Skip to content
WordPress hardening

Make attacking your site cost more than it's worth.

We harden access, permissions, server configuration and your WordPress defenses with concrete, verifiable changes - no magic plugins, no promises we can't keep.

The problem

What “hardening” a WordPress site actually means

WordPress’s default configuration is designed to be easy to install and use - not hard to attack. That isn’t a flaw; it’s a reasonable design decision for a project meant to power millions of very different sites. The problem is that this default configuration is exactly what automated attackers know by heart, as they probe thousands of sites an hour looking for the easiest door.

Hardening means closing those doors deliberately: limiting what an attacker can do even if they find a vulnerability, restricting who can access what, and making sure every attempt to get in is logged and blocked. It doesn’t make your site invulnerable - nothing does - but it does take it out of the “easy target” category, which is where the overwhelming majority of automated attacks live.

You don’t need to have suffered an attack to harden your site - in fact, it’s better not to wait for one. We start with a short, no-obligation assessment of your current configuration, and tell you exactly which changes are worth making in your case.

What's included

The full scope, no fine print

Every item is concrete, verifiable work. If something doesn't apply to your case, we say so in the diagnosis - not in an invoice.

  • Two-factor authentication (2FA) for every administrator account
  • Review and reduction of permissions: every user on the minimum role their work requires
  • Hardening of wp-config.php: unique security keys (salts), debug constants disabled, correct file permissions
  • A web application firewall (WAF) configured for your site - it filters malicious traffic before it ever reaches WordPress
  • Login rate limiting to shut down brute-force attacks
  • Protection of the admin panel and the most-attacked endpoints (xmlrpc.php, unneeded REST API routes)
  • Theme and plugin file editing disabled from the WordPress dashboard
  • Removal of plugins, themes and user accounts no longer in use - every one of them is a potential way in
  • Controlled updates of the core, themes and plugins to versions with no known vulnerabilities
  • Automated backups configured outside your hosting, verified to actually restore
  • HTTP security headers (Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options) where the hosting allows it
Process

How we do it

Steps in order, with honest timelines. When a deadline depends on a third party, we say so.

  1. 01

    Initial assessment

    We review your current configuration to see which changes apply to your case - not every site needs the same things.

    1–2 business days
  2. 02

    Hardening plan

    We show you what we're going to change and why, before touching anything. You confirm, and then we start.

    after the assessment
  3. 03

    Implementation

    We apply the changes in stages, verifying after each one that the site keeps working exactly as before.

    2–3 business days
  4. 04

    Verification and handover

    We test logins, forms and the site's critical functions, confirm the defenses with external tools and hand you the report.

    1 business day
Deliverables

What you get at the end

The job doesn't end with "done" - it ends with something you can read, keep and verify.

  • Your site with its defenses active, verified with external tools
  • A technical report: what was changed, why, and how to roll it back if ever needed
  • New credentials, delivered through a secure channel
  • Automated backups configured and verified with a test restore
  • Recommendations for keeping the hardening current - or the option of having us do it, with a monthly plan
Questions

Frequently asked questions

How much does it cost to harden a WordPress site?

It depends on how your site is configured today - a well-kept site needs less work than a fresh install. The initial assessment gets you a fixed quote before we start.

Does hardening guarantee I won't get hacked?

There's no such thing as 100% security, and we're not going to promise you that. What hardening does do is shrink the attack surface and raise the cost of getting in - which is exactly what takes your site off the easy-target list that automated bots do find.

Can I harden my site if it's never been hacked?

Yes - and it's both the most common case and the most sensible one. Hardening before an incident costs less and is far simpler than cleaning up after one.

What's the difference between hardening and a monthly plan?

Hardening is a one-off job: we lock your site down once and hand it over. The monthly plans keep those defenses current, with continuous monitoring and response if something happens - the managed version of making sure this doesn't quietly decay over time.

Harden my site

Tell us about your site and what you need - we'll reply within one business day, with a fixed quote before anything starts.

Would you rather this never happened again?

The monthly plans include continuous monitoring, backups and incident response - the managed version of the recommendations in your report.

View plans