Buyer’s guide for site owners
Website security audit cost: what you should actually pay
A website security audit can cost $0 or more than $20,000. It depends on who does it and how deep they go. Here is what each price level buys, what moves the number, and how to budget without overpaying.
Search for this and you mostly find forum threads where everyone gives a different number, or “contact us” pages. This page gives you real price levels for a security audit of a website. An SEO or speed audit is a different job. If you want the penetration-testing side of pricing, see our penetration test cost guide.
Website security audit cost by tier
| Tier and typical cost | What you get | Best for | What it misses |
|---|---|---|---|
| $0: free scanners and plugins | Automated checks for known issues and public exposure. Bug Circuit’s free Pulse scan is passive and touches nothing on your site. | A first look, and routine checks between audits | Logic and access-control flaws, such as one customer seeing another customer’s order. Results can include false positives a person must confirm. |
| Paid automated scanning subscriptions (billed monthly or yearly) | Scheduled scans that run on their own and flag known problems. Prices depend on the product and the number of sites, so check each vendor’s current page. | Watching for known issues once the basics are fixed | The same blind spot as free scanners. A person still has to judge what matters and fix it. |
| $49 to $299: focused manual audit (Bug Circuit) | A security expert tests one website by hand. You get a written report with every issue, its severity, evidence, plain-English impact and exact fix steps. The $299 plan adds fixes, retesting and 3 months of cover. | Small business sites, WordPress, Shopify stores, small SaaS | Scoped to one website. It is not a compliance certificate or an enterprise engagement. |
| $5,000 to $20,000+: agency or consultancy audit, full penetration test | Custom scope, senior testers (roughly $900 to $2,200 per day), a formal report, and sometimes retesting. | Large or custom applications, regulated industries, buyers who need a named firm | Often more than a simple site needs. Retesting can cost extra. |
Where does $5,000 to $20,000 come from? Do the sums. Say a test takes 5 to 10 days. At $900 to $2,200 a day, 5 days is $4,500 to $11,000 and 10 days is $9,000 to $22,000. You are paying for senior human hours. The same logic is why a tightly scoped audit of one small site can cost so much less. To estimate a penetration test price from your own scope, try the pentest cost calculator.
What changes the price of a website security audit
- Scope: a five-page brochure site and an online store are very different jobs. More pages, features and integrations mean more testing time.
- Number of sites: every extra site, app or API adds work. Circuit covers one website. For several, ask about Enterprise (one scoped engagement, custom fixed quote in USD).
- Logins and user roles: each role (visitor, customer, staff, admin) must be tested for what it can see and do. This is where access-control flaws hide.
- Checkout and payments: money moving through your site calls for extra care, and extra time.
- APIs: each set of endpoints is more surface to test.
- Retesting: checking that a fix really worked. Some quotes include it. Some charge for it.
- Fixes: finding a problem and fixing it are separate jobs. Many audits stop at the report.
- Paperwork: a plain, clear report is cheap. Compliance-style documents add cost worth paying only if someone requires them.
Cost by type of website
A WordPress site is a well-known scope: most of the risk sits in plugins, themes and logins (see our WordPress security audit). On a hosted store the platform covers part of the work, so the risk moves to apps, staff accounts and custom theme code (see Shopify and online stores). Custom sites and SaaS products usually take the most testing time, because logins, roles and APIs widen the scope (see audits for startups).
Hidden costs, and how to budget each year
An audit tells you what is wrong. It does not fix it. Budget for these as well:
- Fixing: developer or agency time to apply the fixes. A report with exact fix steps makes this faster and cheaper than a vague one.
- Retesting: ask whether it is included and what it costs.
- Your own time: answering questions, sharing test accounts and approving changes.
- Repeat audits: a new checkout, login system or platform move needs another look.
That is why Signal exists. For $299 you get the audit, our fixes for the high and critical issues (done with you), a retest and 3 months of cover as you ship changes, in one payment. A full year of cover is $407, about $34 a month, with no subscription.
A simple yearly budget for a small site
- All year, $0: keep your platform, plugins and themes updated, use unique passwords with two-factor login, and keep backups. Run the free security check whenever you like.
- Once a year and after any big change: one manual audit. That is $49 for a report, or $299 to have the high and critical issues fixed with you.
- Set aside fix time: some developer hours for what the report finds. The size depends on the report.
- Only if someone requires it: $5,000 to $20,000 or more for a named firm, when a contract, insurer or framework asks for one.
How to get a quote that is not inflated
- Get the scope in writing: which domains, user roles and APIs. A price given before anyone asks about your site is a guess.
- Ask for days and day rate. Price is days times rate, and $900 to $2,200 a day is the usual range for experienced manual testers. If a quote is far above that, ask why.
- Ask who does the testing and ask for a sample report. A person or a tool with a logo? See what a real one looks like in our sample report.
- Ask if retesting is included and what it costs if not.
- Prefer a fixed price for a defined scope, so surprises cannot appear later.
- Compare scope line by line, not just totals, and skip add-ons you did not ask for, such as a year of monitoring bundled onto a one-time audit.
More help in how to choose a penetration testing company.
Where Bug Circuit fits, and where it does not
Bug Circuit is built for small business websites. Prices are in US dollars, paid once through Stripe. Reports usually arrive within about 5 business days after you verify your domain. Before any active testing we verify ownership and record an Authorization to Test, and there is a 14-day money-back guarantee if testing has not started. Customers rate us 5.0 out of 5.
- Free Pulse scan: see what attackers can see, with nothing touching your site. Run it now.
- Circuit, $49: a full manual audit of one website with a written report. Get Circuit.
- Signal, $299 for 3 months: everything in Circuit, plus fixes, retesting and cover. Get Signal.
A cheaper audit is the wrong choice in two cases. First, if a compliance framework, insurer or customer contract names an accredited firm. Bug Circuit is not a PCI DSS QSA, not a HIPAA auditor and does not issue compliance certifications, so our report is extra evidence, never a certificate. Second, if you run a large custom platform that needs a bigger engagement. We will tell you straight if that is you. Ask us.
Frequently asked questions
How much does a website security audit cost?
How much is a website audit?
How much does website security cost per month?
How much should a single audit cost?
How much does a cyber security audit cost?
How do you security audit a website?
Do I need a security audit for PCI DSS, HIPAA or SOC 2?
Keep reading
See what an audit would find, for free
Run the free passive check on your domain first. No login, no card, no impact on your site. Then pick the plan that fits your budget.
Ready for the full manual audit? See pricing