Resources / FAQ

Helpful answers to frequently asked questions.

/01

WordPress Risk & Why It Matters

WordPress powers more than 60% of all CMS-driven sites on the internet, which means attackers see it as a massive opportunity. Poorly maintained WordPress sites become true ‘low-hanging fruit.’ Because the platform is open-source with a massive community, security gaps are discovered and publicly reported quickly. Without proactive management, even attackers with minimal skill can compromise a site.

Neglect. When site owners fall behind on updates — core, themes, plugins, libraries — they create huge attack windows. Plugins especially require constant updates; some release fixes almost daily. Without disciplined version control and active maintenance, a WordPress site simply cannot stay secure.

No. Themes, plugins, and custom code often depend on specific versions. We analyze each update, test it against the client’s customizations, and confirm nothing breaks. If an update does cause issues we fix them proactively. ‘Click and pray’ is not a methodology.

/02

The OwlEye Service

Continuous updates to core, themes, plugins, and libraries; 24/7 monitoring for exploits and emerging vulnerabilities; proactive patching after controlled testing; WordPress-specific WAF tuning with custom rules; hardening of forms and access control; uptime monitoring; bug-fix remediation; and a monthly bucket of net-new development hours.

Automated tools catch the basics — patching core files, scanning for known malware, running generic firewalls. They have serious blind spots. We add the human layer: senior developers and security analysts who understand WordPress internals, address complex bugs, plug vulnerabilities automation misses, tune WAF configurations, and intervene 24/7 when something looks wrong.

Functional operation means the site stays secure AND continues working exactly as intended after any update — WordPress, plugin, theme, or browser. Security is one part; ensuring nothing breaks is the other. We verify that themes, plugins, and custom code function normally so user experience, forms, checkout flows, and integrations remain stable.

Because a secure site that’s broken is still a failure. Updates can introduce incompatibilities that take down forms, disable plugins, or break entire sections. We treat functional integrity as mission-critical and our regression testing ensures updates don’t disrupt operations.

/03

Vulnerability Management & Patching

We monitor WordPress and plugin releases daily. When a new version drops, we analyze its changelog, identify what security issues it addresses, and test it in a controlled environment. Only after we confirm compatibility and stability do we deploy it to your site.

10 business days for full remediation of any disclosed vulnerability. For critical CVEs, our SOC writes a virtual patch at the WAF layer in under 30 minutes — protecting you while the upstream fix is engineered and tested.

Yes. Different organizations have different risk tolerances. Some prefer weekly or monthly maintenance cycles; others need immediate patching the moment a critical vulnerability is announced. We offer tailored SLAs, including rapid-response tiers for clients who require immediate action.

/04

Customer Fit & Engagement

We support organizations of every size — from small businesses to full-scale enterprises. Any company that values security, user experience, uptime, and reliable site performance is a strong fit. Our core audience is mid-size to enterprise organizations that require professional management, but we also work with smaller businesses whose WordPress sites are critical to daily operations.

Yes. Our team is available 24/7 — every day, every holiday. WordPress threats don’t observe office hours and neither do we.

Yes. Findings are presented for the learning and benefit of your programming and IT teams to enhance your overall security posture. The goal is to empower your developers with knowledge to write more robust, secure code.

/05

Certifications, Clearance & Standards

Our team holds OSCP, CISSP, CISM, and CEH certifications, among others. We hire and develop senior practitioners — not generalist support staff.

All OwlEye employees must obtain SECRET clearance from the Federal Government of Canada.

We align with OWASP secure-code-review standards and our internal policies and procedures align with SOC 2 and ISO 27001. Compliance evidence is collected continuously and made available to your auditors.

/06

Adjacent Services

A process where a human reviewer — typically a security expert or a software engineer with security training — examines source code to identify security vulnerabilities, flaws, or weaknesses that automated scanners miss.

OwlEye employs a dual-method approach: hands-on manual review combined with automated scanning to effectively detect security weaknesses within the source code.

Our specialists cover everything from antiquated systems to specialized stacks and rare languages. No code base is too outdated or complex.

/07

Design, Development & Content Management

Both. Our Design & Development practice covers UX research, IA, visual design, theme and block development, accessibility-first builds, and integration work. Every line of code we ship is reviewed under the same secure-development discipline we apply to managed security — methodical, documented, and regression-tested.

Day-to-day editorial production handled by senior WordPress operators: page builds, content migrations, campaign landing pages, multilingual updates, media optimization, and accessibility remediation. Hours are tracked transparently and roll forward where contracts allow.

We run continuous accessibility operations against WCAG 2.2 AA and applicable jurisdictional mandates (ADA, Section 508, EAA, AODA). Automated pipelines (axe-core, Pa11y, Lighthouse) run on every change; quarterly manual passes cover NVDA, JAWS, VoiceOver, keyboard-only, and zoom/reflow. Findings are remediated at the source and documented in monthly conformance reports with VPAT-ready artifacts.

/08

Penetration Testing

Six distinct engagements: External Network, Internal Network, Web Application, API, Secure Code Review, and Red / Purple Team exercises. Each is scoped independently with its own rules of engagement, deliverables, and remediation support.

Every engagement is led by OSCP-credentialed practitioners following PTES, OWASP Testing Guide, and NIST SP 800-115 methodology. Findings are delivered in an executive summary plus a technical report with reproduction steps, evidence, CVSS scoring, and prioritized remediation guidance — and our team is available to verify fixes.

Yes — and it is the most common pairing. Test findings flow directly into the managed remediation pipeline, with virtual patches written at the WAF layer where source-level fixes need time to engineer safely.

/09

Partner & Referral Program

It is a referral program. Partners introduce qualified clients to OwlEye, we own the discovery, scoping, contract, and delivery, and partners earn commission on signed contracts and recurring service revenue. There is no requirement to white-label or resell our service.

Agencies, MSPs, hosting providers, and consultancies whose clients run institutional WordPress estates and who would rather hand off security than build it themselves. We work best with partners who value being able to point to a serious specialist when WordPress security comes up.