Why WordPress needs this
WordPress runs a vast share of the web, which makes it the most targeted platform on it. The overwhelming majority of hacked WordPress sites are not broken into through clever attacks, they are walked into through outdated software: a plugin left un-updated for months, a theme with a known hole, a core version behind on its security fixes. Keeping everything current is most of security, and a dedicated security layer is the rest.
WP Security Manager is our managed service that handles both.
What the service includes
It is an optional add-on for our WordPress and WordPress/WooCommerce clients, and while it is active we take responsibility for the security of your installation:
- We install and configure a professional security plugin, Solid Security, set up properly rather than left on its defaults.
- We keep it updated and maintained, so the protection stays current rather than ageing quietly.
- We keep your WordPress core and licensed plugins updated as part of the service, which is the foundation everything else rests on, and the reason the two go together.
- If your site is ever compromised, we clean it, removing malicious files and restoring the site, with no per-incident charge for as long as you are subscribed. Unlimited cleanups, not a capped number.
The conditions, and why they exist
The unlimited-cleanup guarantee rests on us being able to actually secure the site, which means two things have to be true:
- We have admin access. We cannot protect, update, or clean a site we cannot log in to. On our WordPress tiers this is straightforward, the access is already part of how those plans work.
- Your plugins are properly licensed. We can only update a plugin that is licensed to your site, and a plugin we cannot update is a hole we cannot close. Where a plugin came bundled free with a theme, WP Bakery is the common example, it is not licensed to you and cannot be updated by anyone, as our article on the WordPress update service explains. If such a plugin matters to your site, buying its own licence brings it under the umbrella. Where it cannot be licensed, we cannot guarantee that part of the installation, and we will tell you so plainly rather than pretend otherwise.
None of this is fine print designed to wriggle out of a cleanup. It is the honest boundary of what is possible: we can stand behind the security of a site we fully control and keep current, and we cannot stand behind one running software nobody is allowed to update.
If your site is hacked and you are not subscribed
We will still help. Malware removal for a site not on WP Security Manager is available on request, charged per event rather than covered, and we assess and quote each case since no two compromises are the same. Open a support ticket and we will tell you what is involved.
Worth doing the sums, though: a single paid cleanup often costs more than a good stretch of the managed service, and the managed service is what stops the next one happening. Most clients who come to us mid-hack for a one-off end up on the add-on afterwards, having learned the expensive way.
You don't have to host with us
WP Security Manager, and our WordPress update service alongside it, are about access and management rather than where the site lives. We provide both to an agency we work with for sites that are not hosted with us at all, on exactly the same terms. If you manage WordPress sites elsewhere and want them properly maintained and protected, talk to us, the service travels.
Good to know
Security and backups are partners, not substitutes. This service prevents the great majority of compromises and cleans up the rare one that slips through, while a backup is your independent safety net for everything else, a bad update, a mistake, a hardware failure. Our article on backups covers your options, and the two together are what let you stop worrying about your website and get back to your actual business.