
The audit + remediation engagement is the one to book before something happens. The retainer is the one that keeps the hardening from rotting six months later.
Senior WordPress engineering since 2007 · E-E-A-T-first builds with verified schema, AODA and WCAG 2.2 AA compliance · dozens of plugins released, five on WordPress.org, 18+ WordCamp talks · Fort Erie, Ontario
Book the 20-minute discovery call See full pricing and scope
The problem you’re solving
Most WordPress sites get compromised through a small number of well-documented doors: weak admin credentials, an outdated plugin with a known CVE, a left-behind user account with administrator rights, or a misconfigured file-upload field. None of those are exotic. Almost none of them get fixed until after the site is already shipping pharmacy spam from the footer.
The hardening engagement closes the doors before someone walks through them. Three days, fixed scope, written report you can hand to your insurer or your security committee.
What you get
- A hardening pass. Login URL, file permissions, salts and keys, disable file editing, restrict XML-RPC where appropriate, secure wp-config.php, lock down the upload pipeline, set HTTP security headers.
- User and role audit. Every account reviewed. Stale admins removed, role assignments cleaned up, capability creep documented and reset.
- Two-factor authentication for administrators. Configured, tested, and documented for your team. App-based by default; backup-code procedure included.
- Web application firewall configuration. Either at the host level (if your host provides one) or via a plugin layer. Rules tuned for WordPress, not generic.
- Malware scan. File-system and database scan, with quarantine recommendations on anything suspect. If the scan finds an active compromise, the engagement pauses and converts to incident response (separate hourly engagement; you will not be silently up-billed).
- Written remediation report. What I did, what I found, what is left to do, and the priority order. The document survives a security committee review.
Hardening rots over time as new plugins get installed, new users get added, and new vulnerabilities get disclosed. A Security Retainer keeps the hardening current with a monthly review, plugin update strategy, monitoring, and a quarterly written status. The retainer is optional and the FAQ below covers when it makes sense.
What this is not
- Not incident response. If your site is currently compromised, defaced, sending spam, or actively under attack, this is the wrong engagement. Email me directly; incident response is hourly and starts the same day.
- Not a penetration test. The hardening pass is preventive, not adversarial. If you need a full pentest with a written attestation, I will refer you to specialists.
- Not a one-time vaccine. Without ongoing review, the hardening you pay for in May is partially gone by October. The retainer exists for exactly this reason.
- Not “we’ll just install Wordfence.” Wordfence is a fine tool inside a real hardening strategy and a useless tool by itself.
Who this is for
- Fit. Operating WordPress sites that hold customer data, take payments, or whose downtime would cost real money.
- Fit. Organizations whose insurance carrier or compliance program is asking for documented security posture.
- Fit. Teams who have inherited a WordPress site from a previous developer and have no idea what was done to lock it down (likely answer: very little).
- Not fit. Sites currently under active attack. That is incident response.
- Not fit. There is no honest cheaper version of this work; what looks cheaper is usually a security plugin install and a confidence-trick report.
The three-day hardening engagement, day by day
- Day 1. Access provisioned. User and role audit. Plugin and theme inventory. File-system and database scan.
- Day 2. Hardening pass. 2FA configured. WAF tuned. HTTP headers set. Login surface locked down.
- Day 3. Verification, written report, and a 30-minute walkthrough call to hand off to your team.
Why work with me on this specifically
- WordPress development since 2007. Security work has been part of the job since well before WordPress security was an industry of its own.
- Curriculum developer and instructor at the M.L. Campbell Training Centre, Sherwin-Williams’ training facility. Part of the team on a 2011 to 2012 migration for one of Canada’s largest news networks, where the security surface was a daily concern.
- Author of practical WordPress and SEO articles. Speaker at WordCamp Toronto.
Common questions
We already run a security plugin. Is that not enough?
It helps, and it is not the same thing. A security plugin watches for known attacks. Hardening reduces what an attacker can reach in the first place: file permissions, admin surface, what runs with what privileges, and which of your plugins is quietly abandoned upstream. The plugin is the alarm. Hardening is whether the door was worth alarming.
What if we have already been compromised?
Say so on the call, because that changes the order of everything. Hardening a compromised site just locks the attacker in with your data. Clean-up comes first, then we find how they got in, then we harden so it does not recur. Skipping the middle step is why sites get re-infected within weeks.
Will hardening slow the site down?
No, and in a few places it speeds things up, because a fair amount of hardening is removing things that were running for no reason. Where a control has a genuine performance cost I will tell you what it buys you, and you decide. Security you cannot live with gets switched off within a month, which helps nobody.
Ready when you are
Security and hardening, three shapes. The security audit ships a written findings report organized by severity with reproduction steps and recommended fixes. The audit-plus-remediation engagement implements the critical and high findings and hands you the diff. The ongoing hardening retainer keeps the posture current with post-update reviews, new-plugin audits, and quarterly re-scans.
Pay up front, get access provisioned, the clock starts.
Book the 20-minute discovery call See full pricing and scope
Tell me about your project
The fastest way to a straight answer. Tell me what you need and I will reply within a business day, honestly, even when the answer is that I am not the right fit.
Prefer to talk? Call 647-641-0643
Share your project details
Use this form for project scope, technical SEO support, onsite training requests, or a focused next-step conversation.