Vulnerability exposure
Review relevant disclosures affecting installed WordPress core, plugins, themes, PHP, and agreed server components.
Managed WordPress security
Ongoing security care tracks vulnerability exposure, update decisions, material configuration changes, administrative access, and recovery readiness. It begins with a known baseline and keeps ownership visible when the environment changes.
Never send credentials, private keys, backup archives, or confidential source code through this website.
Coverage
Review relevant disclosures affecting installed WordPress core, plugins, themes, PHP, and agreed server components.
Assess urgency, compatibility risk, ownership, testing requirements, and exceptions instead of treating every update identically.
Track material changes to administrative access, security controls, exposed services, and the agreed baseline.
Review administrative users, stale access, privilege changes, and the lifecycle of temporary accounts.
Check backup signals and schedule appropriate restoration evidence rather than assuming a successful backup job is recoverable.
Keep escalation contacts, safe access procedures, evidence expectations, and response ownership current.
Operating model
An alert without context or an owner is not a security outcome. Reports distinguish urgent exposure, scheduled remediation, accepted exceptions, provider-owned work, and observations that require more evidence.
The exact service boundary is documented: who applies updates, who validates compatibility, who owns the host, what constitutes an emergency, and whether remediation time is included or separately approved.
Maintenance plan or managed security
Most “WordPress maintenance” plans include a security line item. This table shows what that line usually covers and what security care adds.
| Activity | Typical maintenance plan | Managed WordPress security |
|---|---|---|
| Plugin, theme, and core updates | Applied on a schedule | Triaged by exploitability, tested where the risk warrants, exceptions recorded |
| Vulnerability disclosures | Whatever the security plugin flags | Reviewed against the installed versions, with an owner and a deadline for each |
| Configuration drift | Not tracked | Administrative access, exposed services, and security settings compared to the audited baseline |
| Administrator and access review | Rarely | Monthly review of users, roles, stale access, API keys, and temporary accounts |
| Backups | Backup job runs | Restore evidence: a backup is only counted once it has been restored |
| Edge and server layer | Out of scope | Cloudflare rules, origin exposure, and agreed host controls reviewed for drift |
| Incident response | Best effort, often billed separately | Escalation path, evidence expectations, and response ownership defined in advance |
| Monthly report | Uptime and update log | Open risks, completed actions, accepted exceptions, and the next decisions |
| Content edits and feature work | Included | Not included — kept separate so security work is never displaced |
The monthly report
Not general maintenance
Routine content editing, design changes, SEO publishing, feature development, and unlimited technical support are not implied by this service. Keeping that boundary clear prevents important security work from disappearing into a generic maintenance plan.
Common questions
No. Existing platform and plugin controls can supply useful signals. The service adds independent review, ownership, and decisions around those signals.
Only if that responsibility and workflow are explicitly included. Higher-risk sites may require staging, backups, compatibility checks, and an agreed maintenance window.
Incident response is included only when stated in the service agreement. The monitoring plan defines what happens when compromise is suspected.
Yes, after defining which party owns client communication, hosting access, updates, remediation approval, and incident escalation.
From $75 per site per month for a single business-critical site, with fleet pricing below single-site rates once several sites or servers share one baseline and reporting cadence. The fee follows fleet size, update ownership, included remediation time, and response expectations; the written proposal fixes it.
No. A maintenance plan keeps the site running and usually applies updates on a schedule. Managed security tracks vulnerability exposure, configuration drift, access, and recovery evidence against an audited baseline, and defines what happens in an incident. The comparison table above sets out the difference line by line.