Keep your WordPress site off our repair list.
Hardening, monitoring and patching, run as an ongoing service rather than a one-off checklist. Built for site owners who’d rather not find out how good their backups are.
The problem
Most WordPress sites are open by default.
A new WordPress site is fairly safe. Six months on, with a dozen plugins, an old theme and a reused password, it usually isn’t. Attackers rarely target you by name. They scan millions of sites at once, looking for the same known gaps.
The fix isn’t one big lockdown. It’s small habits, done well, over and over: set the right permissions, protect logins, patch plugins fast, and have someone watch when things look off.
If your site already shows signs of a hack, this isn’t the right page yet. Go to hacked site repair first. Come back here once it’s clean, to stop it happening twice.
What you get
Hardening that actually holds up.
Server and file hardening
Permissions locked down, security headers set, and loose attack surfaces like XML-RPC switched off unless your site genuinely needs them.
Login protection and 2FA
Rate limiting on login attempts and two-factor authentication for every admin account.
Web application firewall
A firewall sitting in front of your site, filtering known attack patterns before they hit your code.
Malware and vulnerability scanning
Regular scans of your files plus monitoring of disclosed vulnerabilities in the exact plugins and themes you run.
Patching within a window
Critical vulnerabilities get patched or the affected plugin disabled within a defined window, not at the next quarterly review.
Backups and incident response
Backups tested by restoring them, a log of who changed what, and a plan already written for the day something still gets through.
Process
How it runs.
Baseline review
We audit your current setup, list every plugin and theme, and check for known vulnerabilities. Usually a day or two.
Harden
We apply the fixes above: permissions, login protection, headers, firewall rules and 2FA.
Connect monitoring
Vulnerability and malware monitoring goes live, watching the specific software your site runs.
Ongoing patching and reporting
Critical issues get patched inside the agreed window. You get a plain-English summary each month.
Plugin limits
Honest about the limits of a security plugin.
A good security plugin scans for known malware, blocks obvious brute-force attempts and adds a basic firewall. That’s genuinely useful, and we use tools like it as part of our own stack.
What it won’t do: patch a weak plugin for you, catch a hand-built attack it hasn’t seen before, review your custom code, or make a judgement call when a log looks strange. That part still needs a person, not a plugin running on its own.
- We review every flagged issue ourselves, rather than forwarding you an alert and leaving you to work out what it means.
- Log and code-change analysis is AI-assisted, so an odd pattern surfaces in hours rather than at the next monthly review.
- Hardening is included on the Grow and Scale maintenance plans, and quoted as an add-on for sites on Care or on somebody else’s hosting.
Is WordPress secure?
The core software is well maintained and patched quickly. Most break-ins come through outdated plugins, weak passwords or old themes nobody’s touched in years, not through WordPress itself. Security is really about what you add on top of it.
Isn’t a security plugin enough?
A plugin can block common attacks and flag suspicious files, but it won’t patch a vulnerable plugin for you, review your code by hand, or tell you what to do when it finds something. It’s one layer, not the whole job.
What if I’m already hacked?
This service is for hardening a healthy site so it stays that way. If you’re currently compromised, head to our hacked site repair page instead. We can move straight into ongoing security once it’s clean.
What’s the difference between this and a maintenance plan?
Our maintenance plans cover updates, backups and small changes across the whole site. Security is narrower and deeper: hardening, a firewall, vulnerability monitoring and incident response. Grow and Scale maintenance plans include it. On Care, it’s added separately.
Do you need hosting access?
Yes, along with WordPress admin access. Hardening touches file permissions, server headers and login protection, which we can’t apply from inside WordPress alone.
How do you handle a critical plugin vulnerability?
We monitor vulnerability disclosures for the plugins running on your site. When something critical comes up, we patch or temporarily disable the affected plugin within a defined window rather than waiting for the next scheduled update run.