# WordPress Support & Security

> Custom security scanning with 13 audit modules, automated hardening and a 5-phase incident recovery process, on a monthly retainer.

Source: https://lastdoorsolutions.com/services/wordpress-support

## Before: checklists and crossed fingers

Most teams rely on manual updates and generic security plugins. That works until a PHP upgrade breaks a critical plugin, a vulnerability goes unnoticed, or a hacked site forces an emergency restore. The real cost is downtime, data loss, and lost client trust.

## After: tooling that replaces the checklist

Our security scanner is agentless: it connects to sites via SSH and WP-CLI. No plugins installed on the site. No performance overhead. No added attack surface. It runs 13 audit modules, including core file integrity, malware patterns, plugin vulnerabilities, user sessions, cron jobs, .htaccess, file permissions, wp-config, mu-plugins, the options table, server configuration, and admin anomalies.

After scanning, hardening runs automatically. It disables the file editor, removes WordPress version headers from source, restricts admin access paths, applies security headers, and locks down file permissions. These steps are scripted, repeatable, and version-controlled.

## Incident Recovery with a Defined Playbook

When a site gets compromised, speed matters, but so does thoroughness. Our recovery process runs 5 phases:

1. Assess the damage
2. Contain the breach
3. Clean malicious files and database entries
4. Harden against reinfection
5. Verify with a full rescan

Each phase has defined inputs and outputs. No guesswork.

## Maintenance That Scales

For agencies managing client portfolios, WordPress maintenance across dozens or hundreds of sites is a staffing problem. PHP version upgrades, plugin and theme updates, compatibility testing, performance optimization, hosting coordination. These tasks multiply with every site added. We handle this at scale because our tooling was built for it. One CLI command can scan, report, and harden across an entire fleet.

## What's Included

- **Security scanning:** 13 audit modules covering core integrity, malware patterns, plugin vulnerabilities, user sessions, cron jobs, htaccess, permissions, and more
- **Automated hardening:** Scripted lockdown of file editor, version headers, admin access, security headers, file permissions
- **Incident recovery:** 5-phase process: assess, contain, cleanup, harden, verify
- **PHP upgrades:** Version upgrades across all managed sites with compatibility testing
- **Plugin and theme updates:** Controlled updates with pre and post testing
- **Performance optimization:** Caching, database cleanup, asset optimization, server tuning
- **Managed hosting coordination:** Direct communication with hosting providers for server-level issues
- **Monthly reporting:** Scan results, actions taken, issues resolved

## Tech Stack

- **Security scanner:** Custom WordPress security scanner (Node.js, SSH2, WP-CLI, SQLite)
- **WP-CLI:** Server-side WordPress management without plugin overhead
- **SSH:** Agentless architecture, no plugins required on target sites
- **SQLite:** Local scan result storage and historical tracking
- **WHM/cPanel:** Server-level configuration and management
- **Cloudflare:** DNS, CDN, WAF, and DDoS protection

## Who This Is For

- **Agencies with WordPress client portfolios** that need reliable maintenance across dozens of sites without hiring dedicated WordPress ops staff. Our tooling replaces a full-time maintenance team.
- **Companies running multiple WordPress sites** that cannot afford downtime, data breaches, or the reputation damage of a compromised website.
- **Organizations on managed hosting** that need someone between their team and the hosting provider. Handling updates, security, and performance so their developers can focus on building.

## Proof

- Ticket-based WordPress support for one agency partner over 13 years, 10,000+ tickets resolved.
- Custom security scanner with 13 audit modules that installs nothing on the site.
- Incident recovery workflow in 5 phases, tested on real compromises.
