WordPress security hardening, done before a breach forces it

Terminal window showing chmod and htaccess commands in sharp focus with blurred server rack status LEDs in background right third

The audit + remediation engagement is the one to book before something happens. The retainer is the one that keeps the hardening from rotting six months later.

Senior WordPress engineering since 2007 · E-E-A-T-first builds with verified schema, AODA and WCAG 2.2 AA compliance · dozens of plugins released, five on WordPress.org, 18+ WordCamp talks · Fort Erie, Ontario

Book the 20-minute discovery call See full pricing and scope

The problem you’re solving

Most WordPress sites get compromised through a small number of well-documented doors: weak admin credentials, an outdated plugin with a known CVE, a left-behind user account with administrator rights, or a misconfigured file-upload field. None of those are exotic. Almost none of them get fixed until after the site is already shipping pharmacy spam from the footer.

From audit to ongoing Security The progression from an initial WordPress security audit and remediation engagement to long-term protection through a security retainer. The first phase is a fixed-scope hardening process lasting three days. This results in a written report detailing completed tasks and remaining priorities. A monthly retainer provides continued monitoring, updates and review. HARDENING From audit to ongoing Security The path from initial hardening to sustained protection. Initial hardening pass Three days: login URL review, file permissions, salts and keys, disable file editing, restrict XML-RPC, secure wp-config.php, lock down uploads, HTTP Security headers. Written remediation report Details what was done, findings, remaining tasks, and priority order for your team or Security committee. Security retainer (optional) Monthly review, plugin update strategy, monitoring, quarterly written status: keeps hardening current over time.
I lay out the three phases of my WordPress security service, a one-time pass, a report, and ongoing maintenance.

The hardening engagement closes the doors before someone walks through them. Three days, fixed scope, written report you can hand to your insurer or your security committee.

What you get

  • A hardening pass. Login URL, file permissions, salts and keys, disable file editing, restrict XML-RPC where appropriate, secure wp-config.php, lock down the upload pipeline, set HTTP security headers.
  • User and role audit. Every account reviewed. Stale admins removed, role assignments cleaned up, capability creep documented and reset.
  • Two-factor authentication for administrators. Configured, tested, and documented for your team. App-based by default; backup-code procedure included.
  • Web application firewall configuration. Either at the host level (if your host provides one) or via a plugin layer. Rules tuned for WordPress, not generic.
  • Malware scan. File-system and database scan, with quarantine recommendations on anything suspect. If the scan finds an active compromise, the engagement pauses and converts to incident response (separate hourly engagement; you will not be silently up-billed).
  • Written remediation report. What I did, what I found, what is left to do, and the priority order. The document survives a security committee review.

Hardening rots over time as new plugins get installed, new users get added, and new vulnerabilities get disclosed. A Security Retainer keeps the hardening current with a monthly review, plugin update strategy, monitoring, and a quarterly written status. The retainer is optional and the FAQ below covers when it makes sense.

What this is not

  • Not incident response. If your site is currently compromised, defaced, sending spam, or actively under attack, this is the wrong engagement. Email me directly; incident response is hourly and starts the same day.
  • Not a penetration test. The hardening pass is preventive, not adversarial. If you need a full pentest with a written attestation, I will refer you to specialists.
  • Not a one-time vaccine. Without ongoing review, the hardening you pay for in May is partially gone by October. The retainer exists for exactly this reason.
  • Not “we’ll just install Wordfence.” Wordfence is a fine tool inside a real hardening strategy and a useless tool by itself.

Who this is for

  • Fit. Operating WordPress sites that hold customer data, take payments, or whose downtime would cost real money.
  • Fit. Organizations whose insurance carrier or compliance program is asking for documented security posture.
  • Fit. Teams who have inherited a WordPress site from a previous developer and have no idea what was done to lock it down (likely answer: very little).
  • Not fit. Sites currently under active attack. That is incident response.
  • Not fit. There is no honest cheaper version of this work; what looks cheaper is usually a security plugin install and a confidence-trick report.

The three-day hardening engagement, day by day

  • Day 1. Access provisioned. User and role audit. Plugin and theme inventory. File-system and database scan.
  • Day 2. Hardening pass. 2FA configured. WAF tuned. HTTP headers set. Login surface locked down.
  • Day 3. Verification, written report, and a 30-minute walkthrough call to hand off to your team.

Why work with me on this specifically

  • WordPress development since 2007. Security work has been part of the job since well before WordPress security was an industry of its own.
  • Curriculum developer and instructor at the M.L. Campbell Training Centre, Sherwin-Williams’ training facility. Part of the team on a 2011 to 2012 migration for one of Canada’s largest news networks, where the security surface was a daily concern.
  • Author of practical WordPress and SEO articles. Speaker at WordCamp Toronto.

Common questions

We already run a security plugin. Is that not enough?

It helps, and it is not the same thing. A security plugin watches for known attacks. Hardening reduces what an attacker can reach in the first place: file permissions, admin surface, what runs with what privileges, and which of your plugins is quietly abandoned upstream. The plugin is the alarm. Hardening is whether the door was worth alarming.

What if we have already been compromised?

Say so on the call, because that changes the order of everything. Hardening a compromised site just locks the attacker in with your data. Clean-up comes first, then we find how they got in, then we harden so it does not recur. Skipping the middle step is why sites get re-infected within weeks.

Will hardening slow the site down?

No, and in a few places it speeds things up, because a fair amount of hardening is removing things that were running for no reason. Where a control has a genuine performance cost I will tell you what it buys you, and you decide. Security you cannot live with gets switched off within a month, which helps nobody.

Ready when you are

Security and hardening, three shapes. The security audit ships a written findings report organized by severity with reproduction steps and recommended fixes. The audit-plus-remediation engagement implements the critical and high findings and hands you the diff. The ongoing hardening retainer keeps the posture current with post-update reviews, new-plugin audits, and quarterly re-scans.

Pay up front, get access provisioned, the clock starts.

Book the 20-minute discovery call See full pricing and scope

Tell me about your project

The fastest way to a straight answer. Tell me what you need and I will reply within a business day, honestly, even when the answer is that I am not the right fit.

Prefer to talk? Call 647-641-0643

Share your project details

Use this form for project scope, technical SEO support, onsite training requests, or a focused next-step conversation.

Required fields.

Include your goals, team size, current blockers, and any launch or training date you have in mind.