The Security Audit • Specialty 13 of 13

When dealer sites get breached, the cost is not measured in repair dollars. It is measured in OEM relationships, customer trust, and headlines.

We audit mixed content, outdated CMS modules, exposed admin paths, missing security headers, CSP, and known-vulnerable dependencies. The layer that ends careers when it goes wrong.

See pricing

Why security debt accumulates silently

Most dealer-site breaches are not the result of sophisticated attacks. They are the result of an outdated module, an exposed admin URL, or a default credential left in place.

Security configuration on most dealer sites was set years ago and has not been reviewed since. Modules update; defaults change; new vulnerabilities are disclosed quarterly. Without review, the gap widens silently.

The cost of a breach varies, but the floor is high: customer notification, OEM reporting, brand damage, and remediation. The cost of preventive review is a fraction of any of those.

What nobody has told you

"Your platform vendor handles platform-level security. The custom modules, third-party scripts, and one-off integrations on top of the platform are usually not their problem and often nobody's."

"Default admin URLs, default credentials on internal tools, and exposed staging environments are more common than vendors admit."

"Penetration tests are expensive and infrequent. Most dealer sites have never had one. The basics catch most issues for a tiny fraction of the cost."

"You may be locked down. You may have low-hanging exposure. The scan tells you in 30 seconds."

The five failures we find on almost every dealer site

On most dealer sites in this area, you almost certainly have at least three of these.

HIGH

Outdated CMS or known-vulnerable modules

CMS or plugin versions with publicly disclosed vulnerabilities. Automated scanners exploit these constantly. The fix is updating to current; the cost of not is real.

How we fix it: Inventory all modules, identify CVE-flagged versions, schedule and apply updates with rollback plan.

HIGH

Exposed admin paths

Admin URLs at default paths (/admin, /wp-admin) without IP restriction or rate limiting. Combined with default credentials anywhere, this is the highest-risk exposure.

How we fix it: Move admin to non-default path, IP allow-list, multi-factor auth, brute-force lockout.

MEDIUM

Missing or weak Content Security Policy

CSP headers absent or set to permissive. Allows arbitrary script injection from compromised third parties. Increasingly important as ad and analytics ecosystems expand.

How we fix it: Deploy CSP in report-only mode, monitor violations, transition to enforcing mode with allow-list.

MEDIUM

Mixed content over HTTPS

HTTPS pages loading scripts or iframes over HTTP. Browsers either block or downgrade trust silently. Also a security risk if the HTTP source is compromised.

How we fix it: Asset URL audit, force HTTPS for all embedded content.

LOW

Sensitive data exposed in client-side code

API keys, internal endpoints, or PII references in client-side JavaScript. Often left from development.

How we fix it: Source code scan, rotate exposed credentials, move sensitive endpoints behind authentication.

Inside the full Security Audit

Public surface, headers, dependencies, configuration.

Software hygiene

  • • CMS version vs current
  • • Plugin and module inventory + CVE check
  • • JavaScript dependency CVE scan
  • • End-of-life software detection

Surface exposure

  • • Admin path discovery
  • • Staging and dev environment exposure
  • • Robots.txt and sitemap leakage
  • • Subdomain enumeration

Headers + transport

  • • Strict-Transport-Security
  • • Content-Security-Policy
  • • X-Frame-Options + Permissions-Policy
  • • Referrer-Policy and CORS

Authentication + access

  • • Default credential check
  • • Multi-factor auth status
  • • Rate limiting on login endpoints
  • • Session management hygiene

SAMPLE AUDIT OUTPUT

60 / 100 Grade: Fair

Fair. Significant gaps

  • Outdated dependencies 12 (3 critical CVE)
  • Admin path Default + open
  • CSP header Missing
  • Mixed content 5 assets

Risk classification

Elevated

Top fix: Patch critical CVEs + restrict admin. Estimated lift: Removes elevated-risk classification.

Illustrative sample. Not your site.

What happens when you fix it

Fixing this is not a website redesign. It is a series of specific, surgical changes.

01

DIAGNOSIS

We give you the report

48 hours. Every finding, ranked by impact and effort, with platform-specific instructions for your CMS. You can hand it to your web vendor and they can implement most of it.

02

IMPLEMENTATION (OPTIONAL)

We do the work

If your vendor cannot or will not, we install the fixes ourselves. Most live in Google Tag Manager, the head of the page, or as a CDN-level configuration. Live in 7 to 14 days.

03

VERIFICATION

We re-run the scan

30 days after the fixes go live, we re-run the audit and confirm the lift. Site Health Score increase, category-level pass, downstream impact verified.

What the data says.

Most breaches

result from known-vulnerable software left unpatched, not from sophisticated novel attacks.

Default credentials

and default admin paths remain a leading exposure on dealer sites we audit.

CSP

is increasingly a baseline expectation. Most dealer sites still ship without one.

The Proof

How one dealer remediated 14 critical exposures in 10 days.

A dealership running a heavily customized CMS had 12 outdated modules with disclosed CVEs, an admin path at /admin with no IP restriction, and no security headers.

We patched all flagged modules, moved admin behind IP restriction with multi-factor auth, deployed full security headers including a CSP in enforcing mode, and remediated mixed content.

10 days later: zero CVE-flagged software, security headers grade A, CSP in enforcement, automated scanners no longer flagging the site. Insurance premium for cyber coverage renegotiated downward at next renewal.

14 → 0

Critical exposures

F → A

Security headers grade

10 days

Time to remediation

↓ premium

Cyber insurance impact

Pricing

Three options. No retainer. No negotiation.

Pay once for the diagnosis. Pay once for the fixes. Or pay once and get both.

DIAGNOSIS

$997

Full Diagnostic

  • Comprehensive site audit across all 14 specialty areas
  • Search Console authenticated review
  • Platform-specific fix instructions
  • Priority-ranked master fix list
  • Estimated impact and effort per fix
  • Refundable if we do not find 3 surprises
  • 48-hour delivery
FIXES ONLY

$6,497

Fix Sprint

  • Bring your own audit report
  • We implement your top 5 priority fixes
  • Schema, speed, and structural fixes
  • Live within 30 days
  • No code changes required from your vendor
BEST VALUE DIAGNOSIS + EVERY FIX

$6,997

Full Treatment

  • Full Diagnostic included ($997 value)
  • We implement every fix on the priority list, not just 5
  • Schema, speed, and structural fixes
  • Live within 7 to 14 days
  • 90 days of regression monitoring after launch
  • We handle your web vendor directly

$500 more than the Fix Sprint. Includes the $997 diagnostic and the complete fix list.

Security Audit-specific questions dealers ask.

Answered straight.

Will fixing security break things?

Patching can introduce regressions. We stage all changes, test, and provide rollback plans. Surprise outages are rare with proper procedure.

Do I need a penetration test?

For most dealers, the basics covered here address 80+ percent of real-world risk. A full pentest is appropriate for larger groups or after a major platform change.

Is HTTPS enough?

No. HTTPS protects data in transit. Most modern attacks exploit application-layer issues that HTTPS does nothing about.

Will this affect my SEO?

Positively. Security headers and HTTPS hygiene are ranking signals. Patched, fast-loading sites rank better.

What about customer data?

We audit the public surface. Customer data protection is primarily a CRM and BDC concern, which is outside our scope but adjacent.

How often should I run this?

Quarterly automated scans, full review annually.

What platforms do you support?

All major dealer platforms. Findings and remediation are platform-specific.

Find out where your security exposure actually sits.

30-second scan. We probe public surfaces and known-vulnerable signatures and report risk.