Focused website support

Security Hardening

WordPress security review, malware cleanup, login hardening, and proactive measures to reduce the risk of compromise.

Most WordPress security issues come from the same places — outdated plugins, weak login credentials, leftover staging sites, or infections that went unnoticed for months.

I review what's actually running on your site, clean up what shouldn't be there, and tighten the parts that are most commonly exploited. No upselling on tools you don't need — just practical steps based on what your site actually requires.

Common problems

  • Site flagged as unsafe by Google or browser warnings
  • Hidden SEO spam or injected pages appearing in search results
  • Suspicious admin users or unfamiliar plugins
  • Login page targeted by bots or brute-force attempts
  • Malware that keeps coming back after cleanup
  • Old staging or test sites left unattended on shared hosting

What is included

  • Full site scan and manual file inspection
  • Malware removal and post-cleanup verification
  • Review of user accounts and admin access
  • Login protection and brute-force mitigation
  • Plugin and theme audit for known vulnerabilities

How the work proceeds

  1. 1 Describe the issue and share the site URL
  2. 2 I review the setup, identify risks, and confirm scope
  3. 3 Cleanup or hardening work carried out as agreed

Service story

Related work

Vanpoelgeest

Hidden SEO Spam Infection — Vanpoelgeest

The site was infected with hidden SEO spam — malicious content injected into the site's files, not visible to regular visitors but picked up by search engines. This type of infection can quietly damage a site's search reputation without the owner even noticing. The first cleanup didn't hold. Automated security scans caught surface-level traces but the infection kept coming back. This type of malware is built to survive plugin-based scans. It took a thorough manual inspection of the entire installation to find everything, followed by hardened security measures to keep it clean.

Janosch

10+ Infected Sites on a Single Hosting Account

A different client had a hosting account with over 10 WordPress installations — active sites, old staging environments, and forgotten test setups all sharing the same space. Every single one was compromised. With shared hosting like this, cleaning one site while the others remain infected is pointless — the malware just re-spreads through the shared filesystem. The cleanup required working through each installation systematically: identifying which sites were still needed, removing the ones that weren't, and then cleaning every remaining site before any of them could be considered safe.

Need practical help with this?

Describe the site and what needs attention. Please do not send passwords or private access details through the public form.

Request support