How to choose a CMS security provider: technical criteria and red flags
By Kike Gandia · Co-Founder & CEO, OSCP
The "CMS security" market mixes very different profiles: web agencies offering "security reviews" as a maintenance service, automated tools sold as complete solutions, and cybersecurity firms with genuine technical pentesting capability. Knowing how to tell them apart is critical to choosing well.
What sets a genuine technical CMS security provider apart
A provider with genuine technical CMS security capability:
- Has certified pentesters (OSCP, CEH, eWPT) with documented experience analysing WordPress, Drupal, Magento or PrestaShop
- Delivers reports with evidence (screenshots of the executed exploit, payloads used, affected code) rather than just CVE listings
- Distinguishes between "vulnerability detected" and "vulnerability exploitable in your specific configuration"
- Offers a re-test to verify that findings have been remediated correctly
- Can explain the business impact of each finding, not just the CVSS score
Red flags when evaluating a provider
They use an automated scanner as the main deliverable: If the report is the output of WPScan, Nessus or similar with no additional manual analysis, it is not technical pentesting.
They cannot explain the specific attack vector: A real security analyst can describe step by step how they would exploit each vulnerability found. If all they can say is "plugin X has a high-severity CVE", they have not validated real exploitability.
They do not define a technical scope before the project: A good provider defines what is analysed, how it is analysed and what is not analysed before starting. "Security" services with no defined scope are generic by design.
They promise to "certify" the security of your website: No pentest certifies that an application is secure; it certifies that, within the agreed scope and timeframe, no vulnerabilities of the type analysed were found. A serious provider explains it this way.
Questions to ask before you hire
- What methodology do you use? OWASP WSTG, PTES, OWASP Top 10?
- Can you share a sample report (anonymised)?
- What tools do you use, and what percentage of the analysis is manual?
- Does the team have specific experience with the CMS we use (WordPress, Magento, etc.)?
- Does the price include a re-test?
- How do you handle finding an active compromise during the pentest?
- Is the report valid as evidence for ISO 27001/ENS/PCI-DSS?
FAQ
Can our web agency do the pentest, or do we need an external third party?
An independent assessment by an external third party carries more weight both technically (an outside perspective, free of bias about your own code) and for any compliance or due-diligence process that requires it. ISO 27001 and ENS certifications explicitly require the pentest to be carried out by a team different from the one that develops and maintains the application.
How much should a quality CMS security audit cost?
A genuine technical audit with manual analysis for a medium-complexity installation costs between €2,000 and €8,000 depending on the scope, the number of extensions and the complexity of the environment. Offers below €500 for a "security audit" are usually automated scanners with no manual analysis.
Related service
Related content
- CMS pentesting and audit
- CMS security vs web maintenance
- CMS pentesting for businesses
- CMS security for web agencies