Visible on the site
What the technical review can observe.
- Forms, scripts, cookies, public endpoints, and policy links.
- WordPress and plugin settings available to an authorized local check.
- Evidence, confidence, coverage, and not-tested reasons.
Outside the scan
Where manual review is required.
- Legality, document sufficiency, and regulatory status.
- The full server and organizational context without relevant access.
- Penetration testing, threat models, and guarantees that no incident exists.
Next step
Keep evidence separate from decisions.
Run a local baseline, then route confirmed unknowns to the relevant engineering or legal specialist.
Sources
Review forms against primary sources.
Tell us what the site needs.
A goal, the current difficulty, and an optional website address are enough. Do not send passwords, keys, or private exports.