Web Security Services

Web Security Services is an online security scanner for your website or CMS system.


Web Security Services is a small Dutch company specialized in Web Security. We are addressing a major issue in website security: the way malware, spyware and trojans get distributed online. Since 2004 there has been an explosion of Malware and Trojan distribution via websites and vulnerable CMS systems. The main problem is the increased usage of Content Managment Systems around the globe. Plagued by weak admin or user passwords and poorly updated CMS systems, CMS systems are easliy and routinely compromised by spammers or worse.

Even Popular CMS systems that are thought of as being secure, are not safe and have found to be vulnerable on a regular basis to mass exploits for automated remote inclusion of iframes, javascript inclusion, cross site scripting and url rewriting tricks.

These kind of exploits can be used to let your website distribute malware or trojans to your customers or visitors. Or to piggyback on your website ranking in major search engines for URL spamming purposes. Possiblilties for exploits are endless and people are paying a lot of money to get hold of a popular compromised website.

This can eventually result in damage to your corporate image and may result even in legal claims and that could have been easily prevented by monitoring your pages for changes

Be aware when using the following CMS systems:

Expression Engine, Joomla, Drupal, Wordpress, Wordpress MU, Movable Type, Textpattern, Concrete5, Radiant CMS, Cushy CMS, Symphony, MODx, Plone CMS, Railfrog, Typo3 CMS and Silverstripe CMS.

The CMS systems listed above can be exploited or abused easily if you do not take basic security measures like keeping up with CMS patches and bugfixes.

How Web Security Services can help you prevent a corporate disaster or embarrasment:


The Web Security Scanner which is the backend used by Web Security Services automatically scans the content of the pages of our users and notifies them when there has been made a change to a specific page. Only the real webmaster can submit a page for scanning, a security code has to be inserted into the html code to verify that the page you are submitting is really yours.

During a first scan our Security Scanner takes a snapshot of your page and commits it to the Web Security Scanner Cache.
When a change occurs to a specific page an e-mail notification will be sent within one hour to the account holder. Checks are done every hour.
In the user control panel the detected change can be reviewed and if the change is legitimate it can be committed to the Web Security Scanner Cache. All changes to your page will be compared to our cached copy and marked in red. Any hidden unauthorized iframes or scriptcode inserted through a hacked CMS system or website account can be detected easily this way.

What to do if you suspect that your website has been hacked.


Contact one of our security specialists to review your site. Normally we can assist you in the recovery process of a hacked website.

E-mail: