Visible on the site
What the technical review can observe.
- TLS and security headers, versions, roles, and public endpoints.
- Update, backup, logging, and accessible configuration signals.
- Known vulnerable components only through an explicitly selected intelligence source.
Outside the scan
Where manual review is required.
- Protection level, threat model, and organizational controls.
- Staff access, physical infrastructure, and every backup.
- A full penetration test and absence of hidden persistence.
Next step
Keep evidence separate from decisions.
Connect WordPress hardening to the wider information-system model and assign an owner to every uncovered area.
Sources
Review forms against primary sources.
Tell us what the site needs.
A goal, the current difficulty, and an optional website address are enough. Do not send passwords, keys, or private exports.