WordPress security hardening, done before a breach forces it

The audit + remediation engagement is the one to book before something happens. The retainer is the one that keeps the hardening from rotting six months later.

Senior WordPress engineering since 2007 · E-E-A-T-first builds with verified schema, AODA and WCAG 2.2 AA compliance · 21 WordPress.org plugins, 18+ WordCamp talks · Fort Erie, Ontario

Book the 20-minute discovery call See full pricing and scope

The problem you’re solving

Most WordPress sites get compromised through a small number of well-documented doors: weak admin credentials, an outdated plugin with a known CVE, a left-behind user account with administrator rights, or a misconfigured file-upload field. None of those are exotic. Almost none of them get fixed until after the site is already shipping pharmacy spam from the footer.

The hardening engagement closes the doors before someone walks through them. Three days, fixed scope, written report you can hand to your insurer or your security committee.

What you get

  • A hardening pass. Login URL, file permissions, salts and keys, disable file editing, restrict XML-RPC where appropriate, secure wp-config.php, lock down the upload pipeline, set HTTP security headers.
  • User and role audit. Every account reviewed. Stale admins removed, role assignments cleaned up, capability creep documented and reset.
  • Two-factor authentication for administrators. Configured, tested, and documented for your team. App-based by default; backup-code procedure included.
  • Web application firewall configuration. Either at the host level (if your host provides one) or via a plugin layer. Rules tuned for WordPress, not generic.
  • Malware scan. File-system and database scan, with quarantine recommendations on anything suspect. If the scan finds an active compromise, the engagement pauses and converts to incident response (separate hourly engagement; you will not be silently up-billed).
  • Written remediation report. What I did, what I found, what is left to do, and the priority order. The document survives a security committee review.

Hardening rots over time as new plugins get installed, new users get added, and new vulnerabilities get disclosed. A Security Retainer keeps the hardening current with a monthly review, plugin update strategy, monitoring, and a quarterly written status. The retainer is optional and the FAQ below covers when it makes sense.

What this is not

  • Not incident response. If your site is currently compromised, defaced, sending spam, or actively under attack, this is the wrong engagement. Email me directly; incident response is hourly and starts the same day.
  • Not a penetration test. The hardening pass is preventive, not adversarial. If you need a full pentest with a written attestation, I will refer you to specialists.
  • Not a one-time vaccine. Without ongoing review, the hardening you pay for in May is partially gone by October. The retainer exists for exactly this reason.
  • Not “we’ll just install Wordfence.” Wordfence is a fine tool inside a real hardening strategy and a useless tool by itself.

Who this is for

  • Fit. Operating WordPress sites that hold customer data, take payments, or whose downtime would cost real money.
  • Fit. Organizations whose insurance carrier or compliance program is asking for documented security posture.
  • Fit. Teams who have inherited a WordPress site from a previous developer and have no idea what was done to lock it down (likely answer: very little).
  • Not fit. Sites currently under active attack. That is incident response.
  • Not fit. There is no honest cheaper version of this work; what looks cheaper is usually a security plugin install and a confidence-trick report.

The three-day hardening engagement, day by day

  • Day 1. Access provisioned. User and role audit. Plugin and theme inventory. File-system and database scan.
  • Day 2. Hardening pass. 2FA configured. WAF tuned. HTTP headers set. Login surface locked down.
  • Day 3. Verification, written report, and a 30-minute walkthrough call to hand off to your team.

Why work with me on this specifically

  • WordPress development since 2007. Security work has been part of the job since well before WordPress security was an industry of its own.
  • Curriculum developer and instructor at the M.L. Campbell Training Centre, Sherwin-Williams’ training facility. Part of the team on a 2011 to 2012 migration for one of Canada’s largest news networks, where the security surface was a daily concern.
  • Author of practical WordPress and SEO articles. Speaker at WordCamp Toronto.

Ready when you are

Security and hardening, three shapes. The security audit ships a written findings report organized by severity with reproduction steps and recommended fixes. The audit-plus-remediation engagement implements the critical and high findings and hands you the diff. The ongoing hardening retainer keeps the posture current with post-update reviews, new-plugin audits, and quarterly re-scans.

Pay up front, get access provisioned, the clock starts.

Book the 20-minute discovery call See full pricing and scope