WordPress security · from $79/mo
Almost every hacked WordPress site was months out of date.
Not targeted, not sophisticated — running a plugin with a published flaw that a bot found automatically. Security for a normal business site is mostly the boring discipline of patching fast, and that is what we sell.
How sites actually get in trouble
Outdated plugins
The overwhelming majority. The flaw was public and patched; the site was not.
Reused passwords
One leaked credential elsewhere, tried automatically against your login.
Nulled themes and plugins
Pirated premium software very often ships with a backdoor included.
A compromised host account
Shared hosting where a neighbouring site was the way in.
What we do, and when.
Continuous
Vulnerability monitoring
Your installed plugins checked against a live vulnerability database. When a flaw is disclosed for something you run, we patch within days rather than at the next update cycle.
Weekly or daily
Malware scanning
Weekly on every plan, daily with the advanced security add-on. Files and database both, because injected code hides in the database more often than people expect.
Once, then checked
Hardening at onboarding
File editor disabled, correct file permissions, XML-RPC restricted, security headers set, debug output turned off, and predictable admin usernames flagged.
Ongoing
Access control
Two-factor authentication on administrators, login rate limiting, and a review of who actually still needs access — usually fewer people than have it.
Add-on, $29/mo
Firewall
With the advanced security add-on: a web application firewall in front of the site, blocking known attack patterns and abusive countries before they reach WordPress.
Free on any plan
Cleanup if it happens anyway
No security is perfect. If a site under our care is compromised, we clean it at no charge, every time, with no argument about whose fault it was.
What a security plugin cannot do
Wordfence and its equivalents are good tools and we use them. But a plugin tells you something is wrong; it does not update the vulnerable plugin, decide whether a change is legitimate, or clean an infection without breaking the site.
The gap between "scanner alerts you" and "somebody acts on it" is where nearly every compromise we clean actually happened.
What we will not claim
Nobody can promise a site will never be compromised, and anyone who does is selling you something. What we promise is that it is patched fast, watched continuously, and that if it happens we fix it free and you are not left working out what to do at 11pm.
Read the guaranteesWant to know where your site stands right now?
Our free plugin checks your site against the live vulnerability database and tells you what it finds. No account, nothing to buy, and it changes nothing.