Sample Report · Real Case Study

See exactly what you'll receive.

Not a scanner printout. A client-ready report with an executive summary, severity-rated findings, hard evidence, and a prioritised fix plan. Below is a real engagement — fully anonymized — plus the full report itself.

Real, anonymized engagementWeb + PDF deliveredClient reports stay private
What's inside

Every report includes

The same structure whether it's a routine audit or a live incident — so it's readable by your team and actionable on day one.

  • Executive summary written for decision-makers
  • Visual “at a glance” risk dashboard
  • Severity-rated findings with CVSS scores
  • Evidence and indicators of compromise (IOCs)
  • Confirmed vs. suspected, clearly separated
  • Malware analysis with the actual injected code
  • Likely infection vector and persistence points
  • Prioritised P0–P3 remediation plan
Case study

Anatomy of a live compromise

Professional services · WordPress + ElementorActive compromise confirmed

The site looked completely normal to its owners, but was quietly serving malicious JavaScript to every visitor.

Site-wide malware injection

An obfuscated loader disguised as a “performance optimizer” was present in the head and footer of every page.

Hidden command-and-control

It base64-decoded hidden Traffic Distribution System domains at runtime, then fetched and executed remote attacker code in the visitor’s browser.

Nulled premium plugin

An unofficial redistribution of a premium page-builder plugin — unmaintained, unpatched, and the most probable entry point.

Exposed admin account

Open REST user enumeration disclosed a predictable administrator username, lowering the cost of a credential attack.

The outcome

What the client walked away with

  • Confirmed active compromise with reproducible evidence
  • Documented every IOC (domains, script handles, encoded strings)
  • Identified the most likely infection vector and persistence
  • Delivered a P0–P3 plan the client could action immediately
16
Findings documented
2
Critical severity
5+
IOCs captured
P0–P3
Prioritised plan
FAQ

About our reports

Is the sample report from a real assessment?
Yes. It is a genuine production WordPress engagement, fully anonymized — the client name and domain are replaced throughout. The technical findings, evidence and remediation plan are exactly as delivered.
Will my report look like this?
Yes — same structure and depth. The length varies with the size of your site and how much we find, but every report includes the executive summary, severity-rated findings, evidence and a prioritised remediation plan.
Do you publish client reports?
Never. Real client reports are private and delivered through an encrypted, password-protected link that only you and your team can open. The public sample exists purely so prospects can see our format before engaging.
Can I get the report as a PDF?
Yes. Every engagement is delivered as both a shareable web report and a branded, print-ready PDF you can forward to stakeholders, insurers or auditors.

Want a report like this for your site?

Start with a non-destructive security scan and get the same clarity — findings, evidence, and exactly what to fix first.