Websites for practices and small businesses, live in under 2 weeks. Get a quote →
marketing@eterni.tech Book a 15-minute call ↗ Toronto · Working with businesses across the US & Canada

WordPress security

WordPress security, from people who build WordPress

Most hacked WordPress sites weren’t targeted. They were found: an old plugin, a reused password, an exposed file. We audit, harden and fix WordPress sites so the automated attacks that hit every site, every day, find nothing to use.

What’s included

Done properly, start to finish

01

Plugin and theme audit

Every plugin and theme checked against known vulnerabilities, abandoned projects flagged, and anything you don’t need removed.

02

Users and access

Admin accounts reviewed, roles cut down to what each person needs, and two-factor sign-in for anyone who can change the site.

03

Login protection

Rate limits, lockouts and generic error messages, so password guessing gets nowhere and usernames stay private.

04

Locked-down configuration

Dashboard file editing off, XML-RPC and user listing closed, PHP blocked in uploads, correct file permissions.

05

Security headers and CSP

HSTS, a strict content security policy and the other headers that stop whole classes of attack in the browser.

06

Backups that restore

Off-site backups on a schedule, and a restore we’ve actually tested, so a bad day stays a bad day.

The hardening checklist

Twenty things we check on every WordPress site

Grouped the way an attacker would approach them: who can get in, what code runs, what the server allows, and what the browser trusts.

Access

  • Two-factor sign-in for admins
  • No shared or default admin accounts
  • Least-privilege roles
  • Login rate limiting and lockout
  • Application passwords reviewed

Code

  • Core, plugins and themes current
  • Abandoned plugins replaced
  • Custom code checked for escaping and nonces
  • No nulled or pirated plugins
  • Dashboard file editing disabled

Server

  • PHP blocked in uploads
  • Correct file ownership and permissions
  • wp-config.php and dotfiles protected
  • XML-RPC disabled
  • Directory listing off

Browser

  • HTTPS with HSTS
  • A content security policy
  • Clickjacking protection
  • Referrer and permissions policies
  • Secure, HTTP-only cookies

The steps

From first message to closed

  1. 01

    Audit

    Everything above checked, findings ranked by risk.

  2. 02

    Harden

    We apply the fixes, with a backup first.

  3. 03

    Verify

    Every page and form re-checked; a short report.

  4. 04

    Keep

    Monthly updates and checks, if you want them.

Start here

Request a security assessment

Tell us what you run and what worries you. We’ll reply with a scope, dates and a fixed price in writing, and you decide from there.

  • A reply from the people who’ll do the work
  • Scope, dates and a fixed price before anything starts
  • An NDA before we start, if you want one
  • Nothing is tested without written authorization

Urgent? Message us on WhatsApp ↗

How urgent is it?

Please don’t include passwords, keys or full findings. We use your details only to reply. Privacy

Questions

Before you ask

Anything else: marketing@eterni.tech

Isn’t a security plugin enough?

It helps, but it’s one more piece of code with access to everything, and it can’t fix an outdated plugin, a weak admin password or a misconfigured server. We fix the causes. Whether you keep a security plugin afterwards is up to you.

Will hardening break my site?

Not if it’s done carefully. We take a backup first, try changes on a staging copy where we can, and check every page and form afterwards.

Do you secure sites built with Elementor or other page builders?

Yes. We secure the site you have. If the page builder itself is part of the problem, or the reason the site is slow, we’ll tell you and explain the options.

How often should WordPress be updated?

Security updates as soon as they’re out and tested; everything else at least monthly. That’s exactly what a SecOps retainer or care plan covers.

Next step

Find out what an attacker would find

Tell us what you run. We’ll reply with a scope, dates and a fixed price, and you decide from there.

Projects: marketing@eterni.tech Everything else: contact@eterni.tech