Aegisify company logo
Pricing2026-08-13T00:18:57+00:00

Starting at only $ 79 a month.

Cancel at anytime! 14 Days Money Back Guarantee. No questions asked.

starter

$79/mo
  • Billed Monthly – Cancel Anytime

Included
  • 1 Target / Domain

  • 1 Root Account

  • 1 Admin Account

  • Unlimited Artificial Intelligence
Included in aLL plans
  • External DAST and WordPress Attack-Surface Discovery
    Public routes, sensitive files, administrative surfaces, parameters, forms, APIs, assets, scripts, and exposed application entry points.

  • Authenticated Multi-Role Access-Control Testing
    Guest-versus-user comparisons, role-based route mapping, privilege-boundary review, and IDOR/BOLA replay candidates.

  • REST, GraphQL, OpenAPI, and Web API Security Testing
    Endpoint discovery, methods, schemas, authentication requirements, excessive exposure, mass-assignment indicators, token exposure, and authorization boundaries.

  • Static Code Security Analysis
    PHP, JavaScript, Python, and WordPress-specific security rules, supported by bundled PHPCS/WPCS analysis and optional Semgrep-compatible workflows.

Best Value Deal

Professional

$149/mo
  • Billed Monthly – Cancel Anytime

Included
  • 3 Target / Domain

  • 1 Root Account
  • 2 Admin Account

  • Unlimited Artificial Intelligence
included in ALL plans
  • Known Vulnerability and Software Supply-Chain Analysis
    WordPress core, plugins, themes, Composer, npm, Yarn, pnpm, and Python dependency visibility and advisory matching.

  • WordPress Hardening and Security Misconfiguration Review
    Debug exposure, XML-RPC, file editors, file modification, SSL administration, version exposure, privileged users, REST boundaries, and recovery posture.

  • Malware Heuristics, File Integrity, Permissions, and Drift
    Suspicious PHP patterns, encoded payload indicators, changed files, new files, deleted files, world-writable paths, and recent executable files.

  • WooCommerce and Payment-Surface Risk Intelligence
    Checkout availability, TLS, gateways, test mode, payment logging, webhooks, REST keys, Action Scheduler, templates, HPOS, and sensitive logs.

Business Enterprise

$299/mo
  • Billed Monthly – Cancel Anytime

Included
  • 10 Target / Domain

  • 2 Root Account

  • 5 Admin Account

  • Unlimited Artificial Intelligence
Included in aLL plans
  • STIG/SRG-Style Application and Database Posture Checks
    Cookies, headers, REST/AJAX boundaries, SQL modes, database privileges, local file loading, database encryption and identification.

  • HTTPS, TLS, Headers, Cookies, and Browser Hardening
    Redirect review, certificate, HSTS, CSP, framing, Referrer Policy, MIME protections, caching, mixed-content indicators, and cookie attributes.

  • Authentication and Session Security Review
    Login surfaces, admin boundaries, session fixation, logout invalidation, timeout posture, remember-me behavior, MFA/lockout visibility, and token handling.

  • Continuous Evidence, Correlation, Risk Scoring, and Reporting
    Activities, application logs, telemetry, drift, threat intelligence, evidence correlation, confidence, AI-assisted prioritization, and PDF reporting.

Still having doubts and trouble deciding? Get Answers.
Get the Facts & Proof about Aegisify Audit at https://secure.aegisify.com/facts-proof/

  • The Full detail Listing

Find the signal. Filter the noise. Act with evidence.

Complete Agent-to-SaaS Security Service Inventory

1,000+ WordPress Security Audit Touchpoints, Vulnerability, Code, Compliance, and Risk Intelligence Capabilities

Aegisify Audit combines WordPress security audit intelligence, external DAST, authenticated offensive testing, static code security analysis, software supply-chain vulnerability scanning, malware heuristics, file-integrity monitoring, WooCommerce security review, STIG/SRG-style posture checks, activity evidence, and SaaS reporting in one connected Agent-to-SaaS workflow.


Instead of treating external scans, local WordPress evidence, source code, dependencies, logs, configuration, and business risk as separate products,


Aegisify brings those signals together so site owners, agencies, ecommerce teams, and security operators can see what matters, understand why it matters,


and prioritize the next safe action.

Secure your WordPress site today with smart, automated security technology built to detect risk, strengthen protection, and help you respond faster.

One Connected WordPress Security Intelligence Workflow

The Aegisify Audit SaaS reviews the public attack surface, browser behavior, APIs, routes, sessions, and externally observable security conditions. The Aegisify Agent adds authenticated local evidence from WordPress core, plugins, themes, code, dependencies, database posture, WooCommerce, files, permissions, activity, telemetry, and approved logs. The SaaS can then correlate those evidence sources, assign severity and confidence, compare historical drift, and produce stored or PDF reports.


This inventory includes active tests, passive observations, inventory collectors, continuous sensors, conditional authenticated checks, and report evidence. It should not be interpreted as 292 separate exploit attempts or as a guarantee that every possible vulnerability will be detected.

A

External Exposure, TLS, and Browser Hardening

  • HTTPS reachability and HTTP-to-HTTPS redirect behavior
  • TLS certificate validity and expiration posture
  • Mixed-content and downgrade indicators
  • HSTS and Content Security Policy review
  • Frame and clickjacking protection
  • Referrer Policy and MIME-sniffing protection
  • Permissions Policy and cache-control posture
  • Secure, HttpOnly, and SameSite cookie attributes
  • Sensitive public-file exposure
  • WordPress login and administrative boundary exposure
  • Public route, form, and parameter discovery
  • JavaScript and source-asset discovery
B

SaaS DAST and Active Security Testing

The SaaS implementation contains 41 explicit DAST rules covering externally

observable application risk and safe active probes.

  • Open redirects, reflected XSS, and stored-XSS candidates
  • SQL injection and NoSQL injection indicators
  • SSRF, path traversal, and parameter-pollution indicators
  • CSRF and WordPress nonce posture
  • Session fixation, logout invalidation, and timeout posture
  • Unauthenticated administrative exposure
  • IDOR/BOLA and privilege-escalation candidates
  • HTTP verb tampering and sensitive caching
  • Upload workflow discovery
  • API authentication and unauthenticated method exposure
  • Excessive data exposure and schema mismatch
  • Mass-assignment and token-in-URL indicators
  • GraphQL introspection, depth, and complexity indicators
  • OpenAPI and Swagger discovery
  • DOM-XSS, source-map, client-secret, and token indicators
  • Third-party script inventory and attack-surface graphs
  • Route-contract harvesting and role-replay coverage
C

Authenticated and Advanced Offensive Testing

  • Authenticated route discovery
  • Multi-role authenticated surface mapping
  • Guest-versus-role comparisons
  • Session fixation and session-aging review
  • Logout invalidation and remember-me posture
  • GraphQL schema and type-relationship mapping
  • OpenAPI contract import
  • Browser-assisted route discovery
  • Object-level authorization replay candidates
  • Safe workflow and stored-XSS candidates
D

WordPress Hardening and Misconfiguration Review

  • WordPress version and core-version inventory
  • XML-RPC status
  • Production debug exposure
  • WordPress file-editor controls
  • File-modification controls
  • Administrative SSL enforcement
  • readme.html exposure
  • Privileged configuration and recovery posture evidence
E

Known Vulnerabilities and Software Supply Chain

  • WordPress core, plugin, and theme vulnerability matching
  • CVE identifiers, CVSS details, and fixed versions when available
  • Available core, plugin, and theme updates
  • Disabled automatic updates and inactive components
  • Installed plugin and theme inventory
  • Composer manifest and advisory-tool discovery
  • npm, Yarn, and pnpm manifest and audit-tool discovery
  • Python dependency and pip-audit visibility
  • Dependency evidence for deeper Agent-side risk analysis
F

Static Code Security Analysis

  • Unsafe database-query concatenation and prepared-query misuse
  • Unsafe uploads, dynamic evaluation, and dynamic includes
  • Unsafe deserialization and SSRF-prone requests
  • Missing capability and nonce checks
  • Weak REST permission callbacks
  • Sensitive option modification and unsafe shortcode output
  • Token, secret, and sensitive-data logging indicators
  • Dangerous database tooling and excessive-grant references
  • Direct-access guards, updater safety, and uninstall safety
  • JavaScript DOM-XSS, unsafe templating, and browser token storage
  • Insecure JavaScript REST requests and missing nonce headers
  • Python shell execution, pickle, dynamic SQL, SSRF, and debug indicators
  • Bundled PHPCS/WPCS checks for SQL, validation, escaping, redirects, settings, internationalization, performance, and forbidden functions
G

Malware Heuristics, Integrity, Permissions, and Drift

  • PHP and PHTML inspection in plugin and theme directories
  • Executable-file inspection in uploads
  • Dangerous execution-function indicators
  • Encoding, decompression, and decode-and-execute chains
  • Long encoded payload and variable-function indicators
  • PHP files found in upload locations
  • Suspicious-file heuristics
  • Baseline file hashing
  • New, changed, and removed file detection
  • World-writable files and directories
  • Recently modified executable-file review
H

STIG/SRG-Style Compliance Posture

  • Secure, HttpOnly, and SameSite cookies
  • HSTS, CSP, frame protection, Referrer Policy, and MIME protection
  • XML-RPC restrictions
  • REST authentication and public admin-ajax.php boundaries
  • Disabled WordPress file editors
  • Strict database SQL modes
  • Excessive ALL, FILE, SUPER, GRANT OPTION, CREATE USER, and PROCESS privileges
  • Disabled local_infile and restricted secure_file_priv
  • Database SSL availability or enforcement
  • Database engine and version identification
I

WooCommerce and Commerce Risk Intelligence

  • WooCommerce version, update status, and API surface
  • Checkout availability, TLS, and checkout implementation mode
  • Guest checkout and account-creation settings
  • Payment-gateway inventory and tokenization indicators
  • Payment debug logging and test-versus-live indicators
  • Webhook inventory, missing secrets, and insecure destinations
  • REST API-key metadata and privilege review
  • Legacy API and HPOS posture
  • Action Scheduler backlog and failures
  • Outdated template overrides and sensitive commerce logs
  • Privileged commerce users and business-impact evidence
  • Commerce risk scoring and workflow correlation
J

WordPress Activity and Security Evidence

The Agent records 47 event types that support continuous auditing and

incident context.

  • Login, logout, and password-reset activity
  • User creation, modification, deletion, role, and capability changes
  • Plugin activation, deactivation, update, and deletion
  • Theme activation, update, and deletion
  • WordPress core updates
  • Post and page creation, update, deletion, and restoration
  • Option, media, comment, taxonomy, category, and menu changes
  • Administrative and system-change evidence
K

Telemetry, Logs, Correlation, Risk Scoring, and Reporting

  • Agent connectivity and capability reporting
  • WordPress, PHP, and site telemetry
  • Cron and operational-health visibility
  • Recovery-mode visibility
  • Approved debug-log and application-log retrieval
  • WordPress activity ingestion
  • External and internal evidence correlation
  • Finding severity and confidence
  • Drift and historical comparison
  • Stored report generation
  • PDF security report generation
  • Connected evidence for prioritization and human review

Do Not Forget Aegisify’s Defensive Security Tools

Aegisify Audit helps identify, analyze, correlate, and report WordPress security risk. Aegisify Shields and Aegisify WAF
add defensive controls that help reduce exposure, strengthen WordPress, and protect application traffic. Together,

they support a connected detect, understand, and defend security workflow.

Aegisify company logo featuring a stylized shield icon.

Aegisify Shields strengthens the internal WordPress environment with security hardening, login and registration protection, user and role safeguards, session controls, monitoring, lockouts, and security alerts. It helps reduce common WordPress configuration risks while preserving controlled access and operational visibility.

Aegisify Web Application Firewall logo featuring a stylized shield icon.

Aegisify WAF inspects WordPress application traffic for suspicious requests, abusive behavior, malicious payload indicators, automated attacks, and excessive request activity. Its configurable firewall, rate controls, exclusions, and threat logging protects the application layer without replacing responsible hosting, DNS, network, or edge security.

Evidence Confidence Is Part of the Result
Aegisify distinguishes between observed, suspected, verified, active-safe, authenticated replay, and write-safe findings. These labels help customers understand whether a result came from passive evidence, a safe probe, an authenticated comparison, or a controlled test. View our Facts and Proof Center.

Turn Noisy WordPress Security Data Into Clear Action

Aegisify Audit connects public attack-surface testing with deeper Agent evidence from WordPress,
code, dependencies, files, activity, databases,
WooCommerce, telemetry, and logs. The result is a more
complete security
picture with traceable evidence, confidence labels, historical drift, and

reporting built for serious WordPress sites.

Aegisify Purple Scroll Orbit Preview
See the signal

Find the signal.
Across your entire WordPress environment.

External exposure, code, configuration and activity evidence—correlated in one clear view.

A person using a laptop to sign up for an account on a website.

Got Questions? We got Answers.

Still need answers, contact us today! Or request a demo, get front row.