[ WordPress  /  WordPress Security ]

Harden it now, or clean it later.

WordPress powers a huge share of the web, which makes it the most attacked platform on it. Almost every compromise I clean up came through something on this page that nobody had gotten around to.

Audit in 3 days · No plugin bloat · Fixed price

3 daysto a written audit
Fixedprice hardening
Testedbackups, not assumed
Noplugin bloat added

[ Attack surface ]

How WordPress sites actually get in trouble.

Rarely a WordPress core flaw. Nearly always one of these six.

Outdated plugins

A plugin with a publicly documented vulnerability, unpatched for months because updates were disabled after one broke the site.

Weak admin logins

Guessable usernames, reused passwords, no two-factor authentication and unlimited login attempts.

Nulled themes and plugins

Pirated premium code that arrives with a backdoor pre-installed, by design.

No monitoring

Nothing watching for changed files or new admin users, so a compromise runs for weeks unnoticed.

Backups on the same server

So whatever takes down the site takes the backups with it.

Over-permissive file access

World-writable directories and file editing enabled in the admin panel, which turns one weak password into full code execution.

[ How it works ]

Audit, harden, keep watch.

01  —  Day 1-3

Audit

Plugins, themes, users, permissions, server configuration and backup state reviewed. You get a report rated by severity, and a scan to confirm the site is currently clean.

02  —  Day 4-6

Harden

Findings fixed in priority order, tested against your actual site rather than applied blindly from a checklist.

03  —  Ongoing

Monitor

Optional monthly cover: updates applied and tested, file integrity monitoring, uptime checks and a short written report each month.

[ What actually changes ]

The hardening checklist.

Configuration first, plugins second. Most security plugins duplicate what the server should be doing anyway, and slow the site down while they do it.

Access

  • Login protection — rate limiting, two-factor authentication and no predictable admin usernames.
  • User and role audit — stale accounts removed, administrator rights limited to who actually needs them.
  • Admin area restriction — extra authentication on the login and admin paths.
  • Strong credential policy — enforced for all users, with the database and hosting panel rotated too.
  • Disabled file editing — so an admin password alone cannot execute arbitrary code.

Platform & recovery

  • Update policy — automatic security patches, with a staging site so major updates are tested first.
  • Plugin reduction — abandoned and duplicated plugins removed, which improves speed as a side effect.
  • File permissions — corrected across the install, with executable uploads blocked.
  • Firewall and bot filtering — at the server or CDN layer rather than as another PHP plugin.
  • Off-site backups — automated, stored elsewhere, and restored once so you know they work.

[ Example engagement ]

Twenty-two plugins down to nine, and faster for it.

A membership site with overlapping security plugins, no two-factor authentication and backups written to the same disk. Hardened at the server layer instead.

Illustrative example of a typical engagement. Figures vary with the state of your systems and are not a guarantee of a specific outcome.

13plugins removed
2FAon every admin account
0.9sfaster page load
Off-sitebackups, restore tested

[ Free · 3 days ]

Find out how exposed you are.

A written audit of plugins, users, permissions and backups, with each finding rated by severity. Yours to keep and fix in-house if you prefer.

Request the audit

[ Pricing ]

Pricing that fits your budget.

Tell me the number you have to work with. I'll tell you honestly what's achievable within it — and if it isn't enough, I'll say so before we start rather than halfway through.

Fixed project price

Scope agreed in writing, price agreed in writing, before any work starts. No hourly creep and no invoice you haven't already approved.

Monthly retainer

For ongoing work — maintenance, monitoring, updates and small changes. Month to month, cancel whenever, no minimum term.

Hourly for small jobs

For a single bug or a short task where writing a full scope would cost more than simply doing the work.

Budget too tight for the whole thing? I'll often suggest doing the highest-value part first and the rest later, rather than doing all of it badly.

[ Questions ]

Common questions.

Is a security plugin enough?

It helps, but plugins run inside the application they are protecting, so anything that compromises WordPress can usually disable them. Server and CDN-level protection sits in front and cannot be switched off from the inside.

Will hardening slow my site down?

Usually the opposite. A large part of the work is removing redundant plugins, and sites almost always get faster rather than slower.

We update plugins already. Is that enough?

It is the single most important habit, so that already puts you ahead. It does not cover weak logins, permissions, abandoned plugins that no longer receive patches, or backups that have never been restored.

Do I need this if my site is small?

Attacks are automated and indiscriminate — bots scan every site they can reach and do not check your traffic first. Small sites get compromised constantly, usually to send spam or host scam pages.

Can you cover several sites?

Yes. Multi-site and agency arrangements are straightforward, and per-site cost drops considerably beyond the first few.

[ Let's talk ]

Tell me what's broken.

Describe the problem in a few lines and you'll get a real reply from the person who'd do the work โ€” same working day, no discovery call required.