Technology Security

Secure the platform that runs a third of the web.

Most WordPress sites are not broken into through WordPress itself. They are broken into through a plugin nobody updated, a backup left in the web root, or an admin account with a password from 2019. We look where the breaches actually happen.

Role /orders /admin /export Guest Customer Staff Admin Staff can reach /export — privilege escalation
PluginsVersion & vuln checks
ThemesExposure & config
CoreEnd-of-life tracking
VerifiedEvery finding

Why WordPress needs its own assessment

WordPress is the most attacked platform on the internet for a simple reason: it is the most used, and most of its risk lives in third-party plugins and themes that the site owner never wrote and rarely updates. A generic scan sees a web server; it does not know that the contact-form plugin is three versions behind a known-exploited flaw.

We assess the whole platform the way an attacker enumerates it — the core version and whether it is still supported, every plugin and theme and the exact versions they run, the files that should never be reachable, and the accounts that can change everything. Each finding is checked by a person before it reaches you, so the report is what to fix, not a plugin inventory.

Coverage

What we check on a WordPress estate

The classes of issue that actually lead to compromised WordPress sites.

Vulnerable plugins and themes

Every installed plugin and theme identified by real version, matched against known vulnerabilities and exploit probability — the single largest source of WordPress compromise.

Exposed configuration and backups

wp-config backups, database dumps, debug logs and archive files left readable in the web root, each of which can hand over the whole site.

User and author enumeration

The endpoints that leak valid usernames and feed the credential-stuffing that follows.

Weak or unprotected administration

Login exposure, missing rate limiting, and administrative interfaces reachable by anyone.

XML-RPC and API abuse surface

Legacy interfaces that enable brute-force amplification and unintended data access when left enabled.

Out-of-date or end-of-life core and PHP

Unsupported versions that no longer receive security fixes, tracked against real support calendars.

Directory listing and information disclosure

Uploads and content directories that expose files never meant to be browsed.

Approach

How a WordPress assessment runs

Passive fingerprinting first, active testing only within the agreed scope.

  1. 01 · Fingerprint the estate

    Core, plugins, themes and versions identified from the live site without touching data.

  2. 02 · Correlate and test

    Detected versions matched to known flaws and exposure checks run against the agreed scope.

  3. 03 · Verify

    Every candidate confirmed by a person — no plugin-inventory noise reported as findings.

  4. 04 · Report and harden

    Prioritised fixes plus a hardening baseline your team or ours can apply.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Prioritised finding report

Ranked by exploit probability and impact, each with the exact plugin, theme or setting to change.

Plugin and theme risk register

Every component, its version, and its known-vulnerability status.

Hardening baseline

The configuration changes that close the common WordPress attack paths for good.

Re-test on fix

Confirmation that what you changed actually resolved the finding.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

WordPress Security — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Do you test the plugins as well as WordPress core?

Yes — and that is where most of the risk is. We identify every plugin and theme by its real version and match it against known vulnerabilities, because a fully patched core running a vulnerable plugin is still a vulnerable site.

Will the test take my site down?

No. Fingerprinting is passive, and any active checks are rate-limited and run only within the scope you agree in writing. We do not run anything designed to disrupt a live service.

We use a managed WordPress host — do we still need this?

Usually yes. Managed hosts patch the core and the server; they do not audit the plugins you installed, the accounts you created or the files your team left in the web root. Those are the things that get sites breached.

Can you help us fix what you find, not just report it?

Yes. Every report includes a hardening baseline, and our managed service can apply and maintain it. We also re-test after you remediate, so you know the fix worked.

How often should a WordPress site be assessed?

At least annually, and after any major change — a new plugin, a migration, or a theme swap. Plugin vulnerabilities are disclosed constantly, so continuous monitoring of your installed components is the better answer for a site that matters to the business.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.