Outdated plugins
A plugin with a publicly documented vulnerability, unpatched for months because updates were disabled after one broke the site.
[ WordPress / WordPress Security ]
WordPress powers a huge share of the web, which makes it the most attacked platform on it. Almost every compromise I clean up came through something on this page that nobody had gotten around to.
Audit in 3 days · No plugin bloat · Fixed price
[ Attack surface ]
Rarely a WordPress core flaw. Nearly always one of these six.
A plugin with a publicly documented vulnerability, unpatched for months because updates were disabled after one broke the site.
Guessable usernames, reused passwords, no two-factor authentication and unlimited login attempts.
Pirated premium code that arrives with a backdoor pre-installed, by design.
Nothing watching for changed files or new admin users, so a compromise runs for weeks unnoticed.
So whatever takes down the site takes the backups with it.
World-writable directories and file editing enabled in the admin panel, which turns one weak password into full code execution.
[ How it works ]
Plugins, themes, users, permissions, server configuration and backup state reviewed. You get a report rated by severity, and a scan to confirm the site is currently clean.
Findings fixed in priority order, tested against your actual site rather than applied blindly from a checklist.
Optional monthly cover: updates applied and tested, file integrity monitoring, uptime checks and a short written report each month.
[ What actually changes ]
Configuration first, plugins second. Most security plugins duplicate what the server should be doing anyway, and slow the site down while they do it.
[ Example engagement ]
A membership site with overlapping security plugins, no two-factor authentication and backups written to the same disk. Hardened at the server layer instead.
Illustrative example of a typical engagement. Figures vary with the state of your systems and are not a guarantee of a specific outcome.
[ Free · 3 days ]
A written audit of plugins, users, permissions and backups, with each finding rated by severity. Yours to keep and fix in-house if you prefer.
[ Pricing ]
Tell me the number you have to work with. I'll tell you honestly what's achievable within it — and if it isn't enough, I'll say so before we start rather than halfway through.
Scope agreed in writing, price agreed in writing, before any work starts. No hourly creep and no invoice you haven't already approved.
For ongoing work — maintenance, monitoring, updates and small changes. Month to month, cancel whenever, no minimum term.
For a single bug or a short task where writing a full scope would cost more than simply doing the work.
Budget too tight for the whole thing? I'll often suggest doing the highest-value part first and the rest later, rather than doing all of it badly.
[ Questions ]
It helps, but plugins run inside the application they are protecting, so anything that compromises WordPress can usually disable them. Server and CDN-level protection sits in front and cannot be switched off from the inside.
Usually the opposite. A large part of the work is removing redundant plugins, and sites almost always get faster rather than slower.
It is the single most important habit, so that already puts you ahead. It does not cover weak logins, permissions, abandoned plugins that no longer receive patches, or backups that have never been restored.
Attacks are automated and indiscriminate — bots scan every site they can reach and do not check your traffic first. Small sites get compromised constantly, usually to send spam or host scam pages.
Yes. Multi-site and agency arrangements are straightforward, and per-site cost drops considerably beyond the first few.
[ Related services ]
[ Let's talk ]
Describe the problem in a few lines and you'll get a real reply from the person who'd do the work โ same working day, no discovery call required.