcodes.
Code qualityDead CSS, unused plugins, invalid HTML, version fingerprinting, abandoned dependencies, inline event handlers.
SEO and structurerobots.txt, sitemap, canonical tags, redirect map readiness for any future migration.

No noisy scanners. Every probe is a single HEAD or GET request made with a standard browser User-Agent, the way a real visitor's browser behaves.

How it works

Day 0
Kickoff call (30 minutes)

You share the URL and any context I should know. Advertisers, recent incidents, things you do not want changed.

Days 1 to 3
The audit runs

No access to your hosting needed for the standard package. I probe public endpoints only.

Day 4
Drafting

I write the report and build the slide deck. Live homepage demo if you booked that package.

Day 5
Walk-through call (45 minutes)

I take you through every finding, prioritise, and hand over the full folder.

What is in scope, and what is not

In scope

  • Homepage HTML in detail
  • Security headers (CSP, HSTS, X-Frame, X-Content-Type, Referrer, Permissions)
  • REST API enumeration paths
  • Login and admin paths
  • XML-RPC, RSS feed, sitemap, robots.txt
  • Standard WordPress and Drupal attack-surface paths
  • A sample of internal pages from the sitemap
  • Third-party trackers and consent flow
  • Accessibility signals from the markup (WCAG 2.1 AA)
  • Performance signals (asset count, page weight, font strategy)

Not in scope

  • Penetration testing or active exploitation
  • Authenticated user-journey testing
  • Payment flow and checkout audits
  • Source-code review or hosting-config review
  • Database or backup security
  • Brute-force or rate-limit testing against live forms
  • Probing non-standard ports or subdomain portals
  • Mobile app review

Any of the above can be quoted as a separate engagement.

Proof, three recent audits

JimiDisu.com

Nigerian news commentary site. 15 security findings including open REST API user enumeration, no brute-force protection on the login page, and 10+ trackers running without consent. Full report, redesign demo, and slide deck.

github.com/AdesojiDapo/jimidisu-redesign

ipintegration.com

UK enterprise tech site. Already well-hardened. Audit found two High items (WCAG-blocking viewport and a missing CSP) plus a tight list of minor improvements. About 16 engineering hours of remediation.

github.com/AdesojiDapo/ipintegration-audit

vgpensions.com

Nigerian pension fund administrator. Regulated financial services site. Strong baseline hardening, four High items, all best-practice gaps rather than active vulnerabilities. About 24 engineering hours plus a clear follow-up.

github.com/AdesojiDapo/vgpensions-audit

Same checklist across all three. Same severity grading. Same deliverables. The reports themselves are free to read before you decide.

What it costs

Audit

Standard audit

£499flat fee, all in
  • Written audit report
  • Site-wide review
  • Slide deck
  • 45-minute walk-through call
5 business days
Custom

Full redesign + migration

From £4,995scoped per project
  • Everything above, plus
  • Every template rebuilt
  • Content migration with redirect map
  • 30 days of post-launch support
4 to 6 weeks

Book a kickoff call

One-line email with your site URL. I reply within one business day with a 30-minute slot.

Email Curiosity →