onezlabs

0%

WordPress Security Hardening

Lock Down Your WordPress Site Before Attackers Find the Door

WordPress security hardening and malware prevention by a developer with 6+ years WordPress experience. I implement login protection, file integrity monitoring, WAF rules, and backups — proactive security, not just cleanup.

2FA SetupWAF ConfigurationFile Permission HardeningPlugin AuditLogin Protection
The Problem

A Default WordPress Installation Is Configured for Convenience, Not Security

Out of the box, WordPress uses predictable paths like wp-login.php and /wp-admin/, default database table prefixes, and no rate limiting on login attempts. It allows file editing from within the dashboard. Plugins can be installed without review. These defaults make WordPress easy to set up — and easy for attackers to exploit at scale.

Automated scanners probe millions of WordPress sites every day looking for known plugin vulnerabilities, xmlrpc.php exploits, default admin usernames, and weak credentials. Brute force bots run tens of thousands of login attempts per hour against unprotected sites. Hardening closes the doors that default configuration leaves wide open.

The most dangerous vulnerabilities often come from plugins that are installed but no longer actively maintained. A single outdated plugin with a known CVE is all an automated scanner needs. Plugin auditing and timely updates are not optional — they are the front line of WordPress defense.

The Solution

Systematic WordPress Hardening Across Every Attack Vector

Based in Davao City, Philippines, I implement a complete WordPress security hardening engagement — covering the file system, database, login layer, plugin ecosystem, and network perimeter. Each hardening measure is documented, verified, and explained so you understand what changed and why.

  • File and directory permissions set to block unauthorized writes
  • Two-factor authentication enforced for all admin accounts with brute force lockout
  • Plugin and theme audit against known CVE databases — outdated and vulnerable plugins removed
  • WAF rules blocking SQL injection, XSS, and WordPress-specific attack patterns
  • xmlrpc.php locked down, admin URL changed, file editing disabled from dashboard
Services

WordPress Security Hardening by Attack Surface Each item targets a specific attack vector that attackers actively exploit against WordPress sites.

01

Security Hardening Checklist

A 30-point security checklist applied to your WordPress installation — covering core configuration, file permissions, login settings, plugin status, SSL validity, exposed files, and server headers. Each item verified and documented.

30-Point ChecklistCore ConfigDocumented Audit
02

Login Protection

Login attempt rate limiting configured to block brute force attacks. Admin username changed from the default. wp-login.php access restricted by IP or CAPTCHA. Login page URL optionally moved to a non-standard path.

Rate LimitingCAPTCHAAdmin URL Change
03

File Permission Hardening

File and directory permissions set to WordPress security standards: 755 for directories, 644 for files, 400 for wp-config.php and .htaccess. PHP execution blocked in the uploads directory to prevent uploaded malware from running.

File PermissionsPHP Block in Uploads.htaccess Rules
04

Database Security

WordPress database table prefix changed from the default wp_ to a randomized string. Database user privileges reviewed and trimmed to the minimum required. wp-config.php secured with restricted file permissions and moved above webroot where possible.

Table Prefix ChangeDB User Privilegeswp-config.php Security
05

Plugin Audit

Every installed plugin and theme checked against the WPScan vulnerability database and WordPress.org repository. Plugins with known unpatched CVEs flagged for immediate removal or replacement. Abandoned plugins assessed and removed or substituted.

CVE CheckPlugin UpdatesAbandoned Plugin Removal
06

Two-Factor Authentication

TOTP two-factor authentication configured for all administrator and editor accounts using Google Authenticator or Authy. Backup codes generated. 2FA enforced at the user level so it cannot be disabled without admin credentials.

TOTP 2FAGoogle AuthenticatorEnforced Per User
Pricing

WordPress Security Packages Choose one-time hardening, ongoing monitoring, or emergency response — all at fixed, transparent rates.

One-Time Hardening$300

One-time project

Ideal for: Sites that need a complete security baseline set up once, with no ongoing subscription.

  • Full 30-point security audit
  • Core WordPress hardening
  • Login protection and rate limiting
  • Two-factor authentication setup
  • File permission lockdown
  • Plugin and theme vulnerability audit
  • Documented hardening report
Harden My Site
Most Popular
Monthly Monitoring$150

per month

Ideal for: Sites that want continuous protection, monthly plugin updates, and incident response included.

  • Everything in One-Time Hardening
  • Daily automated malware scans
  • File integrity monitoring with alerts
  • Monthly plugin and theme update management
  • Blacklist status monitoring
  • Uptime monitoring with instant alerts
  • Priority incident response (within 24 hours)
  • Monthly security health report
Start Monthly Monitoring
Emergency Response$400

One-time

Ideal for: Sites that have been compromised and need immediate investigation, cleanup, and hardening.

  • Priority response within 2 to 4 hours
  • Full malware and backdoor removal
  • Database injection cleanup
  • Root cause identification
  • Post-cleanup WordPress hardening
  • Google and Sucuri blacklist removal request
  • 30-day post-cleanup monitoring
Request Emergency Response
How It Works

WordPress Hardening — Step by Step

01
01

Security Audit

Full scan of your WordPress installation: plugin versions checked against the CVE database, file permissions reviewed, user accounts audited, login configuration assessed, SSL status verified, and server response headers analyzed.

02
02

Plugin Cleanup

Vulnerable, outdated, and abandoned plugins identified. Alternatives recommended for any that must be removed. All remaining plugins updated to their latest secure versions before hardening proceeds.

03
03

Core and File Hardening

File permissions corrected, wp-config.php secured, file editing disabled from the admin dashboard, directory browsing blocked, PHP execution blocked in the uploads folder, and xmlrpc.php restricted to only the methods your site genuinely needs.

04
04

Login and Access Control

Two-factor authentication configured and enforced for all admin users. Login attempt limits applied. Admin username reviewed and changed if set to the default. Admin URL optionally relocated to a non-standard path.

05
05

WAF and Documentation

Web Application Firewall rules configured and verified. All changes documented in a full hardening report — what was changed, why it was changed, and what attack it prevents. You own this document regardless of future engagement.

Why This Works

Hardening That Goes Beyond Installing a Security Plugin Real WordPress security requires configuration changes at every layer — not just activating a plugin and hoping for the best.

Every Attack Surface Addressed

File system, database, login, plugin ecosystem, and network perimeter — not just the application layer that security plugins cover. Attackers probe every layer; hardening must match.

Two-Factor Authentication That Gets Used

Configuring 2FA that admins can disable because it feels inconvenient is worthless. I enforce TOTP 2FA at the user level with backup codes — admins cannot bypass it without proper credentials.

Plugin Audit With Real CVE Data

Every plugin is checked against the WPScan vulnerability database. Outdated plugins with known unpatched vulnerabilities are the leading cause of WordPress compromises — this step is non-negotiable.

PHP Execution Blocked in Uploads

Attackers who cannot exploit a vulnerability often try uploading a PHP file through a form or media uploader. Blocking PHP execution in the uploads directory eliminates this attack vector entirely.

xmlrpc.php Attack Prevention

The xmlrpc.php endpoint is a well-known target for credential stuffing and DDoS amplification attacks. I restrict it to only the methods your site actually requires — or disable it entirely if your site does not need it.

Documented, Not Just Done

Every hardening change is written up — what was changed, how to reverse it if needed, and what attack it prevents. When a future developer touches the site, they understand the security configuration.

Client Results

WordPress Sites Secured Before and After Attack

"My website was receiving hundreds of failed login attempts every day. I could see it in the logs but did not know what to do. Johnbert set up login rate limiting, two-factor authentication, changed the admin URL, and configured Cloudflare rate limiting. The brute force attempts still happen but nothing gets through. Peace of mind I did not have before."

Paul D.Consultancy Owner, United States

"After a previous hack, I wanted proper protection before rebuilding. Johnbert found four plugins with known vulnerabilities, fixed file permissions that had been set incorrectly during my original setup, and configured Wordfence properly. I have not had an incident since."

Tina L.WooCommerce Store Owner, Australia

"I manage WordPress sites for eight clients and needed a consistent security baseline across all of them. Johnbert documented a hardening checklist for our agency and implemented it across every site. He also set up centralized monitoring so I receive one report covering all eight. Very thorough, very clear documentation."

Ahmad H.Digital Agency Owner, Malaysia
FAQ

WordPress Security Hardening — Frequently Asked Questions

JO

Johnbert Oñez

AI Solutions Engineer & Full Stack Developer · 6+ yrs · 50+ projects

Based in Davao City, Philippines. Specialises in production AI systems, full-stack web applications, and WordPress. Remote-first, async-friendly, fixed-fee projects.

About me →
Let's work together

Got a project in mind?
Let's build it.

AI systems, SaaS platforms, WordPress solutions — whatever the scope, I bring craftsmanship and precision from day one.

50+Projects shipped
<24hResponse time
6+Years experience