Close the doors, then prove they are closed

A security audit of SSH, firewall, services, PHP, permissions, mail and panel access, followed by the fixes. Hacked site? I clean it, find how they got in and close that door. Audit from €590, clean-up from €249 per site.

from€590audit, excl. VAT 25.5%. WordPress malware clean-up from €249 per site. Proposed prices.

The server on the right is a sample. Turn on hardening steps and watch each door close, or select a door to see the check I run on it.

web1.example.fi 192.0.2.10sample server
hardening steps
exposureexample, not a score

100 of 100Wide open: automated scanners will find several ways in within days.

check: SSHopen
root@web1:~# sshd -T | grep -E '^(permitrootlogin|passwordauthentication)'
permitrootlogin yes
passwordauthentication yes

Anyone on the internet can guess passwords for root, all day.

A real audit runs these checks from outside and inside your server.Test these six doors on my server

Hacked site: the first-hour playbook

The order matters more than speed. Restoring a backup before the evidence is copied usually means the same door is still open tomorrow.

stage 1 of 6, first 15 minutes

Contain

I do
Put the site behind a maintenance page, block public access to admin and upload paths, change panel, SSH, database and admin passwords, and stop outgoing mail if the server is sending spam.
You do
Tell me what you saw and when. Do not delete files or restore a backup yet.
Why now
Every minute online, the attacker can still send mail, add files or reach your customers.
what it looks like on the boxsample server
root@web1:~# exim -bpc
4127

Messages waiting in the mail queue. Thousands means a spam run is in progress; it gets frozen before anything else.

And afterwards, a report you can read

Every clean-up ends with one page in plain language: what happened, how they got in, what changed and what is still a risk. You can forward it to your customers or your insurer.

An honest note. No one can promise a server that cannot be hacked. What I can promise is that every known door is checked, the ones you do not need are closed, and you will know which risks remain and why.

incident report / example-shop.fisample, not a client

What happened

On 8 September someone uploaded a PHP file through an old upload form plugin and used it to add spam pages and send email from the server.

How they got in

The form plugin was three versions behind. The fixed version had been available for months; automatic updates were off.

What I did

Took the site offline for 40 minutes, copied the evidence, removed 2 injected files and 1 admin user, updated every plugin, cleared the mail queue and turned on upload and brute-force protection.

What you should do

Change the passwords you reuse anywhere else. Ask your team to log in again with the new passwords.

Still a risk

The theme is no longer maintained by its author. It is safe today, but plan a replacement within six months.

What hardening covers

Each change is written down with the command to verify it, so the next admin, or you, can check it is still in place.

SSH

Key-only logins, root login off, a named admin user with sudo, and login attempts rate-limited.

Firewall

Only 80, 443, mail and the ports you use stay open; MySQL listens on 127.0.0.1; panel ports allow-listed where you can.

Brute-force blocking

cPHulk on cPanel servers, fail2ban elsewhere, tuned so your own office is not locked out.

ModSecurity

A maintained rule set such as the OWASP Core Rule Set in front of PHP, with false positives whitelisted per site, not switched off.

PHP and updates

Supported PHP versions per site, dangerous functions disabled, OS and panel updates on a schedule you can see.

Files and mail

Correct ownership, no world-writable folders, no PHP execution in uploads, and outgoing mail limits so one hacked form cannot send 10,000 messages.

Running Magento? Security patches and admin hardening for the application itself are on the Magento page.

Not hacked yet? The cheapest clean-up is the one you never need.

Get a security audit

How the audit runs

Nothing changes on the server until you have read the findings and agreed which fixes to make.

  1. 1

    Access

    You add my SSH key, or a temporary WHM login. You can remove it the day the job ends.

  2. 2

    Outside scan

    Open ports, TLS, exposed panels and services, checked from the internet the way a scanner sees you.

  3. 3

    Inside review

    SSH, firewall, PHP, permissions, users, cron, mail and logs, read-only.

  4. 4

    Fix

    Agreed fixes made in a maintenance window, each with a rollback note.

  5. 5

    Prove

    Every door re-tested after the fix, results in the written report.

Security packages

Fixed prices in euros, excluding VAT 25.5%. You keep every login; I hand back access when the job ends.

Recommended

Security audit and hardening

€590from, per server proposed
  • Outside scan and inside review
  • Written findings ranked by risk
  • Agreed hardening fixes applied
  • Every door re-tested afterwards
Get a security audit

WordPress malware clean-up

€249from, per site; other platforms quoted proposed
  • Containment and evidence copy
  • Malware and injected code removed
  • Entry point found and closed
  • Cleaned site hardened
  • Plain-language incident report
Ask about a clean-up

Hardening in a care plan

€149from, per server per month proposed
  • Patching and log review every month
  • Hardening checked after each update
  • Backups checked and drilled
  • One-page monthly report
See care plans

If a cleaned site is reinfected through the same entry point within 30 days, I clean it again at no charge. owner to confirm

When I am the wrong person for this

Server hardening is practical admin work. Some security needs are a different job.

  • 01You need a formal penetration test, a compliance attestation or someone watching alerts around the clock. Hire a security firm that offers exactly that; I can fix what they find.
  • 02The operating system is end-of-life, such as CentOS 7. Hardening it buys little; moving to a supported server is the real fix.
  • 03You have no working backup. Set one up first, so a clean-up never depends on luck: backups and disaster recovery.

Questions about server security

My site was hacked. What now?

Do not delete anything or restore a backup yet. Change your hosting, admin and email passwords from a clean device, then contact me with the site address and what you saw. I contain the damage first, copy the evidence, clean the site, find how they got in and close that door.

What does hardening include?

SSH keys instead of passwords, a firewall that only opens the ports you use, brute-force blocking on SSH, panel and mail logins, ModSecurity rules, supported PHP versions, correct file ownership and permissions, and scheduled updates. Each change is listed in a written report with how to check it yourself.

Can you provide a security report for my customers?

Yes. You get a plain-language report of what was checked, what was found, what was fixed and what remains a risk, which you can share with customers or partners. It is a technical record of the work, not a certification or a compliance attestation, and it says so on the first page.

Get a security audit

Send the server or site address and what worries you. If the site is hacked right now, say so in the first line and I reply first to that. Otherwise you get a written fixed price within one working day.

Prefer email? Write to [email protected]

Pikselipolku is an independent studio and is not affiliated with cPanel, LiteSpeed or any other product named here.

Audit requestReply within one working day
What is wrong? (optional)

Optional: slow pages, lost rankings, a deadline, a law you need to meet.

About 2 minutes. Helps me send a firmer price.

Reply within one working day

Or email me: [email protected]

Made in Tampere. The path ends here.61.4978° N, 23.7610° E

Tell me what you need. I reply within one working day.

About these landmarks
  • Näsinneula tower, Tampere, 1971. Opened in 1971, with an observation deck and a revolving restaurant at the top.
  • Finlayson mill, Tampere, 1820. Cotton mill founded in 1820 by James Finlayson; the red-brick mill and chimney still stand by the Tammerkoski rapids.
  • Tampere Cathedral, 1907. National Romantic granite church by Lars Sonck, with frescoes by Hugo Simberg.
  • Helsinki Cathedral, 1852. White neoclassical church with green domes above the Senate Square steps, designed by Carl Ludvig Engel.
  • Parliament House, Helsinki, 1931. Eduskuntatalo, built of red granite behind a front row of tall columns.
  • Temppeliaukio Church, Helsinki, 1969. The Rock Church: cut into solid bedrock and roofed with a copper dome.
  • Suomenlinna sea fortress, Helsinki, 1748. Island fortress begun in 1748 at the entrance to Helsinki harbour; a UNESCO World Heritage Site.
  • Olavinlinna castle, Savonlinna, 1475. Medieval castle with three round towers, built on a rock island between two lakes.
  • Sauna by a frozen lake, UNESCO 2020. Finnish sauna culture is on UNESCO’s list of the intangible cultural heritage of humanity.
  • Lapland: spruce, reindeer and a fell, North. The northern end of the journey: spruce forest, a reindeer and a snow-capped fell.
© 2026 Pikselipolku, Tampere, FinlandBusiness ID [Y-tunnus]Built to WCAG 2.2 AABack to top