WordPress
Service for
WordPress
Your website is up. That says nothing about whether it is secure.
I specialize in maintaining and securing websites that run on WordPress. Repair after a break-in, migration to my own infrastructure, ongoing updates and monitoring, and development where the standard parts are not enough.
Why websites running on WordPress get attacked
The problem is rarely one line of software. It is the way the site is run.
In July 2026 the German Federal Office for Information Security (BSI) issued a cyber security warning about WordPress at criticality level 3 of 4. 2 chained vulnerabilities, CVE-2026-60137 and CVE-2026-63030, together known as wp2shell, allowed unauthenticated remote code execution. The BSI recorded that proof-of-concept code appeared over the course of the weekend and that reports of first exploitation had already come in. Publication and attack were not weeks apart.
That is the rare case, and it was fixed quickly. The common case is duller. An installation gets set up, it runs, and after that nobody looks after it. Extensions stay where they are, long after a vulnerability in them has been publicly documented. The login path is the same everywhere by default, with no limit on attempts. Do nothing and you accumulate attack surface without noticing any of it.
When it happens, you do not see it
A break-in goes unnoticed because the site still looks normal. It loads, the contact form arrives, the dashboard reports nothing. In the background the site is put to work for someone else: malware served to your visitors, a phishing page in a directory you never open, spam sent in your name.
The bill arrives before anyone says the word attack. Google flags your domain as harmful. Your server address lands on blocklists and your mail stops arriving. Your host pulls the plug without discussing it with you. In the cases I take on, that is almost always the moment someone writes for the first time.
Themes, plugins, and why I hard-code your site
A theme you buy for 59 dollars is not a problem because it was cheap. It is a problem because 200,000 other people bought the same one. Find a hole in it and you have not found a website. You have found a list.
Then there is everything those kits ship with: sliders, form builders, icon libraries, demo importers, half a dozen add-ons you never asked for and never use. Every one of them is somebody else’s code running on your server. Every one of them is a door.
I build it differently. The site itself I hard-code. It is not assembled out of a database and a stack of PHP on every request. It is simply there, finished. The only things left under management are the things that actually need managing: your blog posts, your store. Nothing else has any reason to exist at runtime.
That does 2 things. Your site gets faster, noticeably. And the attack surface shrinks to the part that has work to do. What does not run cannot be exploited.
What is left, the store or the blog, I go through piece by piece. Nothing gets a pass here just because it came from a big name.
Then the extensions. Millions of installations are carrying plugins that have not seen an update in years. That is the first place I look, and almost always the richest. What I find there goes. Not deactivated, deleted. A deactivated plugin is still sitting on the disk, and a hole in the file system does not care whether somebody unticked a box in the dashboard.
What I do
Repair after a break-in
I reconstruct how somebody got in and what they did once inside, remove what does not belong there, and close the way back. Where a clean repair can no longer be justified, I tell you so and we rebuild. What I find, I document, so that you can prove it.
Migration to my own infrastructure
Servers in EU data centers, under my control, hardened and monitored. After that your site is no longer one tenant among a thousand on a machine nobody knows.
Updates and monitoring in day-to-day operation
Core and extensions stay current, and somebody actually looks. It is the least dramatic item on this page and the one that prevents most cases.
Hardening with IPServerSec for WordPress
My own hardening and early-warning system, tuned to an installation like yours. What it does is set out in full under IPServerSec.
Plugin development to your requirements
For when no off-the-shelf module does what you need and you would rather not install 3 extensions to solve one task.
Theme development
The design built rather than bought from a kit that 10,000 other sites are using.
Changes directly in the code
An installation that has grown over the years, with other people’s modifications in it, is not a reason to decline the job.
What you get is yours
You receive the full source code of every plugin and theme I build for you. That keeps you independent of me. Anyone who ties you in by withholding the code has not solved a problem. They have created a second one.
If your site is already behaving oddly, write to me. If it is not, that is the better moment.
WordPress is a registered trademark of the WordPress Foundation. intelligent piXel GmbH is an independent service provider and is not affiliated with the WordPress Foundation or Automattic Inc.