Home/Services/WordPress Security
security service

WordPress Security

European WordPress security: expert hardening, plugin auditing and fixes by OSCP-certified engineers. Fixed price from EUR1,200. Free retest, NDA, EU-wide.

Manual, expert-ledEvidence-based findingsFree remediation retest

WordPress security is mostly about closing the handful of gaps that attackers actually use, because in the vast majority of the WordPress compromises we clean up, the way in was an out-of-date plugin or a weak admin password, not some novel zero-day. SafetyBis hardens WordPress sites for businesses across Europe: we audit what you run, fix the real weaknesses, and lock the site down so the automated attacks that hit every WordPress install go nowhere.

WordPress powers a huge share of the web, which makes it the most attacked platform there is. That popularity is not a flaw in WordPress itself; the core is well maintained. The risk lives in the ecosystem around it, in the plugins and themes and configurations that individual sites bolt on and then forget to look after.

What WordPress security actually involves

Securing WordPress is not installing one plugin and calling it done. It is a set of deliberate changes across the software, the users, the configuration and the hosting, aimed at removing the specific weaknesses that get WordPress sites breached at scale.

Auditing every plugin and theme against known vulnerabilities
Locking down wp-admin and login with rate limiting and strong authentication
Correct file permissions and a hardened wp-config.php
Removing unused plugins, themes and default accounts that widen the surface
A tuned firewall and, where you want it, ongoing security scanning
A manual review that a plugin’s own scan will never do

Whether you run a single business site or you are an agency looking after dozens of client installs, the fundamentals are the same. The difference is scale, and we work with both.

Why WordPress sites get attacked

Understanding the why makes the fixes make sense. WordPress attacks are almost never personal; they are automated, opportunistic, and aimed at everyone running the same vulnerable component.

Most
compromises we see start with an outdated plugin
100%
manual hardening, verified by an engineer
Free
retest after the hardening is in place

The plugin and theme ecosystem

The average WordPress site runs a stack of plugins from many different authors, of wildly varying quality. When a popular plugin ships a vulnerability, it becomes a mass-exploitation campaign within hours, sweeping every site that runs it. The plugin is the entry point far more often than the core or the theme.

Weak accounts and exposed logins

A default “admin” username, a reused password, and a login page open to the whole internet with no rate limiting is a combination that automated brute-forcing finds and beats. A large share of WordPress compromises need nothing more sophisticated than that.

Neglect over time

Sites drift. A plugin that was safe at launch picks up a vulnerability, a theme stops being maintained, an admin who left still has an account. Security is a state you have to keep, not a box you tick once, and WordPress rewards the sites that stay on top of it.

How we harden WordPress

Our hardening follows a clear sequence, and you get told what we changed and why. This is expert configuration work, not clicking “optimize” in a plugin dashboard.

Audit

First we take stock: every plugin and theme with its version and vulnerability status, the user accounts and their roles, the file permissions, the wp-config settings, and the hosting setup. This is a WordPress security scan done with an engineer’s eye, so it flags the risks a tool would rank as informational.

Software and dependencies

We update or replace vulnerable plugins and themes, remove anything unused, and check the provenance of what remains, because nulled or pirated plugins are a classic way malware arrives baked in. Fewer, well-maintained components is a more secure site than a pile of half-used ones.

Users and authentication

We remove default and stale accounts, enforce strong passwords, add rate limiting and, where appropriate, two-factor authentication on wp-admin, and rename or protect the login endpoint to cut brute-force noise. We also review roles so contributors do not quietly hold more power than they need.

Protecting wp-admin

The admin area is the prize, so it gets particular attention: limiting access by IP where practical, disabling file editing from the dashboard, and making sure a compromised low-privilege account cannot walk up to full control.

Configuration and files

We set correct file and directory permissions, harden wp-config.php, disable directory listing, block execution of PHP in the uploads folder, and remove the version-leaking and debug output that helps an attacker profile your site. Small changes, but they close the doors that automated tools rattle first.

WordPress security best practices

The guidance below holds true through 2025 and 2026 and beyond, because it targets how sites are actually breached rather than the plugin of the month. If you take nothing else from this page, take these.

Keep everything updated

The most valuable WordPress security best practice by a wide margin is keeping core, plugins and themes current, and removing what you do not use. It is unglamorous, and it prevents most compromises on its own.

Least privilege and strong access

Give each user the lowest role that lets them do their job, use unique strong passwords, and put two-factor on administrator accounts. Most breaches escalate through an account that had more access than it needed.

Defence in depth

Layer a tuned firewall in front, keep monitoring behind, and take real backups you have actually tested restoring. No single measure is enough; the combination is what makes a site genuinely hard to breach.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Plugins are not a security strategy

People ask us for the best WordPress security plugin, and the honest answer is that the question is slightly wrong. A good security plugin helps: it adds a firewall, rate limiting and a scanner, and we install and configure reputable ones. But a plugin applies generic rules and cannot fix the underlying problems.

A plugin will not remove the abandoned theme carrying a vulnerability, decide which of your accounts should lose admin rights, or correct file permissions the way a hardened setup needs. It scans for patterns it recognises and stays silent on the misconfiguration and the logic issues that a person would catch. The best WordPress security scanner is a useful alarm, not a locksmith. Treat plugins as one layer on top of proper hardening, never as a substitute for it, and you get the value without the false confidence.

Scanning, monitoring and testing

Hardening sets a strong baseline. Keeping it means watching the site as it changes, and going deeper where the stakes are high.

Ongoing scanning and monitoring

For sites that matter, continuous monitoring watches for file changes, new admin users and newly disclosed vulnerabilities in what you run, so a problem is caught in hours rather than discovered by a customer. This pairs naturally with the hardening as an optional monthly add-on.

Penetration testing for custom builds

If your WordPress site has custom plugins, a membership area, WooCommerce with real money moving through it, or an API, a manual penetration test finds the business-logic and access-control flaws that hardening and scanning cannot. That is a separate, deeper engagement we also provide.

Compliance and standards

If your WordPress site holds personal or payment data, hardening is also about being able to show you took reasonable measures.

PCI DSS and GDPR

A WooCommerce store handling card data falls under PCI DSS, which expects hardening, testing and a firewall. For any site holding personal data, GDPR expects appropriate technical measures, and a documented hardening and monitoring process is part of demonstrating that.

ISO 27001

Hardening and vulnerability management map to ISO 27001 Annex A controls, including A.12.6, and our documentation of what was changed supports that evidence trail.

Hardening beyond the basics

Once the fundamentals are in place, a few WordPress-specific surfaces are worth closing that most sites leave wide open. These are the details that separate a site that merely passes a scan from one that is genuinely difficult to attack.

XML-RPC and the REST API

WordPress ships with interfaces that are useful to some sites and pure attack surface to others. XML-RPC is a favourite for brute-force amplification and can usually be disabled outright. The REST API leaks user names by default, which feeds credential attacks, so we restrict what it exposes to anonymous visitors.

Backups you have actually tested

A backup you have never restored is a hope, not a plan. We check that backups exist, run off the server rather than only on it, and can actually be restored, because the worst time to discover a broken backup is the day after a compromise.

What you get

You get a materially harder-to-breach site and a clear record of what was done, which matters if a client, insurer or auditor ever asks.

An audit of every plugin, theme, account and setting with its risk
The hardening changes applied, documented so you know what changed
A prioritized action list for anything left to your team
A free retest to confirm the hardening holds

Pricing

WordPress hardening is a fixed-price project, scoped by the size of the site, how many plugins are in play, and whether it is custom or off-the-shelf. Ongoing protection is an optional monthly add-on on top.

Engagement What’s included Timeline Price
Hardening review Single site: full audit, core, plugin and theme review, wp-config and permission hardening, login protection, free retest 2–4 working days from €1,200
Hardening + fixes Everything above plus applying updates and fixes, firewall setup, user and role cleanup, larger or multi-plugin sites 4–7 working days €1,800–€3,500
WordPress penetration test Manual testing of a custom build, WooCommerce or membership site, with an exec and technical report 5–8 working days from €2,500
Managed WordPress security Ongoing scanning, monitoring, patching and firewall, added after hardening continuous from €150/month
Custom / agency estate Many client sites under one programme, scoped for agencies and multisite on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote

FAQ

How much does WordPress security cost?
A hardening review starts from €1,200, with hardening plus fixes in the €1,800 to €3,500 range depending on the site. Ongoing managed protection is an optional add-on from €150 per month. You get a fixed quote after a free scoping call.
What is the best WordPress security plugin?
A reputable firewall-and-scanner plugin helps and we configure one, but no plugin replaces proper hardening. Plugins apply generic rules; they will not remove an abandoned vulnerable theme or fix your file permissions and user roles. Treat a plugin as one layer, not the whole answer.
Can you secure a site that is already hacked?
Yes. If the site is currently compromised we clean it first through our recovery service, then harden it so the same route cannot be used again. Hardening a still-infected site would only lock the attacker in with you.
Do you work with WooCommerce and membership sites?
Yes, and those benefit most from a deeper look. A store handling card data or a members’ area with accounts has real money and personal data at stake, so we often pair hardening with a manual penetration test.
How long does WordPress hardening take?
A hardening review is usually 2 to 4 working days, and hardening with fixes 4 to 7, depending on the number of plugins and the state of the site. You get the timeline with your fixed quote.
Do you work with agencies managing many sites?
Yes. Agencies come to us to harden and monitor client estates under one programme, with consistent standards across every install. We scope that to the number of sites and how hands-on you want us to be.
Will hardening break my site or my plugins?
No. We test changes as we make them and roll back anything that interferes with legitimate functionality. The goal is a locked-down site that still works exactly as your users expect.
Is my site and its details kept confidential?
Always. The work runs under an NDA and access details are handled securely, shared only with the people you name. As a European provider we treat your data accordingly.

Related services

Who needs this

Businesses and agencies across Europe running WordPress, especially WooCommerce stores, membership sites and custom builds, who want the platform hardened properly against the automated attacks that hit every install, rather than trusting a single plugin to do it all.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "WordPress Security"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.