Skip to content
Services/Website security

Website securitybefore something goes wrong.

Hardening, regular scanning and a quick cleanup if something gets through. Most of it runs quietly in the background.

What's included

Security work you shouldn't have to think about, until the day it matters.

  • Malware scanning

    Regular scans for injected code, changed files and plugins with known holes.

  • Hardening

    Security headers, login protection, file permissions and WordPress settings tightened from day one.

  • Two-factor sign-in

    A second step on every admin account. It stops most password attacks.

  • Cleanup

    If a site is hacked, we restore a clean backup, find how they got in, and close it.

  • Security audit

    A full review of your site, with fixes ranked by real risk.

  • Alerts

    If monitoring spots something wrong, you hear it from us first.

Most visitors to your login page aren't people

Automated scripts try every WordPress site they can find, looking for one old plugin or one weak password. The firewall turns them away before they reach your site. Real visitors pass straight through.

  • Visitors
  • Automated attacks

A drawing, not live data.

What a cleanup really costs

The bill for cleaning up a hacked site depends on what got in and how long it was there. The larger costs are often the ones that don't show up on an invoice: downtime, lost search rankings, and the time spent explaining it to your board or your customers.

On a care plan, cleanup is included.

See care plans

Security isn't set and forget

Most hacked WordPress sites are running an old plugin with a publicly known hole. The next most common cause is a weak or reused password. Both can be prevented, and we deal with both on day one.

A hacked site can go unnoticed for weeks while it sends visitors elsewhere and loses its place in Google. Cleaning it up almost always costs more than preventing it would have.

On a care plan, security monitoring and cleanup are part of the plan, not an extra.

Start a project

What hardening involves

  • Firewall set up and tuned
  • Limits on login attempts
  • Two-factor sign-in for every admin
  • Security headers
  • File permissions checked and fixed
  • WordPress configuration tightened
  • XML-RPC turned off where it isn't needed
  • REST API access reviewed
  • SSL settings checked
  • Malware removal and cleanup

How security work runs

We find out what's actually exposed before we change anything.

  1. 01

    Audit

    Plugins, users, permissions, headers and files, all reviewed.

  2. 02

    Harden

    Fixes applied most important first, tested on staging before the live site.

  3. 03

    Monitor

    Scanning, uptime checks and alerts set up and confirmed working.

  4. 04

    Keep up

    Monthly review on a care plan, or scheduled check-ins.

Questions people ask

My site was hacked. What do I do right now?

Call us at 502-233-1110. We'll put the site in maintenance mode, take a snapshot of what's there, and start the cleanup. The sooner we start, the less there is to undo.

How do I know if my site has been hacked?

Common signs: Google warns visitors about the site, traffic suddenly drops, strange links appear in your pages, or visitors get sent somewhere else. If you're not sure, an audit will tell you.

Is security included in care plans?

Yes. Scanning, monitoring and cleanup are included in every care plan.

Will hardening break my site?

Not when it's done carefully. Every change is tested on staging before it reaches the live site.

Our site is small. Do we still need this?

Most attacks aren't aimed at anyone in particular. They're automated, and they try every site running a plugin with a known hole. Small sites are hacked all the time.

Work order

Let's check your site.

Tick what fits, add a line about it, and send it over.

What do you need?
or call 502-233-1110