Dexfense

Know your attack surface.Build your defense.

Map your system architecture to MITRE ATT&CK® and get a prioritised, exportable security defense plan — in minutes.

MITRE ATT&CK® mapped 70+ components covered NIST CSF 2.0 Gap Analysis Exportable PDF reports
70+ Security Components
200+ ATT&CK® Techniques
NIST CSF 2.0 Aligned
Free to Use
HomeCommunity LibraryWordPress Business Website

WordPress Business Website

Dexfense Reviewed

Security architecture for a business website on WordPress with managed hosting, CDN, WAF and automated backup.

Web ApplicationsSmall Business
10 components·By Dexfense·v1.0 · July 2026

Overview

Covers a typical small or medium business website on WordPress. The architecture includes the CMS layer, a managed web server, a MySQL/MariaDB database, CDN for performance and media delivery, a WAF targeting common CMS vulnerabilities (SQLi, XSS, plugin exploits), DNS management and automated off-site backups. MFA protects the WordPress admin dashboard. No payment processing runs on the CMS itself.

Intended for

Small business owners, web developers and IT administrators managing WordPress websites.

Architecture Assumptions

This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.

  • Hosted on managed cloud hosting (e.g. WP Engine, Kinsta or cPanel-based shared hosting)
  • WordPress admin access is protected by MFA
  • Plugins and themes are kept up to date with a patch management process
  • No payment processing occurs on the WordPress installation itself
  • Automated backups run daily and are stored off-site

Out of Scope

  • Individual plugin ecosystem vulnerabilities are not assessed
  • Custom theme code quality is not reviewed at code level
  • Assumes single-site installation (not WordPress Multisite)
  • No active vulnerability scanning of the application is performed

Architecture Components10 components selected

Web & APIs

Content Management

Content management systems (WordPress, Drupal, etc.)

Web Servers

Public-facing web application servers

CDN

Content Delivery Networks for distributed hosting

Databases

SQL Databases

Relational databases holding structured data

Network

WAF

Web Application Firewall

DNS Services

Domain name resolution services

Storage

Backup Systems

Data backup and recovery systems

Cloud Storage

Cloud-based object or file storage

Auth & IAM

Multi-Factor Auth

Additional authentication verification layer

Monitoring

Logging Systems

Centralized log collection and management

Security Preview

Based on this architecture's component selection

Indicative Risk Score

49/100

10 techniques identified

1 Critical · 2 High

Top Attack Techniques

  • CriticalT1486Data Encrypted for Impact
  • HighT1190Exploit Public-Facing Application
  • HighT1070Indicator Removal on Host
  • MediumT1078Valid Accounts
  • MediumT1110Brute Force

Top Recommended Controls

  • 1Implement Web Application Firewall (WAF) and regular security testing
  • 2Focus on Data Protection as your highest priority security initiative

The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.

Use This ArchitectureRemix This Architecture

Remix copies the components so you can add or remove items before generating your assessment.

Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.

Back to Community Library