Abandoned sub-site and remote-management keys — the two July security items
The two items that came out of the July security findings, taken as one job. Priced individually they are $750 and $500; together they come to $1,250, which is what this quote charges. There is no bundle reduction on two items — each is at the same price it carries on its own. Every deliverable below is itemised, so nothing here is vaguer than it would be bought separately.
An open login on an unmaintained sub-site that shares a filesystem with the production paper, carrying 31 unmaintained plugins. The higher residual risk of the two.
- Survey of what is on the sub-site and what it shares with the production site — proof: the written inventory
- An archive-or-migrate decision recorded per sub-site, with redirects so nothing 404s — proof: the decision record plus a redirect test
- Post-removal re-scan confirming nothing was left behind on the filesystem — proof: the scan output
- Written record of what was removed, what was kept, and where the archive lives — proof: the document
A channel that bypasses wp-login entirely. Two access grants sit on it: one added in 2023 and in regular, legitimate use, and one dormant since May 2021. No sign of a break-in — recent activity is the vendor rotating its own platform signing keys on a routine cycle. The dormant grant is the finding.
- The dormant 2021 grant revoked — proof: before and after key listing
- The active grant rotated and the new key verified working — proof: rotation timestamp plus a successful post-rotation connection
- Stale usage-telemetry entries cleared — proof: before and after counts
- The 20 July failed attach run down and explained in writing — nothing gained access, but it is still unexplained — proof: the written finding
- A written access register, plus a 30-day post-rotation log review — proof: the register and the review note
The two prices above are what each item costs on its own, and they add up to the $1,250 total. Both are done as one job on one visit to the server.
