File rights, updates, and who can write PHP. Not a security plugin.
Core and plugins current, uploads unable to execute PHP, an admin list you recognise. A nulled plugin bypasses all of it. We do not install a suite and call the site locked.
What we change on a site that is still clean
wp-config.php not writable by the web user. PHP in uploads denied. A theme that needs 777 is the thing to replace, not the permission model.
Admin count, the user named admin, an application password nobody remembers. We remove what you do not recognise. We do not reset customers.
Core and a plugin with a known hole. A major PHP jump is not slipped into the same hour. That breaks a site that was fine.
This page is the lock. Cleanup is the other one.
Unknown admins, a redirect, PHP in uploads that you did not put there: that starts at €149 and may become a rebuild if the OS was taken. Hardening a rooted box does not help.
€55 an hour for one site. No “secured” certificate.
Minimum 1 hour. Several sites on the same server are quoted. We do not sell a plugin subscription.
Site still clean, and the file rights are whatever the installer left?
Tell us the host and the PHP version. No admin password in the first message.
