Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Server & firewall

Server hardening and WAF protection for WordPress

Beyond the WordPress layer, the underlying server can be hardened too: SSH and user hardening, firewall rules, hardened PHP-FPM, Apache, and Nginx configuration, plus a suitable WAF with rate limits and bot protection. Most relevant for your own or dedicated hosting — less so for plain shared hosting without server access.

Server hardening and edge protection complement WordPress hardening, they don't replace it. Together, both layers reduce the attack surface far more than either does on its own.

Server hardening

WAF and edge protection

Regular review, not a one-time install

A WAF that gets configured once and never reviewed again loses effectiveness over time — new endpoints, changed plugins, or new attack patterns require adjusted rules. We agree with you on a sensible review cadence.

Server hardening works best alongside a hardened WordPress installation. See WordPress hardening →

Not sure which server hardening fits your hosting? We're happy to advise, no obligation.