Get Clarity on Your Website’s Security - No Tech Headaches Required

🔍 Real Vulnerability Scans, Not Fluff

“Find what hackers actually exploit — outdated plugins, leaked credentials, exposed login panels.”

📉 Avoid Getting Blacklisted by Google

“Don't lose traffic or bookings overnight — we’ll alert you before Google does.”

📬 Stop Email Hijacks Before They Happen

“Prevent spoofing, phishing, and invoice fraud through misconfigured mail systems.”

🧠 Executive-Readable Reports

“No tech jargon. Just clear, human answers on what’s wrong — and how to fix it.”

✅ Monthly Protection Plan

“Continuous monitoring, deep scans, and weekly insights. All done-for-you.”

The Vigil Kiwi Security Kit

More than a scan. It’s the first serious step in securing your business.

Big firms sell bloated audits. We deliver real protection — fast, human, and specific to small business risks. The Security Kit combines everything a small business needs to assess, harden, and verify its digital security posture.

.

Find a detailed walkthrough of ALL of our services at the bottom of the page.


  • 🛡️ Full Security Kit

    Your entire digital perimeter, professionally audited.

    For businesses that take their data, customers, and credibility seriously — or need proof of due diligence for insurers, stakeholders, or compliance regulators.

    🔍 Comprehensive Website & Code Scan

    We deploy our entire scanning toolkit across your live website and supporting infrastructure:

    • CMS platform, plugins, and libraries
    • Server response & open ports
    • Code structure, headers & encryption protocols
    • Known CVEs (vulnerabilities) matched to your site
    • Scans run longer, go deeper, and are manually reviewed to flag high-impact findings

    📄 Official PDF Report

    You’ll receive a professionally formatted, branded document detailing:

    • Executive summary of findings
    • Severity rating of each issue
    • Full technical output as appendix
    • Actionable next steps
    • Timestamped scan date & verification
      Designed to be confidently shared with: Insurers & underwriters, Compliance auditors, Investors, partners or board members

    📞 25-Point Cyber Health Call

    A live 20–30 minute walkthrough with our analyst team, covering:

    • Password practices & credential hygiene
    • File & document access permissions
    • Website and cloud storage setup
    • Backup, MFA, and risk protocols

    We screen for common missteps and give clear guidance on what to fix — even beyond what’s in your scan.

    📃Numerous Guides And Checklists

    🏷️ Cyber Security Badge (Eligibility)

    After issue resolution, your business may qualify for the:

    “Secured by The Vigil Kiwi” badge — with custom HTML embed and verification timestamp.

    Badge display status:

    • ✅ Eligible: No critical or medium issues; ≤ 3 low-severity
    • ⚠️ Suspended: Unresolved high/critical vulnerabilities

    Clients with the badge receive enhanced trust from customers, partners, and search engines.

    🔄 Monitoring Plan Eligibility

    Only clients who have completed the Full Scan and resolved flagged issues can enroll in our ongoing Monthly Monitoring package — ensuring integrity and consistency.

    🎁 Loyalty Perk

    50% Off Your Next Full Scan

    Book your next audit within 60 days and receive half off — useful after site changes, platform migrations, or seasonal campaigns.

    ✅ Who This Is For

    This audit is ideal for:

    • Business owners seeking peace of mind
    • Teams without in-house cybersecurity experts
    • Businesses dealing with PII, bookings, or payment data
    • Those needing compliance proof for contracts or insurers

    💲 Pricing depends on:

    • Website size & complexity
    • Number of pages, integrations, plugins
    • Scan depth, urgency, and turnaround time
    • Custom quotes available on discovery call.
    Request a Scan 
  • 🔐 Monthly Cyber Security Monitoring

    Continuous protection, simplified. Built for small NZ businesses that can’t afford to be left in the dark.

    📡 Ongoing Website Vulnerability Scans

    We run recurring, automated vulnerability scans using the same high-grade toolset as our Full Security Scan — adapted to your business size and risk profile.

    • Weekly scans for small, low-change sites
    • Daily scans for medium/high-risk platforms
    • 6–12 Hour scans for large, dynamic environments

      All results are reviewed, compiled, and stored securely for trend tracking and historical review.

    🧠 Dark Web & Breach Monitoring

    We continuously monitor your email accounts and login credentials using the HaveIBeenPwned API.

    If your data appears in a new breach or paste dump, you’ll be alerted immediately — before attackers try to use it.

    🛑 Google Blacklisting & Safe Browsing Checks

    Your website’s Google Safe Browsing and VirusTotal reputation is checked regularly.

    If your domain is flagged — even accidentally — we’ll alert you before customers see that red malware warning screen.

    🧾 Monthly PDF Security Summary

    Each month, you receive a clean, branded PDF with:

    • Scan results & observations
    • Any issues found (with severity ratings)
    • Clear action steps
    • Your current “Secure with Vigil Kiwi” badge status

    Great for your records — or to show clients, insurers, and partners that you’re actively protecting data.

    💬 Ask Us Anything Support

    Clients on our monitoring plan get access to email-based support for light security queries.

    Expect a response within 48 hours, from a real human — no bots, no overseas tickets.

    🏅 Cyber Security Badge Maintenance

    Stay protected, stay verified.

    Your monthly report states your current eligibility for the “Secured by Vigil Kiwi” badge.

    If critical risks arise and go unpatched, the badge is paused until resolved, preserving trust and accuracy.

    🚨 Priority Incident Handling

    Should something go wrong — you go to the front of the line.

    Clients on the monthly plan receive priority attention for:

    • Site lockdowns
    • Defacements
    • Emergency re-scans
    • Guidance on insurance or breach disclosure steps

    💼 Who This Is For

    This package is ideal for:

    • Small to mid-sized NZ businesses
    • eCommerce stores, med clinics, service providers
    • Those needing real-time oversight without enterprise overhead
    • Owners serious about maintaining trust with customers & partners
    Book a Discovery Call 
  • 🔄 Maintain Protection Your Way

    You can purchase the Full Security Kit at any time — no strings attached. And once your site is cleared, you’re eligible to continue with our Monthly Monitoring Package indefinitely — no need to rescan unless risks appear.

    .

    However, based on your website size and activity, we typically recommend:

    • Large websites → Monthly Full Scans
    • Medium websites → Bi-monthly Full Scans
    • Small websites → Quarterly Full Scans

    .

    🛡️ We don’t offer standalone website scans outside of the Full Security Kit — because threats don’t stop at the surface. That’s why each recurring Full Scan also includes a refreshed 25-Point Cyber Health Call, expanded based on your last report. This ensures we continuously improve your security, one layer at a time.

1 of 3

The Full Website Scan Walkthrough

Google Blacklisting & Public Site Reputation

🔍 Google Blacklisting & Public Site Reputation

What exactly are we checking?

We scan your public-facing domain(s) against trusted security reputation databases, including:

  • Google Safe Browsing
  • VirusTotal
  • PhishTank
  • URLHaus
  • SURBL, Spamhaus, etc.

We also validate DNS records for inconsistencies that may indicate hijacking, parking, or redirection to malicious infrastructure.

Why this matters to your business:


If your site is flagged as unsafe—even incorrectly—modern browsers will display alarming red warnings to your users. This often happens silently, without alerting the website owner.

A blacklisting can result from:

  • Malware or phishing payloads injected via outdated plugins
  • Poorly secured third-party scripts
  • Compromised subdomains
  • Inherited hosting or DNS misconfigurations

The risk?


Loss of organic traffic, SEO rankings, and most importantly, user trust.

Even partners and advertisers may pull away from sites that show malware or phishing warnings.

Real Impact Example:


A client approached after a steep drop in organic traffic. It was found that their site had been flagged on Google Safe Browsing due to a malicious script in a forgotten plugin directory. Resolving the issue and re-submitting to Google restored traffic and reputation—but only after measurable business loss.

Included in:


✅ Light Scan  ✅ Full Scan  ✅ Continuous Monitoring

From The SEOSLY Blog:


"Your task, as a website owner or an SEO, is to make sure that your website is safe for its users and does not contain malware... If that happens, your website will become invisible for most internet users."

👉 Read More

Plugins, CMS, WordPress, Framework Checks

🧱 Plugins, CMS, WordPress & Framework Checks

What exactly are we checking?


We identify your website’s underlying technologies and architecture, including:

  • CMS platforms (e.g., WordPress, Joomla, Drupal)
  • Frameworks and back-end languages (e.g., Laravel, Django, Node.js)
  • Installed plugins, themes, and modules
  • Version fingerprints for core components
  • Known vulnerabilities (CVEs) based on version data

We flag:

  • Outdated plugins or themes
  • Abandoned extensions
  • Known exploits publicly listed but unpatched

Why this matters to your business:


Your CMS and plugins form the foundation of your website—and are among the most targeted elements by attackers.

If a plugin or component hasn’t been updated recently, it may contain known vulnerabilities that allow attackers to:

  • Gain unauthorised admin access
  • Deface your site or redirect users to malicious domains
  • Inject malware, cryptominers, or phishing kits
  • Exfiltrate customer data or internal content

These attacks are often automated, meaning you can be targeted just for being online with vulnerable software.

Real Impact Example:


During a Full Scan, we discovered a client using an outdated WordPress contact form plugin that had a public remote code execution (RCE) exploit. An attacker could have executed malicious code on the server—an issue that would’ve gone undetected without scanning the stack.

Included in:


❌ Light Scan (CMS only)  ✅ Full Scan  ✅ Continuous Monitoring

From the SiteLock Blog:


"Hackers don’t need to discover new vulnerabilities themselves—they simply exploit publicly disclosed flaws in outdated plugins... It’s only a matter of time before malicious actors take advantage."

👉 Read More

Open Ports & Exposed Services

Code & Security Headers

WHOIS / DNS / SPF / DMARC Checks

Credential Exposure

Social Engineering & Email Spoofing Potential

The Full 25 Point Cyber Call Walkthrough

Email security

Device access, shared credentials

File sharing & cloud tool usage

Password policies

Admin-level access

Browser plugin hygiene

Backups & recovery options

🛡️ Cyber Security Badge Walkthrough

How Its Displayed

How We Check Eligibilty

What It Stands For

Cross Linking To Our Certified Businesses Page

📊 Monthly Monitoring Package Walkthrough

Monthly Website Scans (Custom Frequency)

Dark Web + Breach Monitoring

Safe Browsing Check & VirusTotal Status

Monthly Report PDF

Ask Us Anything Support

Badge Maintenance & Re-Eligibility

Priority Incident Response