WordPress hardening
WordPress hardening after a security incident
After a cleanup — or independently of one — we harden your WordPress installation against repeat attacks: roles and permissions, access protection, file permissions, update and backup processes, and an integrity baseline with monitoring. We agree the required scope with you before providing a quote.
No measure prevents every attack. Hardening reduces known entry points, limits access and permissions, and makes suspicious changes easier to detect. The appropriate measures depend on hosting, plugins, user roles, and operational requirements.
What WordPress hardening includes
- role and permission cleanup
- multi-factor authentication and secure administrator access
- session and application-password management
- secure update processes
- disabling the dashboard file editors
- file permissions and a writable runtime allowlist
- PHP execution locks in upload, cache, and backup directories
- secret and salt rotation
- backup and restore testing
- integrity baseline and monitoring
Pricing for add-on services
The €699 fixed-price cleanup already includes baseline hardening. The scope of further hardening work depends on your installation and requirements. We provide a price after a short assessment and before you commission the work.
If your site runs on your own or a dedicated server, server hardening and WAF protection are a useful complement to WordPress hardening. See server hardening and firewall →
Not sure where to start? We're happy to advise, no obligation.