Armory Security · Premium

Get every feature — or get a specialist on your compromised site.

Two ways forward. Unlock all of Armory Premium and run continuous monitoring, alerts and one-click response yourself — or hand one compromised WordPress site to us and we’ll investigate, clean it and prove exactly what happened.

Do it yourself

Armory Premium

$49 /year

One site · all features · cancel anytime

  • Everything in the free forensic scanner
  • Scheduled baselines & drift alerts
  • Real-time admin-account & session monitoring
  • Live attack feed & IOC matching
  • One-click hardening & quarantine
  • Incident timeline & timestamped evidence bundles

Secure checkout via Stripe · license key emailed instantly

Done for you

Incident response — 1 site

$250 one-time

A specialist investigates & cleans one compromised site

  • Hands-on forensic investigation of your site
  • Web-shell & obfuscated-PHP removal
  • Hidden-admin & persistence (routes, cron, mu-plugins) cleanup
  • Site hardened against the same way back in
  • Timestamped evidence report of what happened
  • Includes a year of Armory Premium on that site

Secure checkout via Stripe · a specialist starts once payment clears

Not sure which? See how they compare →  ·  Just want the free scanner? Start free →

What Premium unlocks

The free scanner tells you what happened. Premium turns Armory into a standing watch — so you catch the next compromise as it starts and can prove it.

⏱️

Scheduled baselines & drift alerts

Re-baseline on a schedule and get alerted the moment a file is added, changed or deleted — no manual scans.

👮

Admin & session monitoring

Watch every administrator login, IP, device and session in real time and flag anything unfamiliar.

📡

Live attack feed

A running feed of inbound request signatures hitting your site so you see probing before it lands.

🎯

IOC matching

Match files, domains and patterns against known indicators of compromise to confirm a hit fast.

🛡️

One-click hardening & quarantine

Lock the site down and quarantine suspect files in one click — deliberate, reversible actions you control.

🧾

Timeline & evidence bundles

An incident timeline plus timestamped ZIP/CSV evidence bundles you can hand to your host or your report.

🔗

Auth-hook & permission audits

Audit authentication hooks and capability changes attackers use to keep a quiet foothold.

🧠

AI-assisted triage

Summarise findings and suspicious code so you know what matters first, not just a wall of alerts.

Compromised right now? Let us handle it.

If a site is hacked and you don’t want to dig through it yourself, hand it to a specialist. For a single site we investigate end-to-end, remove the attacker’s foothold, harden the way they got in, and give you a clear, timestamped record of what happened — and a year of Armory Premium so it doesn’t happen again unnoticed.

  • One compromised WordPress site, investigated end-to-end
  • Web-shells, backdoors & hidden admins removed
  • Persistence (rogue routes, cron, mu-plugins) cleared
  • Evidence report you can share with your host or client

yoursite.com/wp-admin · Armory incident
# armory incident response — 1 site
baseline + diff ! 3 files changed since last clean
web-shell hunt ⚠ 2 found uploads/.cache.php · index_old.php
hidden admins ⚠ 1 removed user “wp-svc”
persistence ⚠ cron + mu-plugin cleared
harden ✓ applied file edits off · xmlrpc locked
evidence ✓ bundle ready timestamped ZIP + report
# status: clean · premium monitoring armed
$

Buy Premium in under a minute

Self-serve, instant, and activated right inside WordPress.

Check out

Click Get Premium and pay securely through Stripe — $49/year, cancel anytime.

Get your key

Your license key lands in your inbox instantly, with activation instructions.

Activate

Paste the key in WP Admin under Armory Security → License & Plan.

Stay watched

Monitoring, alerts and one-click response switch on immediately.

Premium vs specialist — and other questions

Should I buy Premium or hire the specialist?

Buy Premium ($49/year) if you want every Armory feature on your own sites — monitoring, alerts, hardening and evidence export you run yourself. Hire the specialist ($250, one site) if a site is compromised right now and you want us to investigate and clean it for you. The specialist service includes a year of Premium on that site.

What does Premium include?

Everything in the free scanner plus the response and monitoring layer: scheduled baselines and drift alerts, real-time admin-account and session monitoring, a live attack feed, IOC matching, one-click hardening, quarantine, the incident timeline and timestamped evidence bundles.

How much is Premium and how do I buy it?

Premium is $49/year for one site, billed securely through Stripe — cancel anytime. After checkout your license key is emailed instantly; activate it from WP Admin under Armory Security → License & Plan.

What’s included in the $250 specialist investigation?

A hands-on forensic investigation of one compromised WordPress site: we baseline and diff your files, hunt web-shells and obfuscated PHP, find hidden admins and persistence (rogue routes, cron, mu-plugins), remove the foothold, harden the site, and hand you a timestamped evidence report of exactly what happened — plus a year of Armory Premium on that site.

How do I start the specialist service?

Use “Request emergency help” to tell us what you’re seeing. We scope the work, confirm it’s a single site, and send you a secure payment link — then we get to work.

Will any of this break my site?

Armory is forensics-first and read-only by default — it captures evidence before anything changes. Hardening, quarantine and lockdown are explicit, reversible actions, and during the specialist service we keep a full timestamped record of every step.

Pick your path and move.

Run every feature yourself for $49/year, or get a specialist on one compromised site today.