---
title: "Linux server and website security audit · Ing. Brasile"
description: "Fixed price security audit of a Linux server or a PrestaShop or WordPress site: findings, severity, order of fixes. Chartered engineer."
url: https://brasile.pro/en/order/linux-server-security-audit/
lang: en
---
[All engagements](https://brasile.pro/en/order/)

# Security audit of a Linux server or a website

One server or one site at a time, before anything happens. A report with the findings in order of severity.

## Who it is for

**Fixed price.**For before anything happens: a shop going live, a Linux server inherited from another supplier, a client asking whether their site is secure, an agency that wants a written answer to hand to its own client.

One server or one site at a time. The work runs on read only access, granted after the proforma and revoked when the work ends. Nothing gets changed during the audit: first we look, then we decide what to touch.

## What it covers

- server configuration: exposed services, updates, accounts, file permissions, SSH
- site and CMS: version, modules and plugins, back office, upload folders, files left in the docroot
- search for traces of a compromise that has already happened, with the same criteria as the nightly check
- mail and domain: SPF, DKIM, DMARC, security headers, certificates

The report is technical and is not a signed expert report. If you need a document for a court, an insurer or a public call, that is a separate engagement.

## What you get

A report with the findings, the severity of each and the order to fix them in. Every finding says where it is, what it gives an attacker and how to close it. Fixes are not included: they are quoted separately, on the report.

[Order by email](mailto:info@brasile.pro?subject=Order%3A%20security%20audit%20of%20a%20Linux%20server%20or%20a%20site&body=Engagement%3A%20security%20audit%0AAddress%20of%20the%20site%20or%20server%3A%0AHosting%20or%20control%20panel%20%28HestiaCP%2C%20cPanel%2C%20Plesk%2C%20bare%20VPS%29%3A%0ACMS%20and%20version%20%28PrestaShop%2C%20WordPress%2C%20other%29%3A%0AWhy%20now%20%28new%20site%2C%20change%20of%20supplier%2C%20a%20client%20asked%2C%20other%29%3A%0AWhen%20the%20report%20is%20needed%20by%3A%0AWho%20is%20ordering%20%28company%20name%2C%20VAT%20number%2C%20country%29%3A)

## Questions

How long does an audit take? It depends on what is on the machine: a VPS with one shop is read in a few days, a server with twenty sites is not. The timing is in the quote, together with the price. Does the site have to go offline? No. The audit reads, it does not write. The site stays online and nobody notices. Does it work on shared hosting too? Yes, but the site gets checked, not the machine: without a shell the server side is out of sight, and the report says so.

## From the email to the invoice

Times count in working days. If your mail program does not open, write to the address at the bottom of the page with the same subject line.

- **Right away**pick the engagement and send the pre filled email, with the answers to the questions
- **1 working day**you get an acknowledgement with the missing questions, or the quote with price, deliverables and timing. The quote is valid for fifteen days
- **On your yes**the proforma invoice arrives. Fixed price work is paid half up front and half on completion, the cleanup starts on a deposit, the monthly block is paid before the month
- **On payment**work starts. Access is exchanged only now, on a dedicated account and over an agreed channel, never in the order email
- **When the work ends**report, electronic invoice for the balance, access revoked

## What stays out

- the fixes, which are quoted on the report
- Windows servers: the work is on Linux
- the signed expert report, which has its own page

Order from Detector, the client portal: hours come off your prepaid balance and the proforma is issued from there, with no email in between.

[Open Detector](https://detector.prestashops.it/)

## The other engagements

- [Hacked website cleanup](https://brasile.pro/en/order/hacked-website-cleanup/)
- [Monthly Linux server checks](https://brasile.pro/en/order/monthly-linux-server-checks/)
- [Email that gets delivered: SPF, DKIM, DMARC](https://brasile.pro/en/order/spf-dkim-dmarc-email-deliverability/)
- [Website speed and PageSpeed](https://brasile.pro/en/order/website-speed-pagespeed/)
- [Website or VPS migration](https://brasile.pro/en/order/website-shop-vps-migration/)
- [Environmental claims review](https://brasile.pro/en/order/environmental-claims-review/)

[info@brasile.pro](mailto:info@brasile.pro)

## Sources

- [Directive (EU) 2022/2555, NIS2](https://eur-lex.europa.eu/eli/dir/2022/2555/oj)
- [Regulation (EU) 2016/679, GDPR, article 32: security of processing](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
