Website Security

Website security hardening

Close the gaps attackers use. We review how your WordPress or WooCommerce site could be broken into and close each gap, from outdated plugins and weak logins to file permissions and admin tools that should not be public.

Book a free call See our work Fixed quote after a free call

What you get

  • Software
  • Logins
  • Code changes
  • Server
  • Exposed tools
  • Backups

Sound familiar?

  • Plugins and themes are months behind on updates.
  • Several people share one admin login, without two-factor authentication.
  • Anyone who gets into the dashboard can edit the site's code.
  • You have never checked who has admin access.

Who it helps

  • Stores and member sites

    Customer accounts and payments that make the site worth attacking.

  • Sites after a cleanup

    The gaps closed so the next attempt fails.

  • Agencies

    One hardening standard applied across client sites.

What is included

  • Software WordPress, plugins and themes updated, and abandoned plugins replaced
  • Logins Two-factor authentication, one account per person and the fewest privileges each needs
  • Code changes The dashboard file editor and plugin installs locked when they are not needed
  • Server File permissions, configuration file protection and PHP settings checked
  • Exposed tools XML-RPC, old installers, backups and debug logs removed from public view
  • Backups Off-site backups confirmed, and a restore tested

Not included

  • Hosting changes (we recommend; you choose the host)
  • A guarantee that no attack can ever succeed (nobody can honestly offer one)

How WordPress sites are really broken into

Most successful attacks on WordPress sites use a small number of gaps: a plugin or theme with a known vulnerability, a weak or reused password, an admin account nobody remembers, or a tool left public that should not be. Hardening closes those gaps in order of risk, rather than piling security plugins on top of them.

Locking the code

If an attacker gets into the dashboard, the quickest damage is done by editing theme files or uploading a plugin. On the sites we manage, Guardian Shield Lite keeps the code locked: new code needs approval before it can run, and changes are made during time-limited, recorded unlocks.

Security that does not break the site

Every change is tested against what the site must keep doing: checkout, logins, forms and integrations. Hardening that breaks a store is not security; it is an outage.

How it works

  1. Free call

    We talk about the site, who uses it and any past incidents.

  2. Review and quote

    A security review with the gaps ranked, and a fixed quote.

    From you: Admin and hosting access.
  3. Harden on staging

    Changes that could affect how the site works are made on a copy first.

  4. Apply and test

    Changes applied to the live site, and every key function tested.

  5. Keep it closed

    Optional monitoring and updates so the gaps stay closed.

What affects the price

Every project gets a fixed quote after a free call, so you know the total before anything starts. These are the things that move it.

  • Number of plugins and amount of custom code
  • Hosting type and access
  • Number of users and roles
  • Updates that need testing
  • Ongoing monitoring

Where we have done this

Snowy Owl Sled Dog Tours and White Wolf Rafting
  • Service business
  • Website security
  • Malware removal

Malware removed and two sister tour company websites locked down

Challenge
In October 2023 visitors to the Snowy Owl Sled Dog Tours website started seeing spam pop-ups and redirects. The site also ran an outdated PHP version, an outdated theme and several unused plugins, and it had not been updated since it was built.
Result
The infection was removed and the way in closed within about two weeks of the first report. By 6 November 2023 both sites were fully updated and on PHP 8.2.
WordPress security plugin

Guardian Shield Lite

Our WordPress security plugin: code stays locked, known malware is removed with evidence kept, and every site reports to one hub.

  • Code locked, changes in recorded windows
  • Known malware removed, evidence kept
  • Every site watched from one hub

Questions about website security hardening.

Is a security plugin enough?

A security plugin helps, but it cannot fix an outdated plugin, a shared admin login or a server setting. Hardening fixes the gaps themselves.

Will hardening break my site?

It should not. Changes that could affect how the site works are tested on a staging copy first, and every key function is checked afterwards.

Do you set up two-factor authentication?

Yes, for every account with administrator or shop manager access, using an authenticator app.

How often does a site need hardening?

After the first round, the work is keeping it that way: updates, access reviews and monitoring. We can do that as part of a maintenance plan.

Do you work on sites you did not build?

Yes. We review and harden sites whoever built them.

Tell us your goal. We'll show you the plan.

Book a free 30-minute call. You'll leave with a clear plan and a fixed quote, whether you hire us or not.

Book my free call
Free call, no obligationBook my call