WordPress Security (Retainer)
An audit tells you where your WordPress stood that week. Plugins update, themes go stale and new CVEs land constantly — this is the cover for everything that changes after.
WordPress powers a large share of the web, and the overwhelming majority of its compromises come through plugins and themes rather than core.
That matters for how you defend it. Core updates itself reasonably well. The risk sits in the twenty or thirty third-party components layered on top — written by different people, maintained to different standards, and occasionally abandoned entirely without announcement. A plugin that was perfectly safe when you installed it can become the way in eighteen months later, without you changing anything.
That is not a problem an audit solves once. It is a problem of attention over time, which is what this retainer sells. Each month we check what changed, judge whether it matters for your site specifically, and act on the things that do.
What's included
Plugin and core vulnerability tracking — your installed components watched against newly published advisories, not a generic feed.
Abandonment monitoring — we flag components that have stopped receiving updates, before they become the weak point.
Configuration drift checks — file permissions, user roles and login protection re-verified, because settings loosen over time.
Hardening as it's needed — the add-on from the audit, folded in and applied when a finding warrants it.
A named contact — someone who already knows your setup when something looks wrong, rather than a ticket queue.
Why the plugin count is the real number
When we scope this, the first thing we ask for is your plugin list. A site running eight well-maintained plugins is a fundamentally different risk to one running thirty-five, several of which nobody remembers installing. The second is far more common, and reducing that number is usually the single highest-value thing we recommend — often before you spend anything else with us.
Attention, applied on a schedule
Inventory
Core, theme and plugin versions re-catalogued, so the list we're defending is the list you actually run today.
Cross-check
Your components matched against newly published advisories — and against whether anyone is still maintaining them.
Judge
Not every CVE applies. An operator decides what is genuinely exploitable in your configuration and what is noise.
Act
Hardening applied where warranted, with a short written record of what changed and why.
We secure the site — we don't run it
This is not WordPress hosting, maintenance or development. We are not your uptime provider, we don't fix your contact form, and we won't be responsible if a theme update breaks your layout. Plenty of firms bundle all of that together and call the whole thing security. We would rather be clear about which part we're accountable for.
It is also not malware cleanup after the fact. If your site is already compromised, that is remediation work and needs scoping separately — tell us and we'll say so honestly rather than quietly starting a retainer.
Send us your WP environment details
We'll tell you what's exposed, what's abandoned, and whether you need a retainer or just a good clear-out.
