Website security
You will know exactly what your site contains.
An antivirus compares your files against a list of catalogued threats — a list that will never contain the one targeting you. We work the other way round: we establish where each legitimate file comes from, and we show you what has no provenance.
justified
without provenance
executables
- core/lib/Db/DbPDO.php
- includes/version.php
- modules/paiement/gateway.php
- plugins/catalogue-export/index.php
- themes/boutique/functions.php
- var/cache/prod/min.a3f9c2.js
- admin/includes/file.php
- uploads/2026/01/index.php
- vendor/composer/autoload_real.php
- includes/class-query.php
- uploads/2026/01/i.php
- mu-plugins/.cache.php
- includes/js/editor/tmce.php
Three files could not account for their presence. These are the only ones we will discuss — the other 809 bear the name of their origin.
My site has been hacked
Analysed. Repaired. Attested.
With nothing to install, in a single operation: the complete analysis, the automatic repair — proven or cancelled, your site is re-tested after every action — plus the signed attestation of its recovery.
My site is fine — keep it that way
Monitored. Every day.
Watch compares your files every day against the official fingerprints from their publishers, and only writes to you if something has changed — on your side, or on theirs. No news is good news.
Our seal — a guilloche, the engraving that protects banknotes from counterfeiting. It is born from an equation: copying it requires recovering its numbers. Every document we issue is protected by the same principle — signed by computation, tamper-proof, and verifiable by anyone.
- Renewal
- none — everything is paid once
- Technical action on your part
- none, if you entrust us with your credentials
- Modification of your files
- none without the Restore option
- Data retained
- Record: at most one 64-character fingerprint; Watch: the monitoring record, deleted when it stops
Every executable file must be able to name its origin.
Those that cannot are the only ones we talk about.
- publisher
- 0
- official repository
- 0
- seal applied
- 0
- generated
- 0
- without provenance
- 0
- false positives
- 0,0 %
- across 27 real, live sites
- implants detected
- 19/19
- in an official WordPress
- files of genuine code
- 28 972
- and not one accusation
Almost no vendor publishes its false positive rate. Here is ours, with the protocol and the commands to reproduce it.
Results of our measurementsA short document, and signed
Here is a document we actually issued, transcribed field by field. This isn't a screenshot: the file is online, and its signature can be verified without you having to trust us.
You'll notice it contains no flattering counters. It contains a verdict, zero serious findings, and four things it doesn't look at, which it names itself.
- site
- aigeniestore.com
- when
- 2026-08-11 14:50
- serious findings
- 0
- recognized families
- none
Its four blind spots, declared
- the server files (backdoors dropped outside public pages)
- the database (injected content, added administrator accounts)
- the configuration files (.htaccess, wp-config, scheduled tasks)
- the pages not visited by the analysis
signature Ed25519 · timestamped by a third party
a453 d9ec 0e45 e928 512b 13cd b2eb 3fa1
Timestamping authority non-qualified in the eIDAS sense — we state this in the document. Only 32 bytes of fingerprint were transmitted to it: neither the site's name, nor its content.
What can be signed, shown, and re-verified
The entire difference lies in the form of the final sentence. One makes a negative claim about an infinite set. The other, a positive claim about a finite set. Only the second can be signed, shown, and re-verified by someone else.
What a signature-based tool says
"We found nothing."
- Unverifiable: no one can check an absence.
- Out of date by the next day, with nothing to flag it.
- Blind to anything not yet catalogued — that is, to whatever is targeting you.
- Shown to no one: no host will restore a site on the strength of that sentence.
What we write
"As of this date, all 812 executable files on this site had a named provenance."
- Verifiable: the set is finite, it can be recounted.
- Anchored to the inventory fingerprint — the first file that changes breaks it.
- Signed: your host verifies it in their browser, without taking your word for it.
- Refused until it is true. An attestation you always get is worth nothing.
Where others promise to detect everything, we promise to justify everything — or to attest to nothing at all.
The attestation is anchored to the fingerprint of the entire inventory. A single modified file, and that fingerprint changes all the way up: the document contradicts itself, without anyone having to admit anything.
Six world firsts, in service today.
Every line on this page corresponds to a mechanism actually in place — never an intention. The label "world first" is reserved for what no market player offers as of the 25 August 2026 survey; the dated comparison below provides the proof. If a line ceases to be true, it goes.
World first
The attestation the whole world can verify without us
Every document is signed by computation (Ed25519). Your host, your insurer — anyone — checks the signature in their browser, with no account, without sending us anything, without taking our word for it.
World first
Proven or void — three verdicts, never two
After every repair, your public site is re-tested. Repaired, void — the original state comes back on its own — or not observable: an error page proves nothing, so we conclude nothing.
World first
The verdict "0 unexplained executable files"
Antivirus tools look for the known-bad in an infinite space. We demand the opposite: that every executable file justify its presence. A malware nobody has catalogued yet is still caught — it is unexplained.
World first
The proven silence of monitoring
Watch only writes to you if something new has moved — silence means "nothing new", not "nobody looked".
World first
Repair in a single act
No extension, no account, no mandatory subscription — only the access details your host sent you. The full analysis, the automatic repair and the attestation of reinstatement — one operation, paid once.
World first
The intrusion window, dated
Two time boundaries frame the compromise. A vulnerability published after the window is ruled out outright — it did not exist yet. Nobody dates it; we date it.
Eight more exclusives
Three viewpoints compared
The same page served to the visitor, to Googlebot and to mobile — cloaking shows up by difference, never through a single-identity analysis.
The checkout funnel found by name
In four languages, even in noindex, even absent from the sitemap — the page that matters, the one ordinary tools never open.
The real exfiltration destination, named
When a script reads the payment fields and sends them elsewhere, the finding names the real destination — never an innocent CDN pointed at in its place.
The baseline of served scripts
A script that changes content without changing address is seen by fingerprint — the control the payment standard requires every week.
Official WordPress and PrestaShop fingerprints
Every core file compared against what the vendor actually published — nobody else covers PrestaShop.
Blind spots, disclosed in every report
What the analysis didn't see is written in black and white, with the exact coverage — a "clean" result states what it covers.
The refusal to rewrite what is already sound
The actual state is read before every action; a "repair" that would duplicate what already exists is refused, with its reason.
0.0% false positives, measured
Across 27 real sites, against their own neighbours — a replayable real-world condition, not a brochure figure.
Check for yourself rather than taking our word for it: the rates and the real-world conditions are published on the results page, and every signed document can be checked on the verification page, in your browser.
The only one to repair a hacked site in a single act — and to prove it.
The leaders in the field do good work, each in their own way — cleanup by analysts at Sucuri and Wordfence, automatic repair via plugin at MalCare. None of them brings together the five rows of this table, and two of them exist nowhere else.
| Survey of 25 August 2026 | Sucuri | Wordfence | MalCare | AI Website Security |
|---|---|---|---|---|
Automatic repair, no human intervention Sucuri and Wordfence have their teams of analysts do the cleanup — by ticket, within a set turnaround. | ||||
Nothing to install — no extension, no account to create MalCare and Wordfence live inside a WordPress plugin; Sucuri goes through its firewall. | ||||
Pay per job, no subscription With all three, repair is included in an annual subscription. | ||||
Proven or reverted — the site is re-tested after each action, with automatic rollback | ||||
Signed certificate of restoration, verifiable by a third party It's the document your host or your insurer can check without taking our word for it. |
Survey carried out on 25 August 2026 on the vendors' public pages — offers, pricing and documentation. These products change: if a line becomes inaccurate, write to us and we'll correct it. Comparing honestly is part of what we sell.
Nothing to install
No extension, no account. An address to analyse, your hosting access details to repair.
A one-off job, not a subscription
€199, once. Ongoing cover exists, but it's your choice.
Proven or reverted
Every action re-tested on your live site, otherwise undone.
Attested, signed, verifiable
An enforceable document that anyone can verify.
One answers for today.
The other answers for tomorrow.
"Is my site compromised?" and "will it still be safe tomorrow?" are two distinct questions, and a single tool cannot honestly answer both. Each is purchased separately and works on its own.
Restore reinstates the state published by your editors.
An attacker modified thirty files in the core, your extensions and your theme. Their thirty modifications disappear all at once — including those no signature would have caught, since we aren't looking for them.
This is possible because we know what your site should look like: the official fingerprints published by your CMS vendor, and the official packages of your extensions.
It rewrites only what the publisher releases
No content is guessed. Without an official original, the file is left as is — and named.
Any file set aside remains recoverable
A file whose sole purpose is malicious goes to quarantine. It can be restored in one click.
Proven, or cancelled
Your site is re-checked after every batch. At the first sign of breakage, the whole batch is rolled back.
What belongs to you stays intact
Configuration, content, media, caches: they are never rewritten, even when they diverge.
Restore is added to a product
It can't run on its own: the list of files to restore is derived from an analysis, and without it we wouldn't know what to replace them with. So it's added to one or the other of the two products — Record + Restore to repair today, Watch + Restore so that it's done every night without you.
You connect your site. You start the analysis.
Nothing to install, nothing to download, nothing to delete afterwards. The tool handles the rest.
You connect your site
Its address, and the access credentials your host sent you when you opened your account. One minute.
You launch the analysis
You have nothing left to do. The result is displayed, and your documents are issued.
You install nothing, none of your files are modified without the Restore option, and nothing is kept by us.
Check for yourself.
Everyone in this market asks you to trust them. We'd rather give you what you need to do without it.
Fingerprint of our public key · Ed25519
a453 d9ec 0e45 e928 512b 13cd b2eb 3fa1
Download
A document we actually issued. No file paths, no site data inside.
Drop it in
The file never leaves your computer. The computation runs in your browser, offline if you wish.
Compare
The fingerprint displayed must be exactly the one above. If it differs, the document is not ours.
Three documents
for three distinct uses
A hacked merchant handles three difficult conversations alone: with their host, with their insurer, sometimes with the data protection authority. All three ask for the same thing — dated facts, verifiable by someone other than them.
The findings
You, your insurer, the data protection authority
What was found, when it started, what was done, what remains. It records facts — including the bad ones — and it is never refused.
It doesn't claim the site is clean, and it says so itself.
The document for your host
The abuse team that took your site offline
Short, factual, with a "how to verify it yourself" section. Every file named carries its own proof of belonging: the abuse desk recomputes THAT line and reaches its own conclusion, without ever receiving the list of your files. One goal only: getting your site back online.
No sales pitch. A document that sells ends up in the trash.
The attestation
A client, a buyer, a partner
The positive statement: on this date, every executable file had a named provenance. It is backed by the fingerprint of the inventory.
It withholds itself. As long as a single file remains unexplained, it is not issued.
The mix-up that would cost the most
Showing an incident report while believing you're showing a clean bill of health. That's why every document states its type in full, and why the verification page explicitly warns you when it reads one.
The blind spots are on the front page
They appear in the signed document, not in a footnote. A tool that names its limits lets you know what you still have to do.
We read the site's files, not your database — except for whatever it reveals in the pages served.
We never keep your hosting credentials: they are used to deposit and then remove the agent — or you deposit it yourself, and they are never sent to us.
“Justified” does not mean “safe”: a fully justified site may still have a known vulnerability or a stolen password.
A file's date can be forged with a single command. When we date an intrusion, this caveat is written into the signed document.
How many files on your site can justify their presence?
You'll get the exact number, every file named, and the means to prove it to someone else.