Website securitybefore something goes wrong.
Hardening, regular scanning and a quick cleanup if something gets through. Most of it runs quietly in the background.
What's included
Security work you shouldn't have to think about, until the day it matters.
Malware scanning
Regular scans for injected code, changed files and plugins with known holes.
Hardening
Security headers, login protection, file permissions and WordPress settings tightened from day one.
Two-factor sign-in
A second step on every admin account. It stops most password attacks.
Cleanup
If a site is hacked, we restore a clean backup, find how they got in, and close it.
Security audit
A full review of your site, with fixes ranked by real risk.
Alerts
If monitoring spots something wrong, you hear it from us first.
Most visitors to your login page aren't people
Automated scripts try every WordPress site they can find, looking for one old plugin or one weak password. The firewall turns them away before they reach your site. Real visitors pass straight through.
- Visitors
- Automated attacks
A drawing, not live data.
What a cleanup really costs
The bill for cleaning up a hacked site depends on what got in and how long it was there. The larger costs are often the ones that don't show up on an invoice: downtime, lost search rankings, and the time spent explaining it to your board or your customers.
On a care plan, cleanup is included.
See care plans →Security isn't set and forget
Most hacked WordPress sites are running an old plugin with a publicly known hole. The next most common cause is a weak or reused password. Both can be prevented, and we deal with both on day one.
A hacked site can go unnoticed for weeks while it sends visitors elsewhere and loses its place in Google. Cleaning it up almost always costs more than preventing it would have.
On a care plan, security monitoring and cleanup are part of the plan, not an extra.
Start a project →What hardening involves
- Firewall set up and tuned
- Limits on login attempts
- Two-factor sign-in for every admin
- Security headers
- File permissions checked and fixed
- WordPress configuration tightened
- XML-RPC turned off where it isn't needed
- REST API access reviewed
- SSL settings checked
- Malware removal and cleanup
How security work runs
We find out what's actually exposed before we change anything.
- 01
Audit
Plugins, users, permissions, headers and files, all reviewed.
- 02
Harden
Fixes applied most important first, tested on staging before the live site.
- 03
Monitor
Scanning, uptime checks and alerts set up and confirmed working.
- 04
Keep up
Monthly review on a care plan, or scheduled check-ins.
Questions people ask
My site was hacked. What do I do right now?
Call us at 502-233-1110. We'll put the site in maintenance mode, take a snapshot of what's there, and start the cleanup. The sooner we start, the less there is to undo.
How do I know if my site has been hacked?
Common signs: Google warns visitors about the site, traffic suddenly drops, strange links appear in your pages, or visitors get sent somewhere else. If you're not sure, an audit will tell you.
Is security included in care plans?
Yes. Scanning, monitoring and cleanup are included in every care plan.
Will hardening break my site?
Not when it's done carefully. Every change is tested on staging before it reaches the live site.
Our site is small. Do we still need this?
Most attacks aren't aimed at anyone in particular. They're automated, and they try every site running a plugin with a known hole. Small sites are hacked all the time.