Skip to main content

Is your Umbraco website as secure as you think it is?

Most Umbraco websites we look at are not compromised because of anything clever. They are running an unsupported version, the back office login is sat on the public internet, an API is exposing more than anyone realised, or a package nobody has updated since 2021 has a known vulnerability in it.

None of that shows up in your analytics. It usually shows up when it is too late.

A Nevitech Umbraco Security Review is a structured examination of your website's configuration, code and dependencies, carried out by a team that has worked exclusively with Umbraco since 2013. You get a prioritised report of what is wrong, how serious each item is, and what it takes to fix it.

What the review covers

Umbraco security hardening

We work through your installation against Umbraco's own hardening guidance and the wider set of things that matter in practice.

That includes back office exposure and access restriction, multi-factor authentication, user and permission audit, password and lockout policy, the built-in health checks across security and live environment configuration, HTTPS and TLS configuration, security response headers, Content Security Policy, and the routing settings that can be used to enumerate or render content in ways you did not intend.

If you are on Umbraco Cloud, that also covers the Cloud specific controls: enforced MFA through Umbraco ID, secrets management, and automatic patching settings.

Code review

This is where the differentiated value is, and where a generic security test usually finds nothing.

We review the custom code in your solution: your API and surface controllers, authorisation attributes, model binding and input handling, file upload handling, member authentication logic, and any custom integrations. These are the parts of an Umbraco website that nobody else reviewed, and in our experience they are where the real problems sit.

We also review your dependencies. That means the CMS version and patch level, Umbraco Forms, Commerce, Deploy and Workflow versions, and every community and third party package in the solution, checked against known vulnerability data.

Security audit of the website

The external view. What your website exposes to anyone who looks at it, using only the same requests any ordinary visitor makes.

That covers version and technology disclosure, the Delivery API and what it is making public, Swagger and diagnostic endpoints, error handling and stack traces, robots and sitemap leakage, media and file access controls, form and upload configuration, rate limiting and edge protection, and the endpoints that make your website vulnerable to resource exhaustion even when no vulnerability exists.

That last one is not theoretical. We dealt with a live Umbraco website this year that was taken offline by a layer seven attack against a single expensive endpoint, with no vulnerability involved at all.

What you get

A written report, structured so that both your developers and whoever signs the invoice can use it.

Every finding is given a severity, an explanation of the actual risk in plain English, and a specific remediation step. Findings are ordered by priority so you can fix the important things first rather than working through an alphabetical list.

You also get a fixed quote for the remediation work, so you are not left holding a list of problems with no route to solving them. You are free to take that work elsewhere or handle it in house.

What this is not

We would rather be straight about this up front than have it come up later.

This is a review, not an attack. We inspect, read and analyse. We do not attempt to exploit anything, we do not run attack tooling against your website, and nothing we do generates load, test data or unexpected behaviour in your environment. Everything we touch on the live website is a request an ordinary visitor could make.

That is a deliberate choice. It means the review carries no operational risk, needs no maintenance window, and can be done against a production website without anybody holding their breath.

It is not an accredited penetration test. Nevitech is not CREST or CHECK accredited. If you need a pen test report for ISO 27001, PCI DSS or a supplier assurance questionnaire that names an accreditation, you need a specialist firm. We will tell you that rather than sell you something that does not fit, and we are happy to suggest where to look.

It is also worth knowing that most compliance schemes require the tester to be organisationally independent from the people who build and maintain the website. If Nevitech built your website, we cannot be that independent party, whatever the report is called.

What this review does is find the things that actually get Umbraco websites compromised, using knowledge of the platform that a general security firm does not have. A pen test and an Umbraco review are two different jobs. Plenty of organisations need both, and the review is usually the one that finds more for less.

Who it is for

Businesses running Umbraco who have never had the website looked at from a security point of view.

Agencies who want an independent Umbraco specialist to review a client build before handover, or after inheriting one.

Anyone who has taken on an Umbraco website built by someone else and wants to know what they have taken on.

Organisations still on Umbraco 13, which reaches end of life on 14 December 2026, or on Umbraco 14, 15 or 16, which are already out of support.

Anyone filling in a client security questionnaire who has realised they cannot honestly answer half of it.

How it works

Scoping call. Thirty minutes to understand the website, the hosting, what you are worried about and what you need out of it. No charge.

Written authorisation. You confirm in writing that you own the website or are authorised to commission the review, and we agree the scope, the systems included, and how your code and configuration will be handled.

Access. Read access to the repository, a copy of the configuration with secrets redacted, and a back office account with only the permissions the review needs.

The review. Typically one to two weeks depending on the size of the solution.

Report and walkthrough. You get the report, and a call to walk through it so the findings and the priorities are properly understood rather than just filed.

Pricing

Every website is different, so we price the review after the scoping call, once we understand the size of your solution and what you need. Larger solutions, Umbraco Commerce installations and multi-site setups are quoted individually.

For clients on a Nevitech retainer, the review can be scheduled as a recurring item within your existing hours rather than as a separate engagement. An annual review is usually the right cadence, or after any significant change to the website.

Why Nevitech

Nevitech has worked with Umbraco and nothing else since 2013, across every version from 7 to 17, on premise and on Umbraco Cloud. Every developer here is an Umbraco Certified Master.

We are an Umbraco Silver Partner. Our founder, Justin Neville, is an Umbraco MVP 2026, a winner of the Umbraco AI Package Award, a contributor to Umbraco CMS core with merged pull requests, and co-organiser of the Umbraco Kent Meetup.

That matters here because Umbraco security problems are usually Umbraco problems. Knowing which configuration flags to check, how the Delivery API behaves once enabled, what a surface controller should look like and what the recent advisories actually affected is the difference between a report full of generic findings and a report you can act on.

We carry professional indemnity, public liability and employers' liability insurance. Certificates are available on request.

Frequently asked questions

No. It is a configuration, code and dependency review, plus an assessment of what your website exposes to an ordinary visitor. We do not attempt to exploit anything. If you need an accredited pen test, we will say so and can point you towards firms that do that work.

No, and this is not a hopeful answer. The review does not send anything to your website that a normal visitor would not send. There is no attack tooling, no load, no test data and no need for a maintenance window.

Where any tooling processes your code or configuration, that is agreed with you in advance and named in the written authorisation. Configuration is always supplied with secrets redacted, and we do not need a copy of your production database. For websites holding sensitive personal data, analysis can be run entirely on local infrastructure with nothing leaving Nevitech systems.

Cloud handles the infrastructure and patches the CMS automatically, which removes a real category of risk. It does not review your custom code, your permissions, your API exposure, your headers or your Forms configuration. Those are still yours.

Talk to us about the migration. Umbraco 13 goes end of life on 14 December 2026 and after that there are no security patches without paid extended support. A review of a website you are about to replace is usually not the best use of your budget, though a review immediately after the migration often is.

Yes, quoted separately, and you are under no obligation to use Nevitech for it. The report is written so another developer can act on it.

Get in touch

If you want to know where your Umbraco website actually stands, book a scoping call. It costs nothing and you will get a straight answer about whether a review is worth doing.

Book a scoping call