WordPress security & performance
Checked from the outside. Fixed from the inside.
A technical audit of your WordPress by a senior engineer, followed by an AI-accelerated fix sprint. Start with a free external check. No install, no access needed.
https · performance · security headers · robots.txt · llms.txt · version exposure
Check your WordPress from the outside
A quick external probe of your site: robots.txt, llms.txt, security headers and performance signals. No install, no access needed.
A first signal from the outside, not an audit. Nothing is stored except a short-lived cache of the result.
How it works
Three steps. Each one useful on its own.
Start free, stop whenever you like. Every step leaves you with something you can act on, with or without me.
01 · Check
Free external check
Six signals in seconds: HTTPS, response time, security headers, robots.txt, llms.txt and version exposure. No access needed.
02 · Audit
Technical audit
A senior engineer reviews code, configuration, plugins and hosting. You get a prioritized report: risk, effort and a clear order of work.
03 · Fix Sprint
AI-accelerated fix sprint
A time-boxed sprint closes the top findings. AI speeds up the work, a human reviews every change. Pull requests in your repository, with tests.
The audit
What I look at.
Not a plugin scan with a score. A review by someone who builds enterprise WordPress for a living, with the findings ranked by what actually hurts.
security
Security
Updates and dependencies, roles and capabilities, exposed endpoints like XML-RPC and user enumeration, headers, secrets in the wrong place.
performance
Performance
Page and object caching, slow queries, autoloaded options, asset loading and the Core Web Vitals your visitors feel.
code
Code quality
Custom themes and plugins against the WordPress Coding Standards, static analysis, deprecated APIs and upgrade blockers.
architecture
Architecture
Multisite setups, integrations and APIs, deployment workflow, environments and how changes reach production.
crawlers
Crawlers & AI
robots.txt, sitemaps, llms.txt and structured data: how search engines and AI agents read your site.
operations
Operations
Hosting, PHP and WordPress versions, backups you have actually restored, monitoring and who gets woken up.
Pricing
Clear scope. Fixed prices.
You always know what you pay for before any work starts.
Quick Check
Free
Six external signals, instantly.
- No install, no access
- Verdict per signal
- Shareable in seconds
Technical Audit
Fixed price
Scoped in a 30-minute call.
- Code, configuration and hosting review
- Findings ranked by risk and effort
- Walkthrough call with your team
Fix Sprint
Per sprint
Time-boxed, top findings first.
- Pull requests with tests
- Human review of every change
- Before and after measurements
Audit and sprint are quoted as fixed prices after a short scoping call. No retainer, no lock-in. Details on the Audit & Sprint page.
Who does the work
One senior engineer. No hand-offs.
I am Dennis Plötner. I have been programming professionally since 1997 and build enterprise WordPress every day: plugins, integrations and architectures that have to scale. The person who audits your site is the person who fixes it.
DP
Since 1997
programming professionally
WordPress VIP
Advanced Professional certified
Open source
maintainer of Multisite Language Switcher
Let’s make your WordPress boring. In the best way.
Tell me about your site. You get an honest answer, even if it is “you don’t need me”.