WordPress Security & Hardening
Practical WordPress hardening, firewall configuration and malware clean-up for a site you own or are authorised to manage.
Custom quote after a short consultation · Timeline agreed in your quote
Scope: Work is carried out only on sites you own or are authorised to manage, with written authorisation before we start. This is practical hardening and remediation, not a certified penetration test or enterprise security service.
Overview
WordPress Security & Hardening reduces the common weaknesses that lead to compromised WordPress sites. Each package covers one site and applies a hardening checklist; higher packages add firewall and security plugin configuration, a malware scan and, in the Advanced package, clean-up of an infected site with a written report.
Before any work starts we need written authorisation confirming you own the site or are authorised to manage it. We then review the site's configuration, user accounts, plugins and file permissions, apply the checklist and configure protective settings. Where malware is found, we remove the infected code and restore affected files from clean sources.
This is practical hardening and remediation, not a certified penetration test or enterprise security service. It lowers risk, but no service can rule out future compromise, so we explain the habits that keep a site safer afterwards. Security plugin licences are paid separately.
Who it’s for
- Owners of WordPress sites that have never had a security review
- Businesses whose WordPress site has been hacked or flagged for malware
- Agencies and freelancers managing client WordPress sites with authorisation
- Organisations that want a written record of security work on their site
Problems it solves
- Fewer easy entry points for automated attacks
- A firewall and security plugin configured rather than left at defaults
- An infected site cleaned and returned to normal operation
- A clear record of what was changed and what to do next
What RF ETS delivers
- Hardening checklist applied to one WordPress site
- Firewall and security plugin configuration (Professional and Advanced)
- Malware scan of the site (Professional and Advanced)
- Malware clean-up of one infected site (Advanced)
- Written security report with recommendations (Advanced)
How we work
Authorisation and access
You confirm in writing that you own or are authorised to manage the site, then share admin and hosting access.
Review and back up
We take a backup and review users, plugins, themes, file permissions and configuration against the checklist.
Harden and configure
We apply the hardening steps and, where included, configure the firewall and run a malware scan.
Clean up and report
On the Advanced package we remove malware found, then document the work and recommended next steps.
What we need from you
- Written authorisation to work on the site
- WordPress administrator access
- Hosting or file access, for example through the hosting control panel
- Any security plugin licences you want configured
How pricing works
This work varies too much for fixed packages. We scope it with you, then send a written quote with price, timeline and deliverables before any work starts.
Tell us what you need
Use the quote form or book a consultation and describe your goal, constraints and deadline.
We scope it with you
We review your material and agree deliverables, assumptions and what is out of scope.
Written quote
You receive a fixed price or milestone plan, timeline and revision terms before any work starts.
Not included
- Penetration testing
- Security plugin licences
- Work on sites without your written authorisation
- No guarantee against future infection
- Third-party costs: domains, hosting, paid plugins and themes, software licences, API or AI-model usage fees, data-provider credits
- Work outside the written scope agreed before work starts (handled as an add-on or a custom quote)
- Ongoing support after the delivery and launch-support window unless a support package is bought
Need something different?
Tell us what you need, and we’ll prepare a solution and pricing based on your requirements.
WordPress Security & Hardening: common questions
How are the security packages priced?
Each package is a fixed price for one site and a defined checklist of tasks, so you can compare the packages above and book directly. Additional sites can be added, and security plugin licences are paid by you.
Are revisions included, and what if you find more than expected?
Revisions do not apply because the scope is a checklist of tasks. If we find issues beyond your package, such as an infection on a Starter or Professional package, we explain the options and confirm any extra work before carrying it out.
Is this a penetration test?
No. This is practical hardening and remediation, not a certified penetration test or an enterprise security service. We only work on sites you own or are authorised to manage, and we need written authorisation before we start.
Can you promise my site will not be hacked again?
No service can promise that. Clean-up removes the malware we find and hardening closes common weaknesses, but regular updates, strong passwords and careful plugin choices still matter. We explain the steps that keep the risk down.
Will hardening affect how my site works?
Hardening changes are chosen to avoid breaking normal site functions, and we back up the site before starting. If a setting conflicts with a plugin or feature you rely on, we adjust it and note the trade-off.
Often combined with
Website Maintenance & Support
Monthly website maintenance with core and plugin updates, backups, uptime monitoring and edit hours, plus reports and speed checks on higher plans.
Custom quoteView service →Web & Software DevelopmentWordPress Development
WordPress theme customisation, custom child themes, custom blocks and plugin configuration for sites of up to 15 pages that your team can edit.
Custom quoteView service →Cloud, DevOps & InfrastructureWebsite Migration
Website migration to new hosting covering files, databases, DNS and email, with a staging test and planned low-downtime cut-over for complex sites.
Custom quoteView service →