Synthetic Industry

Job wp-hardening-checklist-one-site · revised 11 October 2026

Apply an agreed security hardening checklist to one WordPress site

Work through a written ten-item checklist on one WordPress site (backup check, eight hardening changes, risks report), test nothing broke, and hand over the evidence. Risk is reduced, not removed.

You might be seeing

  • Nobody can say how many people have an administrator login
  • Plugins and themes you no longer use are still installed and show update warnings
  • The dashboard lets anyone with an admin login edit theme and plugin code
  • You were asked for a security checklist and do not have one

No passwords, keys, card details or admin invites needed to start.

What usually happened

A WordPress install that has run for a few years usually carries avoidable weaknesses: unused plugins and themes that still need patching, administrator accounts nobody remembers, a dashboard code editor an attacker could use after one stolen login, and file permissions that are looser than needed. Hardening reduces risk, it does not remove it, and an over-eager change to permissions or login paths can stop updates or forms from working.

Who it’s for: Owner of a small business with a WordPress site who has never had its settings, users and plugins reviewed, or whose insurer, client or host asked what protections are in place.

Usually starts when: A security warning from the host, a plugin vulnerability notice, a staff member leaving who had an admin login, or a request to show that basic protections exist.

The result: Each of the eight hardening changes on a written ten-item checklist is applied or declined with a reason, the agreed pages, forms and logins still work afterwards, and you hold a before and after record signed off by you. The other two items are the backup check and the remaining-risks report.

Check whether this job fits

Four questions, about two minutes. Your answers stay on this page unless you choose to email them.

Does the site work normally and look as it should?
Is there a recent backup of both files and database?
Do you know who has an administrator login?

In the dashboard, open Users and filter by Administrator.

Who can approve removing plugins, themes and users?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Send an enquiry about this outcome

Checks you can run yourself

  1. List plugins and themes you do not use

    In the dashboard, open Plugins and Appearance then Themes, and list each item that is inactive or that you do not recognise.

    Look for: Inactive plugins and spare themes still need updating and still add risk. Send us the list, not the passwords or settings.

What you get

  • The ten-item checklist: item 1 confirmed, items 2 to 9 each marked applied, declined or not possible with the reason, and item 10, the remaining-risks report
  • A before and after record of users, plugins, themes and file permissions
  • The regression test sheet: agreed pages, a form and a login before and after
  • A short list of risks that remain and who owns them

Included

  • Checklist item 1 (the backup precondition, not a hardening change): one single-site WordPress installation with a recent backup of files and database, either one you tell us about or one we take first. This job does not test that the backup restores
  • Item 2: updating WordPress core, plugins and themes, on a staging copy first where one exists, otherwise in an agreed window after the backup
  • Items 3 and 4: removing the unused plugins and themes you approve, and reviewing the list of administrator accounts with you, one by one
  • Items 5 and 6: switching off the dashboard theme and plugin file editor, and checking file permissions against the values the host recommends
  • Items 7, 8 and 9: a strong, unique password and two-step sign-in for every administrator, using a plugin or host login protection that you approve; secure file transfer instead of plain FTP where the host offers it; and the configuration file restricted where the host allows
  • Item 10 (the report, not a hardening change): a written list of the risks that remain and who owns each, with a regression sheet run before and after

Not included

  • Cleaning or investigating a site that may already be hacked: see the restore job
  • Penetration testing, a security audit for any certification, or compliance advice
  • Setting up a web application firewall, a content delivery network or ongoing malware scanning
  • Patching custom code or a plugin with a known flaw that has no fix
  • Buying a two-step sign-in plugin licence or any other premium security plugin, which you hold
  • Any promise that the site cannot be attacked

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Item 1 is confirmed (a backup exists and its location is recorded), each of items 2 to 9 is marked applied, declined with a reason, or not possible with a reason, with a before and after record for each applied item, and item 10, the remaining-risks report, is delivered.

    Evidence: The signed checklist and the before and after record

  2. The dashboard no longer offers the theme and plugin file editors, every administrator has been confirmed by you as a current person, and unapproved accounts are removed or demoted.

    Evidence: Screenshots of the dashboard menu and the user list, and your written confirmation

  3. Each administrator confirms that two-step sign-in works for their own account, and file transfer to the site uses SFTP, or the host's lack of it is recorded as not possible.

    Evidence: Each administrator's written confirmation and a note of the transfer method

  4. The ten agreed pages, one form submission and one staff login pass the regression sheet both before and after the changes.

    Evidence: The regression sheet with a result and screenshot for each item

Sign-off. You sign off after reading the checklist and the remaining-risks list and seeing the regression sheet pass.

If it fails. If a change breaks the site and cannot be made safely, it is undone and marked not possible. You pay only if the agreed tests pass.

When it fits, and when we stop

It fits when

  • You can create a named administrator account for this job, with a strong unique password and two-step sign-in where possible, and remove it at sign-off, or you will make the changes from our steps. It has the full administrator role, because updates, removals and the editor setting need it
  • Your host lets us read or set file permissions through its panel or secure file transfer
  • A recent backup of files and database exists, or you agree we take one first; this job does not test that it restores

We stop and tell you if

  • The site already shows unexplained files, admin users or redirects, which means it may be compromised
  • A plugin update breaks the site and no compatible version exists
  • The host does not allow permission or configuration changes
  • Nobody can approve which plugins and users to remove

What could go wrong

Each change is recorded, and a change that breaks a page, form or login is undone and marked not possible. File permissions and the configuration file are restored from the recorded values. The backup is the fallback; this job does not test that it restores, so for a restore test see the backup job.

Scroll the table sideways to read it all.

RiskHow we handle it
A stricter permission or editor setting stops updates or a plugin from working.Each change is tested against the regression sheet and undone if it fails.
Removing a plugin that is quietly used breaks a page.You approve every removal and the pages are tested afterwards; removed plugins are kept in the backup.
The checklist gives a false sense of safety.The hand-over lists what remains risky and says plainly that hardening reduces risk but cannot remove it.

A second reviewer, separate from the work that produced the change, checks it against the evidence before you are asked to apply or approve it. No human supervisor is included unless your proposal names one. At launch much of the preparation is automated, and we say so.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Take or confirm a backup and record users, plugins, themes, versions and file permissions
  • Agree the ten checklist items and which plugins, themes and users may be removed
  • Apply updates on a staging copy where one exists, run the regression sheet, then apply each change on the live site in the agreed window
  • Re-run the regression sheet after each risky change and undo any that breaks it
  • Independent review of the before and after record
  • Hand over the checklist, the evidence and the list of remaining risks

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

To keep updates, backups and monitoring going, ask about the standing WordPress responsibility.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • WordPress publishes its own hardening guide, which you or your developer can follow. It describes each measure as risk reduction, not risk elimination. developer.wordpress.org
  • Your host's support can tell you which security settings its control panel offers, and turning on the ones it offers costs nothing. This job also reviews your users, plugins and permissions with you and tests the site after each change.

Questions

Will my site be unhackable afterwards?

No. Hardening reduces common risks and gives you a record of what was done. WordPress's own guidance calls it risk reduction, not risk elimination.

Do I need to give you my password?

No. You create a named administrator account for this job and remove it afterwards, or you apply the changes from our steps. It has the full administrator role because the updates, removals and editor setting need it, so we keep it to this job.

Is this a security audit?

No. It is a bounded checklist on one site. It is not penetration testing or advice for any compliance certificate.

Send an enquiry

Send us

  • The site address and the host
  • Whether a backup exists and how recent it is
  • Who should have an administrator login today
  • Any security warning, insurer question or client request that prompted this

Later, once you agree

  • A named administrator account created by you for this job, with a strong unique password and two-step sign-in where possible, removed at sign-off, or a person who will apply the changes
  • Secure file transfer or host panel access scoped to this site, via a company-controlled handoff
  • The ten pages, one form and one login to test
  • No live passwords or customer records by ordinary email

The site, the host and every account stay in your name. We use only the access you grant, record every change, and you can remove the access when the job is signed off. The administrator account is a full administrator: WordPress describes that role as access to all the administration features within a single site, which is why it is named for this job and removed at sign-off.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “wp-hardening-checklist-one-site” as the subject.