WP-SEC.com
L3 · APPLICATIONWordPress L2 · RUNTIMEPHP & code L0–L5 · FULL STACKServices L5 · GOVERNANCEGRC SELF-SERVETools ENGAGEPricing

L0–L5 defence in depth

Your CMS is a supply chain. We test every link in it.

WP-Sec is an offensive-led security practice built around the WordPress and PHP ecosystem — then extended across the edge, the runtime, the data layer and the people who govern it. We find what scanners miss, fix it in code, and leave you with evidence an auditor will accept.

See the 360° coverage
0Sites hardened
00-days & CVEs reported
0Median IR first response
0Audit pass rate
wpsec scan --target acme.example --depth full RUNNING
0Critical
0High
0Medium
0Passed

L3 application & ecosystem

Where WordPress actually breaks

Core is rarely the problem. The breach almost always enters through something bolted onto it — an abandoned plugin, a nulled theme, an endpoint nobody knew was public. Select any marker to see what we test for and how we close it.

L5 · GOVERNANCE, POLICY & PEOPLE — WRAPS EVERY LAYER BELOW

L2 runtime & source

PHP that survives contact with the internet

We review the code, not just the running site. Here are four patterns our reviewers pull out of real WordPress codebases every month — and the version we replace them with.

Static & taint analysis

Semgrep, PHPStan and custom WordPress rulesets traced from every superglobal to every sink.

Dependency forensics

Composer and npm trees resolved against advisory feeds, including transitive and abandoned packages.

Runtime hardening

disable_functions, open_basedir, OPcache validation, safe session cookies and error suppression.

Manual exploitation

An engineer chains findings by hand to prove real impact instead of listing theoretical risk.

L0–L5 full spectrum

Eight practices. One accountable team.

Most firms sell you a test or sell you a policy. We run the whole loop — find it, fix it, detect it next time, and prove it to your auditor. Select a practice to see what sits inside it.

360° COVERAGE

L5 governance, risk & compliance

Compliance that maps to controls you actually run

We write the policy, implement the control, and collect the evidence from the same systems we hardened. One control set, mapped across every framework you carry — so an ISO control and a SOC 2 criterion are satisfied by one piece of work, not three.

Controls mapped
Typical timeline
Evidence items

Self-serve before you talk to us

Two instruments we use on day one

The same risk model and maturity rubric we run in a kickoff workshop, simplified enough to use right now. No email required.

Risk heat map

Findings from a typical WordPress estate, plotted by likelihood and impact. Hover a cell to read what sits there.

LOW MODERATE HIGH CRITICAL

Security maturity check

Rate your organisation honestly on six dimensions. The score updates live and nothing is sent anywhere.

MATURITY TIER

Engagement what the first 30 days look like

Timeboxed, and dated from signature

DAY 0

Scope & rules of engagement

Asset inventory, crown-jewel identification, testing windows and a signed authorisation letter. No surprises for your hosting provider.

DAY 1–4

Reconnaissance & automated sweep

Passive footprinting, subdomain and origin discovery, dependency SBOM, then tuned automated scanning to clear the noise floor.

DAY 5–12

Manual exploitation & code review

Two engineers work the application by hand and read the source. Critical findings are reported the hour they are confirmed, not at the end.

DAY 13–16

Report, patches & walkthrough

An executive summary your board can read, a technical appendix your developers can act on, and pull requests for the fixes we can write ourselves.

DAY 17–30

Remediation support & retest

We stay in your Slack while your team ships fixes, then retest every finding and reissue the report with closure evidence attached.

ONGOING

Monitoring & annual re-review

File integrity monitoring, advisory watch on your exact plugin set, and a scheduled re-test before your certification renews.

CASE FILE · E-COMMERCE · 11 STORES

Card skimmer removed in 9 hours, root cause closed in 6 days

A multi-store WooCommerce group was silently exfiltrating checkout fields through a modified mu-plugins loader. Their scanner reported the estate as clean for eleven weeks.

We traced entry to a licence-check callback in a nulled premium theme, contained the same day, rebuilt the affected hosts from known-good images, and rewrote their deployment so that no writable path is ever executable again.

CONTAINMENT9h
ROOT CAUSE6d
RECORDS EXPOSED0
REINFECTIONNone

“They found it in the theme, not the logs.”

Head of Engineering, subscription media platform

“The report went to our SOC 2 auditor untouched.”

CTO, B2B SaaS, 40 staff

Engage transparent scoping

Priced by scope, never by fear

Fixed-fee assessments and flat monthly retainers. Every tier includes remediation support and a free retest — a finding you cannot close is not a finding we have delivered.

Prices are indicative for a standard scope and exclude VAT. Regulated industries, multi-region estates and out-of-hours incident retainers are quoted individually.

FAQ the questions buyers actually ask

Before you send the brief

Start response within one business day

Tell us what you are protecting

Send the shape of the estate and the deadline you are working to. You will get a scoping call with the engineer who would run the work — not an account manager.

Enter your name.
Enter a valid email address.
Enter your organisation.
Give us a couple of lines to work with.

We never sell or share what you send.

Active incident?

Call the 24/7 line and we triage immediately, client or not. The first hour is unbilled.

Responsible disclosure

Found something in a site we maintain? Report it under our safe-harbour policy and we will credit you.

Where we work

Remote-first across UK and EU time zones, with on-site incident response available in major hubs.

Typical lead time

Assessments start within 2–3 weeks. Incident response starts the same hour.

Prefer email?

[email protected]