Secure WordPress
Most successful attacks do not use sophisticated methods, but simply an outdated component or a password that was compromised elsewhere.
Hardening addresses exactly that and costs significantly less than cleanup.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
Where things fail in practice
I find these four points in virtually every installation I open for the first time.
Updates are postponed
Security vulnerabilities become public with the update. From that moment on, they are searched for automatically. Anyone who waits two weeks is a known target for two weeks.
Unused plugins remain
A deactivated plugin is still on the server and, in many cases, still accessible. Anything that is not needed should be deleted.
Access credentials are stored in the FTP program
Saved passwords in FTP clients are a preferred target for malware on work computers. More attacks originate there than is generally assumed.
No two-factor authentication
A second factor for administrator accounts makes compromised passwords practically worthless. Setup takes a few minutes per account.
What hardening includes
Initial assessment
Versions, user accounts, permissions, file permissions, and server configuration are recorded. This shows where the installation is actually vulnerable.
Reduce the attack surface
Unused plugins and themes are removed, file editing in the backend is disabled, and interfaces you do not need are closed.
Secure access
New passwords, two-factor authentication for administrators, and a clean separation of roles. Editors do not need administrator rights.
Set up monitoring
Checksums, notifications of new administrator accounts, and a regular comparison with newly reported vulnerabilities.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
Frequently asked questions
Isn’t a security plugin enough?
It is one component, and I use it too. But it replaces neither up-to-date software nor secure access credentials. A plugin that monitors an outdated component does not prevent the attack; at most, it reports it.
What does hardening cost?
As a one-time measure, I charge based on the work involved and provide a range after the initial assessment. It is included in ongoing support from €65 per month.
Will this make my site slower?
No. The effective measures concern software versions, access credentials, and configuration. This does not affect loading time; in individual cases, it even has a positive effect because unnecessary components are removed.
Prevention costs a fraction of cleanup
A call costs you nothing and takes five minutes. If it turns out to be a different problem, I will tell you that too.
Available Monday to Friday from 8 to 20 · Related topics: WordPress maintenance · WordPress hacked – what to do now · Unknown administrators in WordPress · Remove WordPress malware
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.