Updates, backups, monitoring and protection against hackers – so your website stays secure, fast and reachable. And if the worst happens, we step in and clean up compromised sites properly.
To protect many client sites reliably, we built our own software: WP AgentX – a self-hosted control centre that lets us manage, secure, monitor, update and back up every WordPress installation from one place. Your data stays on our servers in Germany. Typo3 projects get the same maintenance and security standard.
Save timeMaintain many sites centrally instead of one by one.
More securitySwarm protection, hardening and monitoring included.
Professional reportsClient reports in your own branding, automatically.
GDPR & data sovereigntySelf-hosted – nothing leaves our servers.
Predictable costsNo per-site fees paid to third parties.
Ready in no timeGuided onboarding for new sites.
WP AgentX · master dashboardLive
DashboardSitesSecurityUpdatesBackupsReports
Connected sites47
Uptime · 30 days99.98 %
Attacks blocked12,480
Pending updates3
All systems running · last scan 2 min ago
Live activity
blockedIP 185.220.101.34 – swarm sync to 47 sites
backupBackup completed: client-shop.com (4.2 GB)
update3 plugins updated on 12 sites – forensics clean
scanIntegrity scan clean: 47/47 sites
patchVulnerability found: form plugin – patch rolled out
Self-hosted & GDPR-friendlyData never leaves our servers in Germany.
Swarm protectionAn attack on one site instantly protects all the others.
Login Guard & 2FABrute-force protection and two-factor on every site.
Backup & RollbackUpdates with a backup beforehand – roll back in one click.
Any number of WordPress sites in one place: status, logs and one-click login (auto-login) straight into the admin area of every connected installation – no hunting for passwords.
Projects, notes & costs
Group client sites neatly into projects and tags. Notes and costs per site (licences, hosting, contract terms) – including automatic renewal reminders.
Onboarding & provisioning
Connect new sites through a guided wizard – the agent installs itself via WordPress login, no manual uploads. Install plugins and themes on many sites at once.
Safe bulk updates
Update plugins, themes and core individually or across every site – with a check and a backup beforehand, update windows, version rollback and an automatic return if something goes wrong.
Backups & remote storage
Scheduled backup jobs with off-site storage. Restore a whole site or a single plugin in minutes instead of hours.
Database optimisation
Clear out revisions, spam, transients and auto-drafts – per site or in one bulk run. A leaner database means a faster website.
Cloning, staging & migration
Clone websites and set up staging environments. Push changes back to the live site with a diff warning and a confirmation prompt – in a single click.
Swarm protection
When one site blocks an attacker, every connected site blocks them too. The network learns from each attack – automatically.
Login guard & brute-force protection
Rate limiting, IP blocks, captcha (without picture puzzles), a hidden login URL and WordPress hardening (9 reversible measures) lock the front door.
Two-factor authentication
TOTP-based 2FA for every user – rolled out centrally and enforced on each site.
Vulnerability scans
Plugins, themes and core are checked continuously against a current feed of known vulnerabilities – an alert before attackers get in.
Integrity & malware checks
Detects tampered plugin and core files by checksum. One-click reinstallation restores a clean WordPress in seconds.
Threat Intelligence
Cross-site analysis spots distributed infections, suspicious duplicate files and recurring attacker IPs across the entire portfolio.
Uptime, SSL & PageSpeed
Uptime checks around the clock (every 5 minutes), warnings before SSL certificates and domains expire, PageSpeed monitoring (Lighthouse) and a PHP error overview – with instant alerts.
Manage content centrally
Edit posts and pages directly – title, content, categories, tags – without logging in to the client site. Comments, media and a jump into the WordPress editor included.
Broken links & SEO analysis
Find dead links before Google does. Built-in SEO checks with traffic-light ratings for key phrases and readability keep content sharp.
Statistics & analytics
Cookie-free, GDPR-compliant visitor statistics plus Google Analytics (GA4) and Search Console in the dashboard: clicks, impressions, CTR, position and top search queries per page – with a month-on-month comparison and WooCommerce revenue.
White-label reports
Branded client reports as PDF with uptime KPIs, security events and completed work – plus an automatic weekly report by email, in NK IT Service branding.
Engineered like a security product. Because it is one.
Encrypted by default
Site secrets are stored encrypted with AES-256-GCM, and every API call between master and agent is signed with HMAC-SHA256.
Tamper protection
Deactivation protection stops the agent being switched off quietly – that requires explicit approval from the master.
Our server, clear rules
No third-party cloud ever sees credentials or client data. The master runs on our own servers in Germany.
Swarm intelligence
The shared IP block list turns every attack on one site into protection for all – versioned, synchronised and fully automatic.
Self-hostedGDPR-friendlyMade in GermanyAES-256-GCMHMAC-SHA256WordPress & Typo3
Security services
Protection, maintenance and emergency cover – complete
Security is not one single product but several layers working together – from updates through firewall and backups to an emergency plan. That invisible work keeps your website secure and fast, so you never have to hear “the site is down” again.
Updates & maintenance
WordPress, plugins and themes always up to date – tested before they go live. Outdated software is the biggest way in for attackers.
Automatic updates
Tested beforehand
Compatibility check
Backups & Recovery
Daily backups kept in a separate location. If something does go wrong, your website is back online in no time.
Daily backups
Off-site storage
Fast restore
Monitoring & alerting
Our own system watches availability, security and performance and raises the alarm at once – often before you notice a thing.
Uptime monitoring
Malware scans
Instant notification
Firewall & hardening
A web application firewall, login protection and a hardened configuration fend off the most common attacks automatically.
Web Application Firewall
Brute-force protection
Secure configuration
SSL & encryption
Encrypted connections are compulsory – for trust, data protection and a good Google ranking. We set everything up correctly.
SSL certificates
HTTPS migration
Secure transmission
Hack clean-up
Has your website been hacked? We remove the malicious code, close the gap and get you off the Google warning list.
Malicious code removed
Security gap closed
Google blacklist removal
GDPR & accessibility law
Data protection and accessibility have been compulsory in Germany since 2025. We bring your website up to a legally sound standard.
GDPR review
BFSG / WCAG 2.1 AA
Cookie & consent setup
Performance protection
Security must not slow you down. We keep your site fast – with caching, optimised images and a CDN.
Caching & CDN
Core Web Vitals
Continuous monitoring
What happens during a hack
A hack rarely announces itself
This is how a typical attack on an unmaintained website unfolds – and why every hour counts. No scaremongering, just everyday experience from our emergency work.
Hour 0
The break-in goes unnoticed
A bot finds an outdated plugin or a weak password and injects malicious code. From the outside the website looks perfectly normal – and that is exactly the problem.
Day 1
Google warns, malware spreads
The site redirects visitors to scam pages or distributes malware. Google flags it with “This site may be hacked”, and browsers block access.
Week 1
Rankings gone, trust damaged
The domain lands on blacklists, rankings collapse, emails end up in spam filters. Customers who saw the warning will not be back any time soon.
The cost
Clean-up, downtime, reporting duty
Emergency clean-up, days of downtime and possibly a GDPR report to the supervisory authority: a single incident quickly costs many times what years of prevention would have.
With protection
It never happens – or it is spotted within minutes
Up-to-date software gives bots almost nothing to attack. And if something does show up, our monitoring raises the alarm at once: restore the backup, close the gap, carry on – instead of weeks in crisis mode.
24/7 monitoringaround the clock
Attacks repelledbefore damage is done
Fast responseimmediate in an emergency
Monitoring
Attacks happen – the question is whether anyone is watching.
Most hacked websites stay infected for weeks before anyone notices – usually through a Google warning or annoyed customers. Our monitoring checks your website around the clock for availability, malicious code and suspicious changes. If something stands out, we act – often before you even hear about it.
Uptime checks around the clock Daily malware and integrity scans Automatic alerts when something looks wrong A short note to you: what happened and what we did
Protection that runs alongside you, not against you.
You never notice good maintenance – it happens quietly in the background. Updates are tested and installed outside peak hours, backups run automatically, certificates renew in good time. Your website stays available throughout, and you can concentrate on your business.
Updates tested first, then live Daily backups kept off site No interruption for your visitors A personal contact instead of a hotline
From the security check to ongoing protection – with no effort on your side.
1
Check
Free analysis of security, updates and backups.
2
Protection
Updates, firewall, SSL and hardening are put in place.
3
Monitoring
24/7 monitoring with backups and alerting.
4
Support
Ongoing maintenance and fast help in an emergency.
Security know-how
The key questions – answered clearly
Answers from practice – easy to follow for people and for AI search engines such as ChatGPT & Google AI.
How?How do I know my website has been hacked?
Typical signs are unknown redirects, unfamiliar pop-ups or content, new user accounts, a suddenly sluggish admin area and Google warnings such as “This site may be hacked”. Many infections stay invisible on purpose, so they can work undetected for a long time. Only regular malware and integrity scans give you reliable certainty.
Why?Why would anyone attack my small website?
Because attacks are automated: bots scan the internet around the clock for outdated plugins and weak passwords – the size of your company is irrelevant. Hijacked sites are abused for spam, phishing and distributing malware. Every unmaintained website is valuable enough for that.
What?What does website security cost?
Ongoing protection with updates, backups and monitoring costs a predictable monthly fee – cleaning up after a hack quickly costs many times as much. On top of that come downtime and lost customer trust. After a free check we quote you a fixed price with no small print.
Enough?Is a security plugin enough?
No – on its own a plugin is only one of several necessary layers and replaces neither updates nor off-site backups or monitoring. Around 9 in 10 WordPress vulnerabilities are in plugins themselves. What works is the combination of current software, firewall, backups and someone who keeps an eye on things.
What?What should I do after a hack?
Stay calm, take the website offline temporarily and change every password immediately – then remove the malicious code, close the gap and have the Google warnings lifted. Important: do not simply restore the backup, or the attacker will be back within days. We handle the entire clean-up for you.
Who?Who is liable if my website is hacked?
The website operator is responsible – if personal data is compromised, the GDPR requires a report to the supervisory authority within 72 hours. Otherwise fines may follow on top of the actual damage. Documented, regular maintenance is therefore also a piece of legal certainty.
Frequently asked questions
Website security – briefly explained
Why is my small website attacked at all?
Most attacks are not personal but automated: bots scan the internet for outdated plugins and weak passwords – regardless of your company size. Small sites without maintenance are an especially easy target. Ongoing updates and monitoring close exactly these gaps.
What is included in the security and maintenance contract?
Automatic updates (tested beforehand), daily backups, 24/7 monitoring for outages and malware, firewall and hardening, SSL and personal support. All for a predictable monthly fee – without you having to look after anything.
My website has been hacked – can you help?
Yes. We remove the malicious code, close the vulnerability that was exploited, rebuild the website cleanly and make sure Google lifts any warnings. Afterwards we secure the site so it does not happen again. If you suspect an active hack, it is best to call us straight away.
How quickly do I find out when something is wrong with my website?
Our monitoring checks availability and security around the clock and raises the alarm automatically. In the event of outages or anomalies we usually react before you or your customers notice anything. You then receive a short note on what happened and what we did.
What does website security cost at NK IT Service?
That depends on the size and the technology of your website. Maintenance and protection come as a predictable monthly fee, well below the cost of a single security incident. After a free check we quote you a fixed price – transparent and with no hidden costs.
Would a free security plugin not be enough?
A plugin is one building block, not a concept. It replaces neither updates nor off-site backups nor someone who reacts in an emergency. Many hacked WordPress sites did have a security plugin installed – but outdated software. What counts is the combination of several protective layers.
How often are updates and backups carried out?
Backups run daily and are stored separately from your website. We install security updates promptly after release – for critical vulnerabilities within 24 hours of the security advisory. Before every update we check compatibility so nothing breaks.
Do I have to report a hack (GDPR)?
If personal data may be affected – from contact forms or customer accounts, for example – the GDPR requires a report to the supervisory authority within 72 hours. We help you assess and document the incident so you meet this obligation correctly and on time.
Is accessibility (BFSG) really compulsory?
Since 28 June 2025 the German Accessibility Strengthening Act (BFSG) has required many commercial websites to meet WCAG 2.1 AA. We check whether you are affected and implement the necessary measures – including the accessibility statement.
Does this also work if you did not build the website?
Yes. We take over maintenance and security for existing WordPress websites built elsewhere too. After a short check we know what state the site is in and set up ongoing protection.
Free security check
Ready for a website that is protected?
Tell us briefly what it is about – we check the updates, backups and protection of your website free of charge and tell you honestly where action is needed. If you suspect an active hack, call us straight away: every hour counts.
Briefly describe your request – we will get back to you promptly. Works directly on our website, no email client needed.
Privacy
Cookies & external content
This website uses technically necessary cookies as well as marketing and analytics services from Meta (Facebook pixel) and Google (Google Ads, Google Analytics 4), which process data as soon as the page loads and may transfer it to the USA. External content such as YouTube videos will only load after your consent. For details, please see our privacy policy.
NecessaryCore website functions and storage of your cookie choice. Always active.
Anonymised usage statistics to improve the website. No statistics services are currently in use.
Content from external providers, e.g. YouTube videos (Google). Data is only transferred to the providers after consent.