01 WordPress security

We secure WordPress sites and clean up hacked ones.

Two doors. Not hacked yet: a $399 fixed audit and hardening pass that closes the ways WordPress sites actually get broken into. Already seeing spam pages or a Google warning: cleanup from $499, triaged free before you pay a cent.

Hacked right now? Spam pages, redirects, or a red Google warning: skip the reading. Send your URL, we confirm the infection free and jump you to the front of the queue.

02 Free 10-point scan

Start with the free scan.

Free 10-point WordPress security scan

We check the ten externally visible signals (versions, exposed endpoints, headers, login surface, known-bad markers) and write you what we found within 24 hours. If something is urgent, we say so plainly.

Free · external checks only, no access needed · reply within 24h on working days

03 The offers

The two offers.

Preventive · fixed price

Security Audit & Hardening

$399

fixed · one site · about a week

  • Core, theme and plugin versions checked against known CVEs
  • User accounts, roles and password policy reviewed
  • Login hardening: brute-force limits, 2FA, XML-RPC closed if unused
  • File permissions, wp-config and salts fixed
  • Off-site backup verified or set up
  • A firewall / WAF configured where your host allows it
  • Written report of what we found and what we changed
Book the hardening

Costs less than one hour of incident response. That is the point.

Emergency · scope-priced

Malware Cleanup

from $499

free triage first · 30-day reinfection cover

  • Free triage first: we confirm infection and scope before you pay
  • Malware located and removed, backdoors included
  • Compromised admin accounts and rogue users cleaned out
  • Google "this site may be hacked" / blocklist review requested
  • Entry point identified and closed, not just symptoms wiped
  • 30 days of reinfection cover: it comes back, we clean it again free
Start with free triage

We confirm the infection and quote before you pay. No fear pricing.

04 Who you're paying

Our WordPress code is public.

Our WooCommerce and WordPress plugins are maintained in the open on github.com/EtherLabZ, and our security work extends to modern stacks too: the €299 vibe-coded app audit reviews auth, payments and secrets for AI-built apps. Founders do the work, a verified 5.0 Clutch review backs the way we communicate, and every engagement ends with a written record of exactly what changed.

05 FAQ

Fine print.

Audit and hardening, or cleanup: which one am I?

Not hacked yet: the $399 audit and hardening, which exists so you never need the other one. Seeing spam pages, redirects, a defaced homepage, or a warning in Google: that is a cleanup. Not sure? Send the URL through the free scan and we tell you which you need, or that you need neither.

Why is the cleanup "from $499" instead of fixed?

Because infections vary wildly. A single-site cleanup with one backdoor is the base price. A multisite with a year-old infection, SEO spam in the database, and a blocklisted domain is more, and we quote it after the free triage, before you pay anything. E-commerce incident response elsewhere routinely starts at $1,800; we quote what yours actually needs, nothing more.

What does the 30-day reinfection cover mean?

If the same site gets reinfected within 30 days of our cleanup, we clean it again at no charge. Reinfection usually means an entry point was missed; closing entry points is part of the job, so a comeback is on us, not you.

What access do you need?

An administrator wp-admin account plus hosting access (panel or SFTP). For cleanups, hosting access is not optional: malware lives in files and the database, not the dashboard. Everything we change is listed in the handover.

Do you sell an ongoing security service?

The Care Plans (from $99/mo) include security monitoring, updates tested on staging, and daily backups, which is most of what keeps a site from being hacked again. The audit is the natural first step; the plan keeps it that way. No bundling tricks: each stands alone.

Is this a penetration test or compliance certification?

No. It is a practical WordPress hardening pass against the ways WordPress sites actually get broken into: outdated components, weak logins, loose permissions, missing backups. No SOC 2, ISO 27001 or PCI paperwork comes out of it, and we say so up front.

Run the scan first.

Ten external checks, one useful email, zero commitment. Then decide between $399 of prevention and $0 of luck.

Scan my site free