Most articles about WordPress security open with a breach statistic and a warning. This one will not. If the risks were not real, we would not sell security services; because they are real, you deserve a calm explanation instead of a scary one. This guide covers what a WordPress security service actually includes, the three jobs any real one has to do, what the market charges in 2026, and the configurations where a plugin honestly is enough.
The short version: WordPress security is three jobs that happen at different times. Hardening happens before an incident: updates, lockdowns, and edge firewall rules that prevent most problems from existing. Monitoring happens during: something watching for the change you did not make, with a human who sees the alert in time. Response happens after: a person who isolates the damage, restores a clean copy, and closes the hole. A security plugin does part of the first job and part of the second. A security service is whoever owns all three. The most common gap on real-world sites is not missing software. It is that nobody owns job three.
Security is three jobs, not one product
“We have security. There’s a plugin.” We hear this in most first conversations, and it is usually said with complete confidence. The confidence is understandable: the plugin dashboard is green, the scans run, the emails arrive. But security is not a product you install. It is three jobs that happen at three different times, and the plugin only reaches into two of them.
Before: hardening. The unglamorous work that prevents most incidents from ever existing. Core, theme, and plugin updates applied promptly, with testing, because known vulnerabilities in outdated software remain the leading cause of WordPress compromises. Unused plugins and themes removed, because every inactive extension is attack surface with no benefit attached. Login surface locked down: strong authentication, limited attempts, no shared admin accounts left over from old developers. Firewall rules at the edge of the network, filtering hostile traffic before it reaches WordPress at all, not just after it arrives. File permissions and database access set to the minimum the site needs.
During: monitoring. Watching for the change you did not make. File integrity checks that notice when core files differ from what shipped. Alerts on new admin users, because a created administrator account is one of the most reliable signs of a compromise in progress. Traffic pattern awareness, because a sudden surge of requests against your login page is not customers. Malware scanning on a schedule. And the part that software cannot supply: a human who actually sees the alert, today, and can tell a real signal from the noise. Detection that nobody reads is a diary, not a defense.
After: response. The job that exists for the day something gets through anyway, because sometimes it does, on every platform, under every provider. Response means a person isolates the damage so it stops spreading, restores the site from a clean backup, identifies how the intruder got in, and closes that hole so the same door does not open twice. With a tested backup and a named owner, response is measured in hours. Without either, it is measured in weeks, and they are your weeks: your searches, your forum threads, your ranking losses while the site serves spam.
Here is the shape of the market in one sentence: nearly everything sold as “WordPress security” concentrates on jobs one and two, and the entire cost of failure lives in job three.
What a real security service includes
A service worth the name covers all three jobs and can show you how. The components:
| Component | Job | What it looks like when done properly |
|---|---|---|
| Updates with testing | Before | Core and plugin updates applied promptly, tested against the site, not just auto-applied and hoped over |
| Attack-surface reduction | Before | Unused plugins and themes removed, stale admin accounts closed, permissions minimized |
| Edge firewall (WAF) | Before | Hostile traffic filtered at the network edge, before it reaches WordPress |
| File integrity and malware scanning | During | Scheduled scans plus change detection, with alerts a human actually reviews |
| Uptime and anomaly monitoring | During | The site watched continuously, so problems surface before symptoms do |
| Backups with tested restores | After | Daily backups, kept off the server, with restores actually rehearsed. An untested backup is a hope, not a plan |
| Incident response | After | A named party who isolates, restores, finds the entry point, and closes it, with a stated response expectation |
| Reporting | All three | You see what was done and what it caught, on a schedule, without asking |
Two details in that table separate real services from packaging. The first is tested restores. Almost every provider says “backups.” Very few rehearse restoring one, and the difference only becomes visible on the worst possible day. The second is a named response owner: not a ticket queue that will “escalate appropriately,” but a party whose job description includes your bad day.
One 2026 note belongs here. As more of the web has become accessible to automated agents since WordPress 7.0, sites now field software that acts, not just software that reads. Most of it is legitimate. Some of it is probing. The practical consequence for security is boring and important: the edge firewall and the monitoring layer now need to distinguish agent traffic you want from agent traffic you do not, and that calibration is ongoing work, not a checkbox. It is one more reason the “install it and forget it” model keeps aging badly.
Is a security plugin enough?
Sometimes, yes. Honesty about this is rare in our industry, so here is the actual boundary.
A well-configured security plugin, kept updated, covers a meaningful slice of jobs one and two: login protection, scanning, some firewall function inside WordPress. For a site with nothing at stake beyond inconvenience, that slice is a reasonable place to stop. Specifically, a plugin alone is a defensible choice when all three of these are true: the site does not process payments or hold customer data; downtime costs annoyance rather than revenue; and you would be willing to rebuild from scratch if the worst happened, because job three is yours and unrehearsed.
The calculus changes the moment the site earns money or holds anyone’s data. Not because the plugin gets worse, but because the unowned job gets expensive. An ecommerce store serving malware to customers, a membership site leaking logins, a lead-generation site quietly delisted from search results: these are job-three events, and no plugin does job three.
The fastest way to find out what you actually have: ask your current provider, in writing, what happens in the first hour after something gets through. A specific answer, with a named owner and a stated expectation, means you have a security service. A pause, or a link to a knowledge-base article, means you have software.
That question has a factual cousin you can answer right now, without asking anyone. Your site’s performance baseline is the number any provider should be measured against, and slow sites and neglected sites are usually the same sites. Our free speed audit reads your real numbers in about 30 seconds and does not ask for your email: https://sunnyhq.io/website-performance-test/
Five ways to cover the three jobs
1. A plugin, self-managed. Free to modest cost, covers parts of jobs one and two, leaves job three with you. The right answer for the low-stakes profile above, and an honest one. Fit: hobby sites, brochure sites with nothing at stake, technical owners who accept owning response.
2. A freelancer on call. A person who knows the site handles hardening and takes the call when something breaks. Personal and often excellent, with the same structural risk freelancer arrangements always carry: continuity. One person is a single point of failure, and incidents do not check calendars. If you go this route, require documented access, offsite backups with a rehearsed restore, and a written runbook someone else could execute. Fit: small sites with an established, responsive relationship.
3. A dedicated security service. Companies that sell security as the product: hardening, scanning, cleanup. The good ones are genuinely good at jobs one and two, and many will do incident cleanup. The structural limit is that they sit outside your hosting, so the deepest fixes (server configuration, edge rules, the infrastructure side of response) live across a boundary they do not control. Coordination on the bad day becomes your job. Fit: sites on hosting you trust that need stronger coverage than a plugin without changing anything else.
4. A maintenance plan with security included. Security as one of the five jobs of a broader upkeep service. Coverage depth varies widely by provider; the questions that matter are the same ones this guide keeps asking (tested restores? named response owner? edge firewall or plugin-only?). We reviewed the field in our maintenance services guide. Fit: stable sites that want one vendor doing scheduled upkeep, security included.
5. A platform. Hosting and security owned by the same party, so the three jobs and the infrastructure they run on live in one place: edge firewall at the network level, hardening and updates as routine, monitoring watched by the people who can act on it, and response with no boundary to coordinate across. This is the model we run at Sunny HQ, as part of managed WordPress hosting with security handled at the platform level. It is the right answer for sites where downtime and data have a price. If that is not your site, one of the four options above is honestly cheaper and honestly enough. The full ownership picture, beyond security alone, is in our website management guide.
What WordPress security costs in 2026
Unattributed market ranges, for orientation:
- Security plugins: free tiers exist; paid tiers generally run $100-$300 per year per site.
- Dedicated security services: roughly $50-$300 per month depending on depth, with response coverage concentrated at the top of that range.
- One-time malware cleanup: typically $150-$1,000 per incident on the open market, more when data exposure is involved. This is the price of renting job three after the fact instead of owning it in advance.
- Maintenance plans with security included: roughly $75-$400 per month for the broader service.
- Platform models: security is included in the hosting price rather than itemized; our own plans start at $129 per month with all three jobs covered.
The pattern worth noticing: prevention is priced monthly and modestly, response is priced per-incident and painfully. Every model above is a different answer to the same question of who pays for job three, and when.
The Bottom Line
WordPress security is three jobs: hardening before, monitoring during, response after. A plugin covers part of the first two and none of the third, which is where the real cost lives. A plugin alone is a fine choice for sites with nothing at stake; the moment revenue or customer data is involved, someone needs to own all three jobs, and you should be able to name who. The one-question test works on any provider, including us: what happens in the first hour after something gets through? Specific answer, real service. Pause, software. And none of this requires fear to be true, which is why we did not use any.
FAQ
What does a WordPress security service actually include?
A real service covers three jobs: hardening (updates with testing, attack-surface reduction, edge firewall rules), monitoring (malware scanning, file integrity checks, alerts a human reviews), and response (isolating damage, restoring a clean backup, closing the entry hole). Backups with tested restores and a named response owner are the two components that most reliably separate real services from packaging.
Is a security plugin enough for my WordPress site?
It can be. A plugin alone is defensible when the site holds no customer data, downtime costs annoyance rather than revenue, and you accept handling recovery yourself. Once a site earns money or holds anyone’s data, the unowned response job becomes the expensive gap, and no plugin covers response.
How much do WordPress security services cost in 2026?
Security plugins run free to about $300 per year. Dedicated security services run roughly $50-$300 per month. One-time malware cleanup typically costs $150-$1,000 per incident. Maintenance plans with security included run roughly $75-$400 per month, and platform models fold security into the hosting price.
What happens if my WordPress site gets hacked?
The response job: isolate the damage so it stops spreading, restore the site from a clean backup, identify the entry point, and close it. With tested backups and a named owner this takes hours. Without them it takes weeks, during which search engines may flag or delist the site.
How do I evaluate a WordPress security provider?
Ask three questions in writing: When did you last test a restore of my backups, and how long did it take? Is your firewall at the network edge or inside WordPress? And what happens in the first hour after something gets through? Specific answers with dates, locations, and named owners indicate a real service.