Defend WordPress against tampering and intrusion,
from assessment through to operations.

We run vulnerability scanning, WAF, login hardening, tamper detection, backups, and patch management continuously in an assess → harden → monitor cycle. We cover the ground that installing a free plugin alone can’t.

Pain points

Do any of these sound familiar?

Because WordPress is so widely used, it’s a frequent target. There are situations that installing a free plugin alone simply can’t handle.

Your site has been tampered with before, and you’re afraid it will happen again.
You have no WAF in place, or its settings are still at their defaults.
Plugin and theme updates have fallen behind, and you have no clear picture of your vulnerabilities.
Your admin URL is still the standard one, and you’re hit by brute-force attacks every day.
An audit, ISMS, or client requirement is asking you for WordPress security evidence.
You have free plugins installed, but you’ve never checked whether they’re actually working.
Reasons

An “assess → harden → monitor” cycle

Security isn’t something you finish in one shot. We include continuous patch management and monitoring as part of the work.

01

Assess

We inspect your current WordPress setup through vulnerability scanning, configuration audit, and a plugin inventory. We combine automated diagnostics from WPScan / Wordfence with a hands-on configuration review.

02

Harden

We implement WAF settings, login hardening, file integrity monitoring, admin protection, and HTTPS hardening. We also remove or replace vulnerable plugins and make themes safe.

03

Monitor

We run tamper detection on production, watch for unauthorized login attempts, and keep plugin updates current on a monthly basis. We build in the operations needed to keep things in their hardened state.

Scope

What we cover

We do only the parts your site needs, depending on its state and requirements.

01 Diagnose

Security assessment report

We inspect your current WordPress with WPScan and a configuration review, and document the vulnerabilities, misconfigurations, and operational risks. You can also choose to stop at the assessment.

  • Known-vulnerability detection with WPScan
  • Plugin & theme inventory
  • Admin & login protection review
  • WAF configuration check
  • SSL / TLS configuration review
  • PDF report delivered
02 Hardening

WordPress core & configuration hardening

We harden the WordPress core, PHP, and database settings to the extent compatible with day-to-day operations. We won’t lock things down so tightly you can no longer edit.

  • wp-config.php / .htaccess settings
  • Disable in-dashboard file editing
  • Block unnecessary REST API endpoints
  • Restrict XML-RPC
  • Hide version information
  • Force HTTPS & set HSTS
03 Login

Login & admin protection

We protect the admin dashboard and login, which are prime targets for brute-force attacks. We cover multi-factor authentication, IP restrictions, login-URL changes, and reCAPTCHA.

  • Custom admin URL
  • Multi-factor authentication (TOTP / WebAuthn)
  • IP address restrictions
  • Login attempt limits
  • reCAPTCHA / hCaptcha integration
  • Audit logging
04 WAF

WAF design & deployment

We select from Cloudflare WAF / AWS WAF / SiteGuard / WP-Cerber and more, to match your server setup. We include rule tuning and false-positive reduction so it holds up in real operation.

  • Cloudflare WAF design
  • AWS WAF design
  • SiteGuard / WP-Cerber configuration
  • Custom rule additions
  • False-positive reduction
  • Alert design for detected attacks
05 Detect

Tamper detection & audit logs

We continuously monitor file integrity on production and detect tampering when it occurs. We also record admin-dashboard activity logs to support internal controls and audits.

  • File integrity monitoring
  • Detection of injected malicious files
  • Admin-dashboard activity logs
  • Failed login-attempt logs
  • Change notifications (Slack / email)
  • Export for audits
06 Backup

Backup & recovery design

We put in place a structure that can recover even after tampering or intrusion. We get backups to a state where we’ve confirmed they can be restored, not merely that they’re being taken.

  • Daily backups (DB + files)
  • Off-site storage (S3 + separate region)
  • Version retention (30 days / 90 days)
  • Restore drills
  • RTO / RPO agreement
  • Recovery manual creation
07 Patch

Continuous patch management

We update the WordPress core, plugins, and themes on a planned monthly basis. Security patches go in immediately; feature updates are applied after verification.

  • WordPress core patches
  • Plugin updates (applied after verification)
  • Theme updates
  • Immediate response to emergency patches
  • Pre-checks in a staging environment
  • Monthly reports
08 Recover

Recovery support for intrusion & tampering

We also handle investigation and recovery for sites that have already been tampered with or breached. Root-cause identification, trace removal, and recurrence prevention come as a set.

  • Identify the intrusion path
  • Remove malware & backdoors
  • Restore to a clean state
  • Bulk password changes
  • Security hardening to prevent recurrence
  • Support drafting reports for stakeholders
Process

How we get to delivery

  • 01Free consultation — we ask for your site URL and current security measures (30 minutes).
  • 02Security assessment — we document the risks through WPScan, a configuration audit, and a plugin inventory.
  • 03Proposal & estimate — we lay out the priorities and timeline for the hardening menu in writing.
  • 04Hardening implementation — we do only the agreed scope, verifying on staging before applying to production.
  • 05Monitoring & operations — we keep tamper detection and patch management running monthly, and share a monthly report.
Plans

Engagement formats

Three formats depending on project size. Pricing is presented in writing after requirements are fixed.

Diagnose

Assessment only

  • WPScan + configuration audit
  • Risk-priority report
  • Option to stop at the assessment
  • PDF report delivered
Continuous

Ongoing security operations

  • Tamper detection & intrusion monitoring
  • Monthly patch management
  • Immediate response to emergency patches
  • Scope agreed individually in the contract
Comparison

Compared with the alternatives

Option A

Free plugins only

  • Installed, but never configured properly
  • Default settings leave protection limited
  • No WAF or tamper detection
  • Slow to keep up with emergency patches
Option B

A single security product

  • Only the product’s “by-the-book” measures
  • You still have to run it in-house
  • No WordPress-specific measures
  • Recovery support after a breach isn’t covered
SHANNON

Assess → harden → monitor

  • Addresses WordPress-specific risks
  • A hardening level compatible with operations
  • Tamper detection + monthly patch management
  • Recovery support after a breach as well
FAQ

Frequently asked questions

Yes. We handle it end to end — identifying the intrusion path, removing malware, restoring to a clean state, and hardening security to prevent recurrence. When urgency is high we start as fast as possible within business days (we don’t provide overnight or weekend on-call response).
Yes. We design around the permission, shared-theme, and plugin-management constraints specific to multisite. When there are many subsites, we discuss and agree on the target scope during the assessment as we proceed.
We deliver in a form you can use for that. We produce assessment reports, operations manuals, tamper-detection logs, patch-application records, and the like at a level of detail you can submit during an audit. If you have specific requirements, we align on them beforehand.
This package is WordPress-specific. For PowerCMS / Movable Type / Drupal and the like, we handle security hardening under the infrastructure build & operations service.
Broadly, no. Introducing multi-factor authentication or IP restrictions does affect editors, but we design it in a way compatible with their day-to-day work. At rollout we also provide operational guidance for editors.
We verify all functionality on a staging environment before applying to production. When we go to production, we take a backup first and apply changes in stages. We also prepare rollback steps in advance in case anything goes wrong.
Request a security assessment
Contact

Let’s talk — the first consultation is free.

Even if your requirements aren’t fixed yet, that’s fine. We reply within 2 business days.

You can also reach us by phone (050-1794-9651, automated voice; we call back on business days). For detailed enquiries with budget and timing, please use the contact form. Note: we do not accept sales solicitations.