WordPress Security Services & Site Hardening NZ & A

If there’s one constant thing about website security, it’s that the game changes daily. Cybersecurity services are needed to offset the sophistication of hacking tools and the skills of the people who use them for nefarious purposes. They seem to have an uncanny ability to find and exploit the tiniest vulnerability within software.

2FA WordPress Security concept
2FA – WordPress security concept.

I look beyond plugins to the server and header levels to provide “Defence in Depth” that basic security tools miss.

Our website maintenance services are primarily for self-hosted WordPress installations. That’s due to it being the world’s leading content management system. With over 810 million installations worldwide (over 40% of all websites), it’s a prime target for hackers. Find a vulnerability in a plugin and it opens up the opportunity to hack thousands of sites! Proactive WordPress security services ca n

WP Website Security Implementation WMS 1

Because we see this on a daily basis, we can respond to problems quickly and eliminate them. Better still, we can implement proactive measures to prevent known issues from arising by installing protective systems for you. For example:

  • Implementing robust onsite cybersecurity measures.
  • Web Application Firewall (WAF)
  • Brute force login mitigation
  • Two-factor authentication
  • Setting Security Headers
  • Deactivating XML RPC
  • Keeping WordPress core files, plugins, & themes up to date.
  • Scanning your website for malicious code injections daily.
  • Backing up files and the database daily.

I’ve worked on WordPress Attacks for over a decade

Many of my annual maintenance plan clients originally came to me in panic and despair because their websites had been hacked. They searched online for help and contacted me from this website or from my WordPressTechSupport.co.nz website.

Some illustrative “Case Study” examples include:

  • My worst personal experience of a hacking attack was 13 years ago. At the time, I had a Virtual Private Server on Arvixe.com with 35+ client websites hosted on it. One night, I was actually working on the server when all hell broke loose. Within a 30-minute period, a dozen of the sites had been hacked, disabled or deleted! The screen “credits” were all claimed by the Bangladeshi Hacking Club. It took me days to undo the damage the rotten swine had caused and to implement robust countermeasures. Basically, I became an instant WP security expert in that week.
  • The BridgeTravel.com site, formerly WorldTravelswithBridge.co.uk, was hacked 10 years ago. Jerry Bridge contacted me, and I cleaned up the mess of corrupted WP files and removed all traces of the malware for him. By a meticulous process of steadily evolving my own preventive measures, I have successfully protected this site (and many others) from any further hacking intrusion since 2016.
  • During 2025, a Wellington client (Readyleaf.co.nz) came under sustained Brute Force Login attacks for months. This was presumably initiated and paid for by an Australian competitor who wanted to buy the business – an offer that was politely refused. I responded to the attacks by tightening down the screws on Wordfence (2 attempts, then blocked for 2 months), and the attacker eventually ran out of IP addresses to use. The next attack tactic was DDoS… at the worst possible times, rendering the site unusable. I created a free Cloudflare account, and when the site was operating behind the proxy services, we switched to a premium hosting plan. Clouidflare provided the DDoS shield, the new hosting gave us significantly better origin server performance AND additional DDoS protection. The attacker no longer knew what the IP address was, and eventually they gave up. Problem solved…
  • In late 2025, an Auckland client (TopTeachingTasksMembers.com) was being harassed by a series of DDoS attacks, we assume by an unscrupulous competitor. By attacking during peak membership access times, this was severely impacting the website’s performance and usability. My solution was to relocate the site from A2Hosting to new hosting provider, under the cover of a Cloudflare account with DDoS protection. This prevented the attacker from discovering the site’s new IP Address. Problem solved…

Over my 20+ years of experience working with WordPress, I have progressively refined a series of 10 steps to harden and protect a website. Every website I add to my portfolio has those steps applied to it – and none have ever been breached. I’ve been contacted by several NZ website designers, in despair because they’ve been spending an inordinate amount of their time protecting client sites. Incessant attacks and repeated hacking. I’ve taken on every one of these website maintenance outsourcing referrals without hesitation, but with some preconditions in terms of what we absolutely must do to fix the situation.

Security Risks

Risks are always present and occur from internal sources through weak passwords, poor site management, and outdated server and/or website software. The external bad actors are always actively launching attacks 24/7. They WILL get to yours eventually, be ready! Proactive WP vulnerability scanning makes sense, and daily scans of your site will highlight potential problems fast.

Server Attacks

Attacks come in several forms, including brute force logins, exploits targeting known or new vulnerabilities in server software, poor server configuration or improperly configured firewalls. Phishing attacks seek to fool people into unwittingly divulging passwords. Secure WordPress hosting can male a difference – but that means cPanel hosting rather that the one-size-fits-all styl of WordPress hosting.

DDoS

Distributed denial of service attacks are becoming ever more common. Bad actors sell DDoS services to businesses wanting to ruin a competitor’s business. Launching such attacks at peak sales times cripples the site. I have expertise and solutions for that…

Types of Web Security

The main types of web protection are WAF (web application firewalls) and brute force login protection. These web solutions protect you from having WordPress infected with malware.

Web Security Services

Implementation of web solutions for your site. This may vary depending on the threat assessment but includes secure headers, WAF, BFL, scheduled scanning, backup systems and more.

We do website repairs almost daily, undoing the damage done by hacking attacks. On this page, we’re talking about proactive security measures to be put in place before an attack occurs. including:

Level 1: A clean small business site with no previous history of malicious attacks.

  • Web Application Firewall: In my experience, the fast and lightweight Block Bad Queries plugin stops troublesome visitors in their tracks.
  • Limit Login Attempts Reloaded or Loginizer – to ensure the bad guys don’t get unlimited time to fiddle behind the scenes, trying to crack a username and password combination.
  • Malcare or Sucuri: To scan core WP files, plugins and themes.
  • Asset Cleanup – which improves load speed and has an option to disable XML RPC

Level 2: A site which is either under attack or has previously been breached.

  • Wordfence: Provides a firewall, brute force login protection, strong password enforcement, 2-factor authentication plus WP core, theme and plugin scanning and file comparison verified against the WordPress repository.
  • Cloudflare: a free Cloudflare account will screen a lot of the “noise” before the attackers even reach your website.
  • Asset Cleanup – which improves load speed and has the very important option to disable XML RPC.
  • Place WordPress in a subdirectory to defeat automated script-based hacking efforts

All sites…

Backups of files and databases are automatically scheduled, and files are uploaded to secure off-site Cloud storage.

As well as proactive measures, we implement a good Database and File backup regime for your site and update all software as soon as new versions are available. In the less likely event that a compromise occurs and content is lost, we are able to recover/restore from the backups.

Cloudflare is also a very good option for both enhanced security AND faster page load speed. I have years of expertise and experience in using Cloudflare on scores of sites, and I do recommend it.

If you’re an NZ or Aussie business, when sourcing your website hardening, NZ-based services are generally your best option. When you’re under pressure and stress, dealing with a man who speaks fluent “Kiwi” is comforting…

“A security plugin is a good start, but true safety comes from hardening the entire environment. I build walls that hackers can’t easily climb.”

Ben Kemp

References

Written by Ben Kemp - WP Specialist

  • Ben Kemp - WMS NZ

    "Ben Kemp is a 20-year WordPress veteran. He doesn't just manage websites; he protects them. Having seen the web evolve since the early 2000s, Ben knows exactly where the 'hidden' security holes are. When you join WMS NZ, you're getting Ben’s direct eyes on your code—not a junior assistant." More Info...


    WP Profile