Lock the doors before someone tries the handle.

A practical security review of your WordPress installation, hosting, user accounts, and access controls. Three fixed-fee packages from £395.

Most security work is preventative. The aim is not to claim a website can never be compromised. It is to remove unnecessary weaknesses, improve recovery readiness, and make common automated attacks less likely to succeed.

Hardening or hacked-site recovery? Choose hardening when the site is currently operating and you want preventative work. Choose Emergency Support when there are active signs of malware, unauthorised access, or website failure.

What the engagement includes

Security Audit

A review of your WordPress installation, plugins, themes, hosting, user accounts, and current security configuration.

Firewall Setup and Configuration

Appropriate firewall settings to reduce malicious traffic, automated attacks, and common WordPress exploits.

Malware Scanning and Threat Detection

Scanning for suspicious code, backdoors, spam injections, and indicators of compromise.

Login and Access Protection

Measures to reduce brute-force attempts, improve account security, and remove unnecessary access.

Backup Strategy Review

A check that suitable backups exist, are stored appropriately, and can support recovery if an incident occurs.

Security Hardening and Report

Package-specific configuration work, followed by a report explaining identified risks, work completed, and further recommendations.

Choose a package

Standard

Security Hardening

£395 fixed fee

For small business websites, brochure sites, blogs, and portfolios with straightforward WordPress installations.

  • Security audit
  • Firewall configuration
  • Malware scan
  • Login protection
  • Backup review
  • Plugin and theme audit
  • Security report

Typical fit: under 20 plugins, standard hosting, no ecommerce or membership functionality.

Enterprise

Security Hardening

£995 fixed fee

For ecommerce, membership, high-traffic, and business-critical systems handling customer accounts or operational data.

  • Everything in Advanced
  • Payment workflow review
  • User role and permissions audit
  • Advanced server-side recommendations
  • Multiple integrations and APIs
  • Higher compliance requirements

Typical fit: WooCommerce stores, booking systems, learning platforms, and customer portals.

Frequently asked questions

Will hardening guarantee the site cannot be hacked?

No. No provider can guarantee complete security. Hardening reduces known and avoidable risks and improves the site's ability to withstand common attacks.

Do you install a firewall?

Firewall configuration is included in every package where it is technically appropriate for the hosting and website setup.

Is malware removal included?

The packages include a malware scan. If an active compromise is found, clean-up may require a separately scoped recovery engagement because the time and risk can vary substantially.

Is the service suitable for WooCommerce?

Yes. The Enterprise package is designed for ecommerce and other systems with user accounts, payment workflows, and more complex integrations.

Do you need hosting access?

Usually, yes. WordPress admin access alone may not be sufficient to review backups, server configuration, files, logs, or firewall settings. We arrange credentials securely after the service is confirmed.

Ready to strengthen the site?

Tell us what the website does, how it is hosted, and whether there are any current security concerns. We will recommend the appropriate package.