WordPress Security Audit & Hardening.
For site owners, store owners, and agencies who've been hacked, are at risk, or need serious security โ not a plugin, a real expert.
One-Time Packages
Pick based on what you need โ audit only, full fix, emergency cleanup, or team training. All include a 7-day warranty.
Security Audit Only
Best for: Know exactly what's wrong before committing to fixes
Audit + Hardening
Best for: Findings fixed, not just reported
Multi-Site Audit + Hardening
Best for: Agencies or owners with multiple WP sites โ especially on shared hosting
Post-Hack Emergency Cleanup
Best for: Sites actively hacked โ spam links, virus injected, admin access lost
Quoted after initial assessment. Price depends on infection depth, number of files, and sites affected.
Security Playbook + Team Training
Best for: Teams who want to be self-sufficient โ not dependent on external help
Add-Ons
Extend any package with these optional extras.
Monthly Security Maintenance
Ongoing protection โ scans, updates, monitoring, and support on a monthly retainer.
Security Basic
Extra: $70/hour beyond included
- โWeekly automated malware + file integrity scan
- โWeekly backup to S3 or Google Drive
- โPlugin + core update management (tested before applying)
- โEmail blacklist monitoring
- โResponse within 48 business hours
Security Standard
Extra: $65/hour beyond included
- โEverything in Security Basic, plus:
- โWeekly manual review of scan results + Cloudflare/WAF logs
- โAdmin user & access audit (monthly)
- โResponse within 24 business hours
Security Priority
Extra: $60/hour beyond included
- โEverything in Security Standard, plus:
- โEmergency incident response included (hack, malware, defacement)
- โWeekly deep review: file changes, login attempts, plugin changes
- โMonthly security summary report
What's Not Included
Full transparency on scope boundaries.
- โHosting or VPS cost (client's own)
- โDomain cost (client's own)
- โPaid plugin or theme licenses
- โCloudflare paid plan (free tier sufficient for most setups)
- โFull website development or redesign
- โFixes caused by third-party plugin bugs (flagged in audit, quoted separately)
- โLegal or compliance advisory (GDPR, PCI, etc.)
๐ Security & Scope Control
All work is performed on client-granted access only. No changes are made outside the agreed scope. A full log of every change is documented and handed over. Client retains full control at all times.
๐ก๏ธ 7-Day Warranty
All audit and hardening packages include a 7-day warranty. If a reinfection or issue occurs within 7 days due to a vector that was in scope, it is addressed at no extra charge.
Not sure which package fits?
Book a call โ describe what's happening and we'll recommend the right starting point.
