How we secure code, infrastructure, and customer data.
Security is part of how we ship, not a separate department. The practices below apply to every engagement, from a one-week audit to a multi-year retainer.
Most security incidents in WordPress are not zero-day exploits. They are
stale credentials, missed updates, plugin conflicts, and shared admin
access. The practices below address the failure modes that actually
account for incidents we see in the wild.
We also operate WP Vanguard, a WordPress security scanner SaaS we run
against our own properties weekly. Customer engagements get the same
scanner on request.
What we do
Six practices that run on every engagement.
Each practice is documented, audited, and the same across every project. No special-snowflake security policies per client.
01
Code-level security
Every plugin and theme we publish runs through WPCS, PHPStan level 5, and a security-focused code review before release. Customer projects follow the same gate. We ship the WP Vanguard scanner against our own properties weekly.
→ Security gates run on every commit, not on every release.
02
Credential isolation
Per-client password vaults, SSH keys rotated quarterly, no shared credentials between teams. Production access requires multi-factor. WordPress admin access is audited and revoked as soon as the engagement ends.
→ Engineers never share credentials in chat or tickets.
03
Hosting partner standards
We work with Cloudways, WP Engine, Kinsta, Pressable, SiteGround, and bare-VPS deployments. Every recommended host meets a minimum bar of automated backups, server-level firewalls, daily malware scans, and TLS 1.3.
→ Hosting recommendations match the security profile of the project.
04
Data handling and encryption
Customer data is encrypted in transit with TLS 1.3 and at rest where we control storage. We do not retain customer data beyond the engagement. PII handling follows GDPR principles by default for every project.
→ Default-on encryption, default-off retention.
05
Access reviews
Quarterly review of who has access to what across every active engagement. Stale access is removed. Departing engineers are de-provisioned the same day. Production access is the smallest set of people who need it.
→ Access list never grows quietly.
06
Incident response
Documented incident response runbook for compromised sites, leaked credentials, and ongoing attacks. WP Vanguard cleanup tooling runs the technical recovery. Communications template covers customer notification, postmortem, and remediation timeline.
→ Incidents have a playbook, not a panic.
Hosting and infrastructure partners
We do not run customer infrastructure. We work with hosting partners that
meet a documented minimum standard. For most WordPress projects we recommend
Cloudways, Kinsta, WP Engine, or Pressable. For Laravel and Astro projects
we deploy on Cloudflare Workers, Render, or Fly.io depending on the workload.
Customer-owned infrastructure works too. We adapt to your hosting choice
and document any security gaps before kickoff.
Vulnerability disclosure
Found a security issue in a Wbcom plugin or theme? Email security at
wbcomdesigns dot com. We acknowledge within 24 hours and ship a fix within
seven days for critical issues. Disclosure timeline is coordinated with
the reporter.
Audit history
We have completed third-party security audits on three of our published
plugins. Audit reports are available under NDA on request. Third-party
penetration tests on customer projects are coordinated through your security
team and we provide remediation within the agreed window.
Common questions
Frequently asked
Do you sign DPAs for GDPR compliance?
Yes. Standard GDPR DPA available on request. We sign before any customer PII flows through our systems.
Do you carry professional liability insurance?
Yes. Coverage details available on request for enterprise engagements that require it.
Can you complete our security questionnaire?
Yes. We respond to vendor security questionnaires within four business days. Common questionnaires we have completed include SIG, CAIQ, and bespoke enterprise procurement forms.
What happens to our data when the engagement ends?
All copies of customer code and data are removed from our systems within 30 days of project close. Production access tokens are revoked the same day the engagement ends. Documented in writing on request.
Need security documentation now?
Tell us what your team needs.
Security questionnaires, DPA, sample contracts, audit reports, references. We respond within four business hours.
Seriously, one of the best software tech experiences I've ever had!
After 16 years of buying WordPress themes and plugins, I know exactly what bad support looks like and Wbcom Designs is the polar opposite. My setup was a nightmare: multiple tools, deep integrations, custom configurations that required…
Duston McGroarty·US·
Great service, great plugins
I was using an excellent plugin created by Wbcom Designs and had both an error and discovered a slight bug in one aspect of the plugin. After creating a support ticket I got a super-quick response and discovered the error was on my part…
Edward Bonthrone·US·
Excellent Theme, Powerful Plugins and Outstanding Support
I am using the REIGN theme and several plugins from Wbcom Designs on my website. The theme is beautifully designed, and the plugins are user-friendly. Everything works smoothly, and the features are perfect for building professional…
S W Malcolm·US·
The best development team ever
It has been a very pleasurable experience working with Wbcom Designs. Anmybia Siddiqui has been a stellar leader of the dev team. Her communications are very professional and productive. Anmybia and her team have completed every task we…
Real America's Voice News·US·
Top notch support
Top notch support. I have been frustrated generally by the slow support for most themes and plugins, but they are helpful and quick to reply. Highly recommend.
Woods·DE·
I was impressed
I have worked with many WordPress plugins over the past 14 years part time. I have learned that if the support is not prompt and effective it is a sign to move on. Tonight, Wbcom has impressed me and I will be hiring them for some more…
Steve Valencia·US·
Perfect plugins for community sites
I wanted to build a community website and these guys created the perfect plugins for me. To be honest, I want to buy every single one of their plugins. If I had more money I would.
Sora Seaton·US·
Excellent Plugins and Outstanding Support
We use BuddyPress with several free BP plugins from Wbcom Designs, and we are extremely satisfied. The plugins add real value for our community, are updated regularly, and are continuously improved. They integrate seamlessly with their…
Peter Gibson·DE·
Great and very supportive
This company have been great and very supportive. I highly recommend them.
Steve s·GB·
Excellent template and first-class support
The template from Wbcom Designs is truly great, modern, flexible, and easy to use. The support is very helpful and friendly. For questions or problems you receive fast, competent assistance and feel well taken care of. Highly recommended.