WordPress security hardening
Cleaning an infected site is the expensive way to learn where the hole was. Hardening closes those holes first, so the automated scanners that probe your site every day find nothing worth taking.
Six things I change on a WordPress site
Every one of these closes a route I have seen used on a real cleanup.
Login protection
Remove the default admin username, enforce strong passwords, add two-factor authentication and limit login attempts so brute-force attacks get nowhere.
File permissions
Set correct permissions across every WordPress file and folder, so only the accounts that should be able to change code can change it.
Database security
Change the table prefix, secure the credentials and restrict access, which makes SQL injection considerably harder to pull off.
Reduce what is visible
Strip version numbers, disable XML-RPC and move the login page, so automated scanners cannot fingerprint what you are running.
Security headers
Add the HTTP headers that protect against cross-site scripting, clickjacking and MIME-type attacks.
Turn off what you do not need
Disable dashboard file editing and directory browsing, and remove features that only widen the attack surface.
Cleaning up costs more than staying clean
A compromise is not only the cleanup fee. It is the downtime, the lost traffic while Google shows a warning, and the work of getting a suspended host to lift the block.
Without hardening
- Default login paths that every scanner tries first
- Writable files an injected script can quietly modify
- Version numbers that tell an attacker which exploit to use
- XML-RPC left open for automated password guessing
After hardening
- Brute-force attempts blocked before they reach WordPress
- File permissions that stop code being written where it should not be
- Far less information exposed about what you are running
- Unused entry points switched off entirely
£59 covers it, whether your site is hacked or not. Hardening is included in every cleanup, and it is the same fixed price on its own for a standard WordPress site. Complex, ecommerce and multisite installations are quoted before any work begins.
Questions about hardening
Do I need hardening if my site has never been hacked?
Most WordPress sites are attacked by automated scanners rather than by someone targeting you specifically. Hardening closes the doors those scanners look for, which is why it is cheaper and less disruptive than a cleanup after the fact.
Will hardening break my site or slow it down?
No. I take a backup first and apply changes one at a time, checking the site keeps working after each. Nothing here adds meaningful load, and I tell you about anything that changes how you log in.
Is hardening included when you clean a hacked site?
Yes. Every £59 malware removal includes hardening, because removing the malware without closing the entry point just means it comes back. This page is for owners who want the same work done before anything goes wrong.
What does hardening on its own cost?
£59, the same fixed price as a cleanup, for a standard WordPress site. Complex sites, ecommerce stores and multisite installations are quoted upfront before any work begins.
Lock your site down before it costs you
Fixed £59 for a standard WordPress site, the same price as a cleanup. Response within 2 hours.