A hack doesn’t just take your site down. It takes your reputation.

Days of downtime, customers greeted by malware warnings, weeks rebuilding Google’s trust — plus an emergency recovery from $490 you didn’t need to buy. Hardening costs less than one bad day. On every care plan it’s simply included — firewall, login protection, daily malware scanning, kept up every month from $149. As a one-off project: send the URL and you’ll have a fixed quote within one business day, with written findings inside the first week of work.

Eight things every WordPress site should have.

The plugin sees the things inside WordPress; the rest sits between WordPress and the world.

Hardening audit

A written review with a fix list ranked by risk.

Firewall configuration

Cloudflare, Wordfence Premium, or Patchstack at the edge.

Login protection

2FA, login throttling, custom login URL, IP allowlisting.

Malware and file integrity monitoring

With a same-day alert if anything on disk changes.

SSL, HSTS, security headers

CSP, X-Frame-Options, Permissions-Policy.

User and role audit

Least privilege, and stale admin accounts removed.

REST API and XML-RPC

Exposure review and lockdown.

Backup verification

Backups that haven't been restored aren't backups.

All of it is included on every care plan — from $149/mo, month-to-month, first month refundable. On Growth and Premium, a hack on our watch is cleaned up at no charge.

See plans & pricing

A few things we’d bring a specialist in for.

For these you want a credentialed specialist alongside us — we’re happy to make the introduction and handle the technical follow-through.

  • Compliance — Formal penetration testing for compliance frameworks (SOC 2, ISO 27001, HIPAA)
  • DDoS — DDoS mitigation beyond Cloudflare's standard tier
  • Forensics — Forensic investigations for legal proceedings
  • Privacy law — Privacy and GDPR legal advice (we do the technical implementation only)

Security, specifically.

Is a security plugin enough?
It helps but it's not enough on its own. A typical WordPress hardening engagement also covers: a firewall at the edge, file permissions, wp-config hardening, login URL changes, 2FA, a user and role audit, and security header policy. The plugin sees the things inside WordPress; the rest sits between WordPress and the world.
Do you do penetration testing?
We do offensive-style hardening reviews — checking for the vulnerabilities a real attacker would actually try (outdated plugins, weak admin auth, exposed XML-RPC, REST API leaks, file upload paths, etc). We do not do formal pentests for SOC 2 / ISO 27001 / HIPAA compliance — for that you need a credentialed third-party firm, and we'll happily refer you to one.
What if I'm currently hacked?
Stop here and go to Emergency Help. Recovery first, hardening after. Trying to harden a compromised site usually just locks the attacker in deeper.
Do you do GDPR / cookie compliance?
We configure cookie banners and basic GDPR-required disclosures (privacy page, data export and delete via WordPress core), but we are not lawyers. For regulated industries, work with privacy counsel and use us as the technical implementation arm.

Get a security baseline before you need one.

Hardening costs less than recovery — and on every care plan it’s included. Send your URL for a one-off: we reply within one business day with a concrete recommendation and a fixed quote.

Already hacked? Start here →