WordPress security · maintenance

WordPress security, on a schedule.

Sites are not broken into through the front door. They are broken into through a plugin nobody updated. Patching, backups and monitoring are inside the monthly, and when something does happen there is a procedure rather than a panic.

The problem

The patch is not the problem.

Fixes ship constantly. What decides whether you get hit is whether anybody applies them, and on most SME sites nobody does — because nobody was ever given the job.

What 2026 has looked like
Plugin flaws disclosed
Around thirty-six a day, and almost half need no login to use.
Still unpatched a month later
One in four.
The worst day so far
Over seventeen thousand attack attempts in twenty-four hours.
The repository itself
Twenty-five plugins compromised in seventy-two hours in April.
What gets done

Every month, whether or not anything happened.

Security is not a product you buy once. It is a short list of things somebody has to do again and again, and the only question that matters is whether that somebody exists.

Updates applied and checked, so a fix never breaks the page it was meant to protect
Plugins you stopped using removed instead of left sitting there
The site watched, so you are not the one who notices
All of it inside the monthly you already pay
The routine
04
A report you can read, in plain language
03
Backups taken off the server, because a backup on it disappears with it
02
Logins limited, file editing off, uploads unable to run code
01
Core, plugins and themes reviewed and updated, not left on auto and forgotten
If it already happened

There is an order to it.

A hacked site is not fixed by deleting the file you can see. It is fixed by finding the way in, and that only works if nobody cleans up first.

How a cleanup runs
Isolate
The site goes dark before anything else. Every minute serving spam is a mark on you.
Freeze the evidence
Files and database copied off the server before a single thing is cleaned.
Find the door
Logs, file dates, unknown admins, scheduled tasks, forgotten backup scripts.
Replace, not disinfect
Core, plugins and themes come back from clean copies.
Rotate everything
Keys, every admin password, the database user, the server logins.
Then lift the flag
The review request to Google, once it is genuinely clean.
Straight answer

What I will not tell you.

That you will never be hacked. Nobody can say that and mean it, and the ones who do are selling you a plugin.

Where the line is
What is promised
A routine that runs, and a procedure when it does not hold.
What is not
That it cannot happen. It can, to anyone.
Before I take an incident
Real access first: server, panel and an off-server backup.
If I cannot fix it
I say so and tell you who can, rather than billing you to find out.
What it costs

In the monthly. Or on its own.

If your site is on a plan, all of the above is already in it and there is nothing to add. If it is not, the two pieces stand alone.

The three ways in
On a website plan
included, nothing extra
Security audit, one-off
$390
Cleanup after an incident
from $690, fixed after a look
What an agency charges to clean up
$500-$3,000
On the plan
included
What clients say

Sites that stay up.

“Our old website was years behind the business. Daniel rebuilt it from scratch and now runs our SEO — one point of contact, and things move without chasing.”

Yoon Phey · AZEO, Malaysia

“Daniel set up our store and SEO completely. Within 3 months we were selling consistently online — he handles everything.”

Jose León · Distribuciones León
Before you ask

What people ask first.

No, unmaintained WordPress is. The software is patched constantly and well. What gets sites broken into is a plugin that stopped being updated two years ago, and that is a maintenance problem wearing a security costume.

We look before we touch anything. The site goes into maintenance, a full copy comes off the server, and only then does the cleaning start, because once you clean you can no longer find out how they got in. Price is fixed after that first look, which is how this work is quoted everywhere.

Server access, the hosting panel and somewhere the backups live that is not the server. Plugins cannot rescue a site that will not start, so a WordPress login on its own is not enough. If those are missing, getting them is the first job rather than the second.

No, and be careful with anyone who does. What is promised is that the routine runs, that the way in gets found and closed, and that you get told what happened in words you can use.

One, configured, not four fighting each other. A stack of overlapping security plugins slows the site down and gives you four dashboards nobody reads. The work is in the routine, not in the logo on the plugin.

Yes, all of it. Updates, backups, hardening and monitoring are what the monthly is for. The audit and the cleanup exist for sites that are not on a plan.

Also on this site

Around the security work.

Hardening is one job. Keeping it that way is another.

Pages
How maintenance and security divide up.
The monthly routine, and what it covers.
A hacked site usually shows up in search first.
The other half of looking after a site.
From the blog
The five things worth doing on any site.
Start here

Tell me where the site lives.

One call. If it is already on a plan there is nothing to buy, and if something is wrong right now, say that first and we start there.

Chat with us