WordPress security
WordPress security, from people who build WordPress
Most hacked WordPress sites weren’t targeted. They were found: an old plugin, a reused password, an exposed file. We audit, harden and fix WordPress sites so the automated attacks that hit every site, every day, find nothing to use.
What’s included
Done properly, start to finish
Plugin and theme audit
Every plugin and theme checked against known vulnerabilities, abandoned projects flagged, and anything you don’t need removed.
Users and access
Admin accounts reviewed, roles cut down to what each person needs, and two-factor sign-in for anyone who can change the site.
Login protection
Rate limits, lockouts and generic error messages, so password guessing gets nowhere and usernames stay private.
Locked-down configuration
Dashboard file editing off, XML-RPC and user listing closed, PHP blocked in uploads, correct file permissions.
Security headers and CSP
HSTS, a strict content security policy and the other headers that stop whole classes of attack in the browser.
Backups that restore
Off-site backups on a schedule, and a restore we’ve actually tested, so a bad day stays a bad day.
The hardening checklist
Twenty things we check on every WordPress site
Grouped the way an attacker would approach them: who can get in, what code runs, what the server allows, and what the browser trusts.
Access
- Two-factor sign-in for admins
- No shared or default admin accounts
- Least-privilege roles
- Login rate limiting and lockout
- Application passwords reviewed
Code
- Core, plugins and themes current
- Abandoned plugins replaced
- Custom code checked for escaping and nonces
- No nulled or pirated plugins
- Dashboard file editing disabled
Server
- PHP blocked in uploads
- Correct file ownership and permissions
- wp-config.php and dotfiles protected
- XML-RPC disabled
- Directory listing off
Browser
- HTTPS with HSTS
- A content security policy
- Clickjacking protection
- Referrer and permissions policies
- Secure, HTTP-only cookies
The steps
From first message to closed
- 01
Audit
Everything above checked, findings ranked by risk.
- 02
Harden
We apply the fixes, with a backup first.
- 03
Verify
Every page and form re-checked; a short report.
- 04
Keep
Monthly updates and checks, if you want them.
Start here
Request a security assessment
Tell us what you run and what worries you. We’ll reply with a scope, dates and a fixed price in writing, and you decide from there.
- A reply from the people who’ll do the work
- Scope, dates and a fixed price before anything starts
- An NDA before we start, if you want one
- Nothing is tested without written authorization
Urgent? Message us on WhatsApp ↗
Isn’t a security plugin enough?
It helps, but it’s one more piece of code with access to everything, and it can’t fix an outdated plugin, a weak admin password or a misconfigured server. We fix the causes. Whether you keep a security plugin afterwards is up to you.
Will hardening break my site?
Not if it’s done carefully. We take a backup first, try changes on a staging copy where we can, and check every page and form afterwards.
Do you secure sites built with Elementor or other page builders?
Yes. We secure the site you have. If the page builder itself is part of the problem, or the reason the site is slow, we’ll tell you and explain the options.
How often should WordPress be updated?
Security updates as soon as they’re out and tested; everything else at least monthly. That’s exactly what a SecOps retainer or care plan covers.
More security services
The rest of the loop
Manual testing of your website, web app or API, following the OWASP testing guide, with every finding re-tested after it’s fixed.
Read more → Vulnerability remediationBring us a pentest report, scan results or a host warning. We fix every finding and re-test it.
Read more → Hack recoveryMalware removed, the entry point found and closed, passwords rotated and search warnings cleared.
Read more → Security operationsMonthly patching, access reviews, log checks and incident response, run by the people who know your site.
Read more →