Website & Cyber Security Audit
for Associations
A fixed-price, engineer-led website and cyber security audit of your WordPress, Drupal or Joomla site, member portal and payment pages. Board-ready report in 5 business days, from $1,950.
- Manual, Not Automated
- Board-Ready Report
- Fixed Price From $1,950
Over a decade of website security expertise
Associations Are Now a Prime Target
In 2025, business and professional associations were the 4th most-breached sector notified to the OAIC, with 103 notifications. Only health, finance and the Australian Government reported more.
Analysis of the OAIC data for the second half of 2025 found 89% of association breaches were malicious or criminal attacks, not staff mistakes.
And the way in is rarely the membership database itself. It is the website provider, a plugin, a payment script, an events or learning platform, or a vendor who kept data long after the contract ended.
Your members trust you with their details. An audit shows you exactly where that trust is exposed.
What Is a Cyber Security Audit?
A cyber security audit is an independent check of how well your organisation protects its systems and data, and where it is exposed. For most associations, the biggest exposure isn’t the office network. It’s the website and everything connected to it: the member portal, event registrations, renewal and payment pages, forms, plugins and the vendors who can log in.
That is what our audit covers in depth: your website and hosting, member portal integration, payment pages, member email authentication, third-party access and every place member data travels. It is a website security audit and a cyber security audit of your member-facing systems in one. If you also need a whole-of-organisation review or a formal penetration test, we will tell you.
We Find Your
Weak Points
Before Attackers
Do
We Find Your Weak Points
Before Attackers Do
We Find Your Weak Points
Before Attackers Do
Most “website security checks” are a free automated scan that lists software versions and stops there. Our website security audit is a manual, forensic review by engineers with over a decade of hands-on experience securing WordPress, Drupal and Joomla sites.
We check what scanners miss: hidden admin accounts, injected scripts, malicious redirects, rogue scheduled tasks, modified core files, abandoned plugins and exposed keys, plus every place member data travels, from enquiry forms to your member portal and payment pages.
You get a plain-English, board-ready summary, a full technical report with every finding rated and the fix spelled out, and a walkthrough call. If we find nothing material, you don’t pay.
Related Services
Why Boards
Trust Our
Audits
Why Boards Trust
Our Audits
Why Boards Trust
Our Audits
Evidence of Reasonable Steps
APP 11 now expressly includes technical and organisational measures. An independent technical audit gives your board documented evidence of the steps you have taken to protect member data.
Supply-Chain Focus
Most association breaches start with a third party. We map every vendor, plugin and integration that can reach member data, including your web provider.
Fixed Price, No Surprises
$1,950 for brochure and lead-generation sites, $2,950 for membership, portal and payment sites. Find an active compromise? We quote the clean-up first and fix it the same day.
Association Breaches Notified to the OAIC in 2025
Of Association Breaches in H2 2025 Were Malicious
Business Days to Your Board-Ready Report
Data Breaches Notified in 2025, a Record
How It Works
We confirm your platforms, member systems and payment pages, then give you a fixed price before anything starts.
Step 2: We Audit
Your Site
An engineer reviews your site, hosting, integrations and data flows over five business days, working carefully alongside your team and vendors.
Step 3: Get Your
Board-Ready Report
A one-page risk summary, full technical findings with fixes, and a 45-minute walkthrough with the engineer who did the work.
Brands We Have Helped
















What People Say
Makes the Magic Happen
“Love the professional finishes . Dustin and the team know how to make the magic happen.”
Sam Hunter
Corporate Headshot Photographer
Always Shows Up
“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”
Kym Bolger
Social Media Marketing
Responsive Professionalism
“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”
Ivan Huang
CPA
What You Can Expect
What’s Checked
Pixelbird Audit
Free Scanner
Manual Forensic Review
With Us
An engineer hunts for hidden admins, injected scripts and rogue tasks
With Them
Automated output full of false positives
Plugins, Themes & Modules
With Us
Every component checked, including abandoned ones
With Them
Version numbers only
Member Portal & Integrations
With Us
SSO, APIs and member data flows reviewed
With Them
Out of scope
Payment & Renewal Pages
With Us
Third-party scripts reviewed against PCI DSS 4.0
With Them
Not checked
Third-Party Access
With Us
Agency, vendor and plugin access mapped
With Them
Ignored
Backups & Recovery
With Us
Off-site backups checked and a restore path confirmed
With Them
Assumed to work
Hosting & Logins
With Us
PHP, SSL, file permissions, 2FA and user access reviewed
With Them
Surface-level checks
Member Email Authentication
With Us
SPF, DKIM and DMARC checked so renewals aren’t spoofed
With Them
Not checked
Privacy & Data Handling
With Us
Where member data goes and who can reach it (APP 11)
With Them
Not covered
Board-Ready Report
With Us
One-page summary, rated findings and a walkthrough call
With Them
A raw PDF export
WordPress Security Audit
Most association websites run on WordPress, and most WordPress compromises come through plugins, themes and logins rather than WordPress itself. Our WordPress security audit goes through what scanners skip:
- Every plugin and theme, including abandoned, nulled and unsupported ones
- Modified core files, injected JavaScript and hidden redirects
- Forgotten administrator accounts, over-powered user roles and missing two-factor authentication
- Rogue scheduled tasks and backdoors hidden in the uploads folder
- Membership, events, forms and payment plugins that handle member data
- Exposed configuration files, API keys and debug logs
We bring the same depth to Drupal and Joomla. Already seeing spam pages, strange redirects or a Google warning? Skip the audit and go straight to hacked website repair.
What’s in Your Audit Report
- One-page board summary: your overall risk in plain English, ready for the next board or committee meeting.
- Rated findings: every issue rated by severity, with what it means for member data and the exact fix.
- Vendor and data-flow map: every plugin, platform and provider that can reach member data, and who has access.
- Prioritised action plan: what to fix now, what can wait, and what to plan for at your next rebuild.
- 45-minute walkthrough with the engineer who did the work, for you, your board or your web provider.
Price and timeframe: $1,950 for brochure and lead-generation sites, $2,950 for membership, portal and payment sites. Board-ready report in 5 business days. See pricing.
Frequently Asked Questions
How much does a website security audit cost?
It is a fixed price: $1,950 for brochure and lead-generation sites, and $2,950 for membership, portal and payment sites. You get the price on the scoping call, before any work starts. If we find nothing material, you don’t pay.
How long does a cyber security audit take?
After a free scoping call, the audit itself takes five business days. You then get your board-ready report and a 45-minute walkthrough call with the engineer who did the work.
How is this different from a free website security check?
A free website security check or vulnerability scan only sees what is visible from outside, such as software versions and SSL. It can’t see hidden admin accounts, injected code, rogue scheduled tasks, vendor access or where member data goes. Our audit is a manual review from the inside, by an engineer, with every finding checked so you don’t chase false alarms.
Is this a penetration test?
No. A penetration test simulates a full attack and often costs $6,000 or more. Our audit is a manual security and privacy review of your website, hosting, integrations and data handling, priced so it rarely needs board sign-off. If you need a full pen test, we will tell you.
Does the Privacy Act apply to our association?
If your association’s turnover is over $3 million, it provides a health service, or it shares member data with sponsors or partners for a benefit, the Privacy Act very likely applies to you. We are not lawyers, so get advice on your own position. Our report gives your advisers the technical evidence they need.
We use iMIS, Salesforce or another platform. Can you still audit us?
Yes. The audit covers your public website, member portal integration, payment pages and data flows whatever your AMS, including iMIS, Salesforce and Dynamics. Deep code review applies to WordPress, Drupal and Joomla, our core platforms.
What if you find we have already been hacked?
We tell you straight away, quote the clean-up and fix it the same day once you approve. And if the audit finds nothing material, there is no charge.
What happens after the audit?
You own the report and can hand it to any developer. Many clients move onto one of our care plans so the fixes stay fixed, but there is no obligation.