Listing Thumbnail

    WordPress V2 by Madarson IT - Hardened Enterprise WordPress on Ubuntu

     Info
    Sold by: Madarson IT 
    Deployed on AWS
    AWS Free Tier
    This product has charges associated with it for seller support. Madarson WordPress V2 is a self-hosted, enterprise-hardened WordPress AMI on Ubuntu 26.04 LTS - fail2ban, AIDE, auditd, and ClamAV active from first boot, an AI Copilot for content help and site-health diagnostics, and a deterministic Security Posture score combining live WPScan vulnerability checks with OS hardening state. No SaaS fees, no shared backend - all data stays on your EC2 instance.

    Overview

    Open image

    This is a repackaged software product from Madarson IT with additional charges for seller support.

    Madarson WordPress V2 is a self-hosted, enterprise-hardened WordPress platform on Madarson Hardened Ubuntu 26.04 LTS. Apache, PHP, MySQL, and WordPress core are pre-installed and running - complete WordPress's own setup wizard on first login and your site is live, already protected by intrusion prevention, file-integrity monitoring, audit logging, and malware scanning running silently in the background.

    Designed for organizations that need enterprise-grade security controls and audit visibility, not just a website - regulated mid-market businesses, agencies managing multiple client sites, and any team that needs a defensible security posture without a managed service. All data stays on your EC2 instance; AI analysis uses your own Anthropic API key.

    WHAT IT DOES

    On top of a full WordPress install, this image runs fail2ban, AIDE, auditd, and ClamAV automatically, and includes a built-in AI Copilot backed by your own Anthropic API key. The Copilot offers SEO/alt-text content assistance and a plain-English site-health chat that reads real diagnostics and answers questions like "why is my site slow?" grounded strictly in what it finds. A Security Posture feature checks every installed WordPress core/plugin version against the WPScan Vulnerability Database and combines it with live OS hardening checks into a single 0-100 score, computed by fixed deterministic rules - never estimated by the AI.

    FEATURES:

    • Intrusion Prevention: fail2ban bans repeated failed logins and automated scanning traffic automatically.
    • File-Integrity Monitoring: AIDE baselines the system at build time and flags unexpected changes, with a guided re-baseline command for legitimate updates.
    • Audit Logging: auditd tracks changes to sudoers, SSH config, and WordPress's own configuration.
    • Malware Scanning: ClamAV runs scheduled scans of the WordPress directory.
    • Security Posture Score: WordPress core/plugin versions checked against the WPScan Vulnerability Database (bring your own free or paid token) plus live OS hardening checks, combined into one deterministic 0-100 score. Scans run weekly, or on demand.
    • Role-Based Access Control: Security Analyst and Security Auditor roles for scoped AI Copilot access without full Administrator rights.
    • AI Copilot Content Assist: SEO meta description and image alt-text suggestions generated directly inside the block editor.
    • Site-Health Chat: plain-English diagnostics grounded in real logs and system state, not guesswork.
    • Staging Environment: WP Staging pre-downloaded for safe testing before changes go live.
    • Optional AWS Integrations: Secrets Manager for centralized API key storage via your instance's IAM Role, and CloudWatch Logs for centralized log visibility.

    WHO IS THIS FOR?

    • Regulated Mid-Market Organizations: credit unions, healthcare marketing sites, universities, government - anyone needing a defensible audit trail.
    • Agencies and MSPs: managing multiple WordPress sites who need posture visibility without a managed security service.
    • Security-Conscious Teams: wanting scoped staff access to AI tools without granting full Administrator rights.

    QUICK START

    1. Launch an EC2 instance (t3.medium or larger). Open ports 80, 443, and 22 in your Security Group.
    2. Browse to http://your-ec2-ip/  and complete WordPress's own setup wizard.
    3. Log in to wp-admin, open AI Copilot, and add your Anthropic API key (console.anthropic.com - pay-per-use).
    4. Open AI Copilot > Security Posture, add a WPScan token (free or paid tier, from wpscan.com), and run your first scan.
    5. Optionally configure AWS Secrets Manager or CloudWatch Logs per the deployment guide.

    CONFIGURATION: Optional integrations are controlled via /etc/madarson/madarson.env and applied with: sudo madarson-apply-config

    • AWS_SECRETS_MANAGER_SECRET_ID - Optional. Sources the AI Copilot's Anthropic key from Secrets Manager via your instance's IAM Role instead of pasting it into wp-admin.
    • AWS_REGION - Required if using Secrets Manager. Nothing here is enabled by default. Full README and deployment guide are on the instance at /opt/madarson/README.md and /opt/madarson/docs/DEPLOYMENT-GUIDE.md.

    RESPONSIBLE USE AND DISCLAIMER: WordPress is a trademark of the WordPress Foundation and is GPL-licensed open-source software. Ubuntu is a registered trademark of Canonical Ltd. Anthropic Claude and WPScan are third-party services requiring your own separate accounts/API tokens, billed by their respective providers. AWS Secrets Manager and CloudWatch Logs are Amazon Web Services billed at standard AWS rates; Madarson IT does not provide these services. This offering is not affiliated with, endorsed by, or sponsored by the WordPress Foundation, Automattic, Canonical Ltd, Anthropic, or WPScan.

    Highlights

    • Enterprise Hardening Out of the Box: fail2ban bans repeated failed logins and automated scanning traffic; AIDE baselines the system and flags unexpected changes, with a guided re-baseline command for legitimate updates; auditd tracks every change to sudoers, SSH config, and WordPress's own configuration; ClamAV runs scheduled malware scans. All active from first boot, nothing to configure.
    • Deterministic Security Posture Score: WordPress core/plugin versions checked against the WPScan Vulnerability Database (bring your own free or paid token) plus live OS hardening checks, combined into one 0-100 score computed by fixed rules - never estimated by the AI - so the same system state always produces the same number. Scans run automatically every week, or on demand.
    • AI Copilot and Role-Based Access, Your Key and Your Data: content assist and plain-English site-health diagnostics backed by your own Anthropic API key, stored only on your instance. Security Analyst and Security Auditor roles let you grant scoped team access without full Administrator rights. No shared backend, no vendor data retention.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 26.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    WordPress V2 by Madarson IT - Hardened Enterprise WordPress on Ubuntu

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (156)

     Info
    • ...
    Dimension
    Cost/hour
    t3.medium
    Recommended
    $0.12
    t2.micro
    $0.06
    t3.micro
    $0.12
    t2.small
    $0.06
    c3.large
    $0.12
    c5a.large
    $0.12
    c6a.large
    $0.12
    c7a.large
    $0.12
    c8a.large
    $0.12
    i3.large
    $0.12

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the software running on a chosen Amazon EC2 instance type. Pricing is not tiered by feature set. Every instance runs the same hardened WordPress image, so your rate depends only on the compute size you select. Options span general purpose, compute-optimized, memory-optimized, storage-optimized, and GPU-accelerated instance families, from small burstable sizes up to very large sizes. Larger instances cost more per hour because they provide more CPU, memory, or specialized resources. You can start small and move to a bigger instance as your traffic grows.

    Top-of-mind questions for buyers

    The hourly rate covers the hardened WordPress software license running on your chosen instance. You also pay standard AWS charges for the underlying EC2 compute, storage, and data transfer. These appear on the same AWS invoice. The size you pick sets both the software rate and the compute cost.
    The software fee meters running time. A fully stopped instance does not accrue the hourly software charge. You may still pay AWS storage fees for the attached volume while the instance is stopped. Charges resume when you start the instance again.
    No. Every instance type runs the same hardened WordPress image. Moving to a larger size only changes your hourly rate, since bigger instances provide more CPU, memory, or specialized resources. You pay the rate for whichever instance is running at that time.
    madarsonit.com
    Helpful?

    Vendor refund policy

    There is no refund policy for this image.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Version 2 - Initial Release

    Madarson WordPress V2 is a full rebuild of the Madarson hardened WordPress AMI, introducing enterprise security tooling, AI-assisted workflows, and a deterministic Security Posture scoring system as core platform features.

    WHAT'S NEW IN V2

    Security Hardening Stack (active from first boot, no configuration required)

    • fail2ban: Automatic intrusion prevention - bans repeated failed logins and automated scanning traffic.
    • AIDE: File-integrity monitoring - baselines the system at build time and flags unexpected changes, with a guided re-baseline command for legitimate updates.
    • auditd: Audit logging - tracks all changes to sudoers, SSH configuration, and WordPress's own configuration files.
    • ClamAV: Malware scanning - scheduled scans of the WordPress directory run automatically.

    Security Posture Score

    • WordPress core and plugin versions are checked against the WPScan Vulnerability Database (bring your own free or paid token).
    • Combined with live OS hardening state checks into a single deterministic 0-100 score computed by fixed rules - never estimated by AI.
    • Scans run automatically every week and on demand from the AI Copilot dashboard.

    AI Copilot (powered by your own Anthropic API key)

    • Content Assist: SEO meta description and image alt-text suggestions generated directly inside the block editor.
    • Site-Health Chat: Plain-English diagnostics grounded in real logs and system state.
    • Security Analyst and Security Auditor RBAC roles for scoped team access without full Administrator rights.

    Base OS

    • Built on Madarson Hardened Ubuntu 26.04 LTS.
    • Apache, PHP, MySQL, and WordPress core pre-installed and running at first boot.

    Staging Environment

    • WP Staging pre-downloaded for safe testing of changes before they go live.

    Optional AWS Integrations

    • AWS Secrets Manager: Source the Anthropic API key from Secrets Manager via your instance's IAM Role instead of entering it in wp-admin.
    • Amazon CloudWatch Logs: Centralized log visibility for audit and operational monitoring.
    • Integrations are opt-in, controlled via /etc/madarson/madarson.env.

    Additional details

    Usage instructions

    Allow inbound SSH access in your security group (TCP port 22) Allow inbound web access in your security group on TCP ports 80 and 443 To connect to your instance using the Amazon EC2 console: Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/  In the navigation pane, choose Instances. Select the instance and choose Connect. Choose the EC2 Instance Connect tab. For Connection type, choose Connect using EC2 Instance Connect. Access the EC2 with the default username: "ubuntu" To access your site and complete the setup wizard: http://your-instance-ip/ 

    Support

    Vendor support

    Support for Madarson IT WordPress V2 provided via email at info@madarsonit.com . Contact us for assistance with deployment, configuration, Security Posture or Secrets Manager setup, hardening feature questions, or troubleshooting.

    How to Submit a Request When contacting support, please include:

    • Your EC2 instance ID
    • A description of the issue or question
    • Any relevant error messages or log output

    Providing this information helps us diagnose and resolve your issue efficiently.

    Private Offers and Custom Licensing For private offers, volume licensing, or custom deployment arrangements, contact info@madarsonit.com  with details about your requirements and expected usage.

    About Madarson IT Madarson IT certified images are always up to date, secure, and follow industry standards. Every image is designed to help organizations establish a strong security baseline and reduce risk exposure to common cyber threats. Madarson IT offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.