PHP security audit and fixes
Find the vulnerabilities in your old application before somebody else does, and fix them.
Older PHP applications often contain patterns that were acceptable when they were written and wouldn't be today: weak password storage, unsafe database queries, forgotten admin pages, abandoned libraries. Attackers scan for these automatically, around the clock.
I review your application and server, prioritise what actually matters, and fix it.
Book a free conversationLegacy System Assessment, from £2,500
Signs you need one
- You run unsupported PHP, a framework or a CMS that no longer receives security fixes. Check your PHP version
- You've failed or expect to fail Cyber Essentials, a customer security questionnaire or an insurer's renewal checks
- A penetration test has produced a list of findings nobody knows how to fix
- You've been hacked before, or suspect you may have been. Hacked site cleanup
- You hold personal or payment data, and you've never had the code reviewed
- The original developer has gone, and nobody can say whether it's secure
What I review
| Area | Typical issues I look for |
|---|---|
| Input handling | SQL injection, cross-site scripting (XSS), command injection |
| Authentication | Weak password hashing (e.g. MD5 or SHA-1), no multi-factor authentication, default or shared logins |
| Authorisation | Users reaching other users' data, admin functions without proper checks |
| Sessions and cookies | Session fixation, missing security flags, long-lived tokens |
| Request forgery | Missing CSRF protection on forms and actions |
| File uploads | Executable files uploaded, no type or size checks |
| File handling | Path traversal, unsafe includes, exposed backups |
| Dependencies | Outdated or abandoned libraries with known vulnerabilities |
| Secrets | Passwords and API keys in code or in public repositories |
| Configuration | Debug mode on, phpinfo() pages, exposed .env or .git directories |
| Encryption | Outdated TLS, missing HTTPS, unencrypted sensitive data or backups |
| Server and infrastructure | Unpatched operating system, open ports, weak SSH, file permissions |
| Logging and monitoring | Nothing recorded, so attacks go unnoticed |
| Backups and recovery | Untested, stored on the same server, or non-existent |
This broadly follows the OWASP Top 10 categories, adapted to PHP and to the realities of ageing systems.
How I work
1. Scope
We agree what's in scope: the application, the server, or both, and what data is involved. I work from copies and read-only access wherever possible. How I handle access
2. Discover
I use AI-assisted analysis across the whole codebase, with automated scanning of dependencies and configuration, to find likely weaknesses far faster than a purely manual review. How I use AI
3. Verify
Every finding is checked by a person. Automated tools produce false alarms, and a report padded with false positives wastes your time. I confirm which issues are real and how exploitable they are.
4. Prioritise
Findings are rated by seriousness and likelihood, in plain English: what could happen, how likely it is and what to fix first. Not a 200-page scanner printout.
5. Fix
Where you want me to, I fix the issues, with tests around the changes, human review and a staged rollout, so the fixes don't break the application.
6. Report
You receive a written report you can show to customers, insurers and auditors, and a record of what was changed.
What you receive
- A prioritised risk register
- A plain-English summary for owners and non-technical decision-makers
- A technical report for whoever maintains the application
- Fixes, where included in scope
- Recommendations for longer-term hardening, upgrades and monitoring
What this is not
I'm straightforward about the limits:
- It's a code, configuration and architecture review. It is not a formal penetration test or a certification. If you need an accredited penetration test for compliance, I can help you scope one and fix what it finds.
- I can't guarantee an application is unhackable. No one can. The goal is to remove the real, known weaknesses and make attacks harder and easier to detect.
- I provide technical remediation, not legal advice or Data Protection Officer services. Data protection and security
Compliance support
I can fix the technical findings behind failures in Cyber Essentials, cyber insurance questionnaires, customer supplier audits and PCI DSS requirements, and supply the documentation to support your answers. I can't certify you against any of them.
What it costs
A security review is included in the Legacy System Assessment, from £2,500. If you want a focused security-only review, tell me about the system and I'll quote a fixed price after a free conversation.
Fixes are quoted fixed-price where scope is clear, or at £950 per day for open-ended work. Urgent incident work is from £1,300 per day. Pricing
For agencies
If a client has had a penetration test result or failed questionnaire and your team doesn't want to fix a legacy application, I can do it white-label or direct. Agency terms
Frequently asked questions
Is this the same as a penetration test?
No. A penetration test attacks a running system from outside. My review examines the code, configuration and architecture from inside, which often finds problems a test misses, and gets them fixed. If you need a formal test for compliance, I can say so and help you prepare.
We already have a penetration test report. Can you fix the findings?
Yes. That's common. I'll turn the findings into a prioritised plan and fix them, with tests, so the fixes don't break anything.
Will you find everything?
Not everything, and nobody honestly can. I'll find the significant, real problems, and tell you clearly what I looked at and what I didn't.
Do I need to upgrade PHP as well?
Often, yes. Unsupported software is itself a risk, and some vulnerabilities can't be fixed without upgrading. I'll tell you what's essential and what can wait. PHP upgrades
What if you find evidence we've already been hacked?
I'll tell you promptly. You may have legal duties to report a breach, so take advice quickly. Hacked site cleanup
Will you need access to live data?
Usually not. Most of the work can be done on code, configuration and limited or sanitised data.
Tell me what you've inherited.
Not sure how exposed you are? Tell me about the system and I'll tell you honestly what a review would involve.
Book a free conversationLegacy System Assessment, from £2,500