WordPress fixes & one-time work
WordPress Security Hardening
Close the common doors before someone walks through them: access audit, firewall, 2FA, offsite backups and a 30+ point hardening pass.
Basics
-
Audit of accounts, roles and accesses — the doors nobody remembers opening
-
WAF / firewall plugin configured
-
Two-factor authentication for admin accounts
-
Automatic backups with an offsite copy — tested, not just scheduled
-
30+ point hardening checklist: PHP, headers, file permissions, xmlrpc, salts
Plans
Pricing
Start
How it works
-
The order becomes a service you can watch
The paid order becomes a service in your panel with a status of its own, and every change to it is recorded on the service page. From that page you write to us whenever you need to — one conversation per service, not one per order, so there is no second chat to check.
-
You hand over access, not passwords by email
The short intake form asked what the work needs while you were ordering, and its answers travel with the service. Credentials go into the panel's encrypted storage, never into an email thread, and the form itself never asks for one.
-
Small requests start; larger ones wait for your word
Every request is estimated first, free. Estimated at two hours or less, it starts right away with a notification to you; above that it waits for you to approve the deduction. You can lower that threshold to zero and approve everything.
-
Every hour is a line, and nothing renews by itself
Work is logged in quarter-hour steps, each entry tied to the request that caused it, with the remaining balance visible as a number. A subscription renews only under a payment mandate you granted — and can revoke — in the panel.
Illustration of the client panel — not a real account. Every deduction is a line, the balance is a number.
Included
What's included
Access and role audit
Every account and its role reviewed: stale admins removed, over-broad roles trimmed, password policy tightened. Most compromises start with an account everyone forgot.
Firewall and 2FA
A web application firewall configured for your site, and two-factor authentication enforced for administrator accounts.
Backups that actually restore
Automatic backups configured with an offsite copy — because a backup living next to the site dies with the site.
30+ point hardening checklist
PHP settings, security headers, file permissions, xmlrpc, database prefix, salt keys and the rest of the checklist — applied and documented item by item.
Written report
What was found, what was changed, what remains your responsibility (passwords, hosting account hygiene) — in your panel.
Not included
Cleaning an active infection — that is the Emergency Fix service, and mixing the two would shortchange both. Server-level work beyond a shared/managed hosting panel is quoted separately.
Promise
Our guarantees
-
No deposits to negotiate, no invoice to chase
Paying in the panel puts the work in our queue and opens its page for you; access collection follows immediately through the encrypted vault. We print no delivery window for this service — our order book does not commit one, and we would rather print nothing than invent a date.
-
Change your mind before we start — 100% back
A one-time order refunded in full on request any time before work begins, per our refund policy.
Questions
Frequently asked questions
My site is already hacked — is this what I need?
No — hardening is prevention, and prevention on an infected site is painting over mold. Order the Emergency Fix first; it cleans the site and closes the attack vector. Hardening afterwards makes the next attack much harder.
Does hardening guarantee I won't be hacked?
No honest provider guarantees that, and we will not either. What hardening does is close the common doors — outdated access, missing 2FA, weak file permissions, exposed endpoints — that account for the great majority of small-site compromises, and leave you a documented baseline plus tested backups if the worst happens anyway.
Will security plugins slow down my site?
Configured carelessly, they can. Part of the checklist is configuring the firewall and scanners so protection does not cost you your loading speed — and the report records what was set and why.
What do you need from me?
WordPress admin and hosting access through the platform's encrypted vault, and the intake questionnaire. If some hardening items need decisions from you — for example retiring a shared login your team uses — we ask, we do not silently break your workflow.
Is this a one-time thing or do I need it monthly?
The setup is one-time. Staying secure over time is mostly about updates and watching — which is what the Website Care plans and Site Monitoring are for. Hardening gives them a clean baseline to maintain.
What stays my responsibility afterwards?
The report says it explicitly: your passwords and where you store them, who you grant access to, and your hosting account's own security. We harden the site; we cannot harden habits — but we do write down which ones matter.
Extras
Related services
Emergency WordPress Fix
AED 1,890one-timeReanimation for a down or hacked site: diagnosis, malware removal or restore from backup, closing the attack vector, basic hardening and an incident report — under a no-cure-no-pay guarantee.
See plans & pricing WordPress fixes & one-time workLanding Page Setup
AED 3,665one-timeA landing page built on an agreed template: design customized to your brand, up to 7 content sections, a lead form with email notifications, GA4 basics, SEO meta and launch on your hosting — with 2 revision rounds included.
See plans & pricing WordPress fixes & one-time workWordPress Site Migration
AED 1,120one-timeA complete migration of your site to new hosting: files and database transferred, everything verified against a checklist (forms, SSL, mail, redirects), DNS switched with minimal downtime, and 7 days of post-move support.
See plans & pricingOrder
Order WordPress Security Hardening
In the panel this service is listed as “WordPress Security Hardening”.