Service for WordPress

Maintenance

Service for
WordPress

What Hardening, repair, development For Websites running on WordPress Where Servers in EU data centres Contact my@intelligent-pixel.com

Your website is up. That says nothing about whether it is secure.

I specialise in maintaining and securing websites that run on WordPress. Repair after a break-in, migration to my own infrastructure, ongoing updates and monitoring, and development where the standard parts are not enough.

Why websites running on WordPress get attacked

The problem is rarely one line of software. It is the way the site is run.

In July 2026 the German Federal Office for Information Security (BSI) issued a cyber security warning about WordPress at criticality level 3 of 4. Two chained vulnerabilities, CVE-2026-60137 and CVE-2026-63030, together known as wp2shell, allowed unauthenticated remote code execution. The BSI recorded that proof-of-concept code appeared over the course of the weekend and that reports of first exploitation had already come in. Publication and attack were not weeks apart.

That is the rare case, and it was fixed quickly. The common case is duller. An installation gets set up, it runs, and after that nobody looks after it. Extensions stay where they are, long after a vulnerability in them has been publicly documented. The login path is the same everywhere by default, with no limit on attempts. Do nothing and you accumulate attack surface without noticing any of it.

When it happens, you do not see it

A break-in goes unnoticed because the site still looks normal. It loads, the contact form arrives, the dashboard reports nothing. In the background the site is put to work for someone else: malware served to your visitors, a phishing page in a directory you never open, spam sent in your name.

The bill arrives before anyone says the word attack. Google flags your domain as harmful. Your server address lands on blocklists and your mail stops arriving. Your host pulls the plug without discussing it with you. In the cases I take on, that is almost always the moment someone picks up the phone for the first time.

What I do

Repair after a break-in. I reconstruct how somebody got in and what they did once inside, remove what does not belong there, and close the way back. Where a clean repair can no longer be justified, I tell you so and we rebuild. What I find, I document, so that you can prove it.

Migration to my own infrastructure. Servers in EU data centres, under my control, hardened and monitored. After that your site is no longer one tenant among a thousand on a machine nobody knows.

Updates and monitoring in day-to-day operation. Core and extensions stay current, and somebody actually looks. It is the least dramatic item on this page and the one that prevents most of the cases.

Hardening with IPServerSec for WordPress. My own hardening and early warning system, tuned to running an installation like yours. What it does is set out in full under IPServerSec.

Plugin development to your requirements, where no off-the-shelf module does what you need and you would rather not install 3 extensions to solve one task.

Theme development, meaning the design built rather than bought from a kit that ten thousand other sites are using.

Changes directly in the code, in the places nobody else wants to touch. I have been writing code for 42 years. An installation that has grown over the years, with other people's modifications in it, is not a reason for me to decline the job.

What you get is yours

You receive the full source code of every plugin and theme I build for you. That keeps you independent of me. Anyone who ties you in by withholding the code has not solved a problem, they have created a second one.

If your site is already behaving oddly, write to me. If it is not, that is the better moment.