Prescription Point
WordPress security-sensitive delivery
A WordPress platform patients and clinicians can trust
Hardening, plugin/theme review, and incident investigation on WordPress sites that already have editors, plugins, and a history.
This is WordPress security consulting on a live install — not a scanner PDF. I review how WordPress is configured, which plugins actually run, and where custom code trusts input. Not a 24/7 SOC, and not a fake hack-proof badge.
Who this is for
Teams with a live WordPress site and a security question they cannot postpone
Healthcare or login-heavy fronts where a pretty theme is not an access model
Organisations that need a plugin/theme and configuration review before a launch
People who already saw odd admin users, spam pages, or mail they did not send
Teams looking for WordPress security consultants are usually hiring a review of the live install, not a SOC.
This is not a security training course, a scanner SaaS, or a guarantee against every future CVE.
Services included
01
Configuration that reduces the obvious surface — XML-RPC, file edit, roles — without breaking the editors who have to work tomorrow.
02
When something already looks wrong: odd users, spam content, or outbound mail nobody queued.
03
What actually runs, what is abandoned, and where custom PHP trusts input.
04
A list of what to change and in what order — including after a compromise. Not a screenshot of a grade.
05
Safer admin and editor practice. Backups and least-privilege accounts stay the baseline; I will not sell a hardening pass as insurance.
Relevant work
Titles, notes, and links are from the existing work section. No invented metrics.
WordPress security-sensitive delivery
A WordPress platform patients and clinicians can trust
More delivery notes sit in the case studies.
Stack
Process
01
What happened, who has admin, and whether we are preventing a problem or cleaning one up.
02
Configuration, plugin/theme inventory, custom code, REST exposure, and file permissions.
03
Change the things that matter, in order, without pretending the site is now immortal.
04
Leave the install in a state the team can keep: updates, roles, and backups they actually run.
Why this practice
FAQ
Hardening, plugin and theme review, and incident work on the live install. It is not training, a scanner SaaS, or a 24/7 monitoring product.
No. Nobody honest does. I reduce obvious risk and clean up incidents. Future CVEs and stolen admin passwords are still possible.
No. If you need a SOC, you need a product and a retainer built for it. I will say so rather than sell a review as insurance.
Yes. That is a remediation engagement: what got in, what to clean, and how to stop the same hole. It is not instant and it is not a magic plugin.
No. Scanners miss custom PHP and misconfigured roles. I look at the actual install.
Yes, when they are part of the constraint. File permissions and PHP versions often live with the host.
Yes. The notes on when a WordPress security consultant is actually useful live on the blog. This page is the service, not that article.
Related
Start
If the install is already live — plugins, editors, and a history — tell me what you are seeing. I will say whether a review is the right next step.
Prefer a calendar? Use the consultation scheduler on the contact page.