This product has charges associated with it for seller support.
Madarson WordPress V2 is a self-hosted, enterprise-hardened WordPress AMI on Ubuntu 26.04 LTS - fail2ban, AIDE, auditd, and ClamAV active from first boot, an AI Copilot for content help and site-health diagnostics, and a deterministic Security Posture score combining live WPScan vulnerability checks with OS hardening state. No SaaS fees, no shared backend - all data stays on your EC2 instance.
This is a repackaged software product from Madarson IT with additional charges for seller support.
Madarson WordPress V2 is a self-hosted, enterprise-hardened WordPress platform on Madarson Hardened Ubuntu 26.04 LTS. Apache, PHP, MySQL, and WordPress core are pre-installed and running - complete WordPress's own setup wizard on first login and your site is live, already protected by intrusion prevention, file-integrity monitoring, audit logging, and malware scanning running silently in the background.
Designed for organizations that need enterprise-grade security controls and audit visibility, not just a website - regulated mid-market businesses, agencies managing multiple client sites, and any team that needs a defensible security posture without a managed service. All data stays on your EC2 instance; AI analysis uses your own Anthropic API key.
WHAT IT DOES
On top of a full WordPress install, this image runs fail2ban, AIDE, auditd, and ClamAV automatically, and includes a built-in AI Copilot backed by your own Anthropic API key. The Copilot offers SEO/alt-text content assistance and a plain-English site-health chat that reads real diagnostics and answers questions like "why is my site slow?" grounded strictly in what it finds. A Security Posture feature checks every installed WordPress core/plugin version against the WPScan Vulnerability Database and combines it with live OS hardening checks into a single 0-100 score, computed by fixed deterministic rules - never estimated by the AI.
File-Integrity Monitoring: AIDE baselines the system at build time and flags unexpected changes, with a guided re-baseline command for legitimate updates.
Audit Logging: auditd tracks changes to sudoers, SSH config, and WordPress's own configuration.
Malware Scanning: ClamAV runs scheduled scans of the WordPress directory.
Security Posture Score: WordPress core/plugin versions checked against the WPScan Vulnerability Database (bring your own free or paid token) plus live OS hardening checks, combined into one deterministic 0-100 score. Scans run weekly, or on demand.
Role-Based Access Control: Security Analyst and Security Auditor roles for scoped AI Copilot access without full Administrator rights.
AI Copilot Content Assist: SEO meta description and image alt-text suggestions generated directly inside the block editor.
Site-Health Chat: plain-English diagnostics grounded in real logs and system state, not guesswork.
Staging Environment: WP Staging pre-downloaded for safe testing before changes go live.
Optional AWS Integrations: Secrets Manager for centralized API key storage via your instance's IAM Role, and CloudWatch Logs for centralized log visibility.
WHO IS THIS FOR?
Regulated Mid-Market Organizations: credit unions, healthcare marketing sites, universities, government - anyone needing a defensible audit trail.
Agencies and MSPs: managing multiple WordPress sites who need posture visibility without a managed security service.
Security-Conscious Teams: wanting scoped staff access to AI tools without granting full Administrator rights.
QUICK START
Launch an EC2 instance (t3.medium or larger). Open ports 80, 443, and 22 in your Security Group.
Log in to wp-admin, open AI Copilot, and add your Anthropic API key (console.anthropic.com - pay-per-use).
Open AI Copilot > Security Posture, add a WPScan token (free or paid tier, from wpscan.com), and run your first scan.
Optionally configure AWS Secrets Manager or CloudWatch Logs per the deployment guide.
CONFIGURATION:
Optional integrations are controlled via /etc/madarson/madarson.env and applied with: sudo madarson-apply-config
AWS_SECRETS_MANAGER_SECRET_ID - Optional. Sources the AI Copilot's Anthropic key from Secrets Manager via your instance's IAM Role instead of pasting it into wp-admin.
AWS_REGION - Required if using Secrets Manager.
Nothing here is enabled by default. Full README and deployment guide are on the instance at /opt/madarson/README.md and /opt/madarson/docs/DEPLOYMENT-GUIDE.md.
RESPONSIBLE USE AND DISCLAIMER:
WordPress is a trademark of the WordPress Foundation and is GPL-licensed open-source software. Ubuntu is a registered trademark of Canonical Ltd. Anthropic Claude and WPScan are third-party services requiring your own separate accounts/API tokens, billed by their respective providers. AWS Secrets Manager and CloudWatch Logs are Amazon Web Services billed at standard AWS rates; Madarson IT does not provide these services. This offering is not affiliated with, endorsed by, or sponsored by the WordPress Foundation, Automattic, Canonical Ltd, Anthropic, or WPScan.
Highlights
Enterprise Hardening Out of the Box: fail2ban bans repeated failed logins and automated scanning traffic; AIDE baselines the system and flags unexpected changes, with a guided re-baseline command for legitimate updates; auditd tracks every change to sudoers, SSH config, and WordPress's own configuration; ClamAV runs scheduled malware scans. All active from first boot, nothing to configure.
Deterministic Security Posture Score: WordPress core/plugin versions checked against the WPScan Vulnerability Database (bring your own free or paid token) plus live OS hardening checks, combined into one 0-100 score computed by fixed rules - never estimated by the AI - so the same system state always produces the same number. Scans run automatically every week, or on demand.
AI Copilot and Role-Based Access, Your Key and Your Data: content assist and plain-English site-health diagnostics backed by your own Anthropic API key, stored only on your instance. Security Analyst and Security Auditor roles let you grant scoped team access without full Administrator rights. No shared backend, no vendor data retention.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on a chosen Amazon EC2 instance type. Pricing is not tiered by feature set. Every instance runs the same hardened WordPress image, so your rate depends only on the compute size you select. Options span general purpose, compute-optimized, memory-optimized, storage-optimized, and GPU-accelerated instance families, from small burstable sizes up to very large sizes. Larger instances cost more per hour because they provide more CPU, memory, or specialized resources. You can start small and move to a bigger instance as your traffic grows.
Top-of-mind questions for buyers
What does the hourly rate cover, and what am I billed for separately?
The hourly rate covers the hardened WordPress software license running on your chosen instance. You also pay standard AWS charges for the underlying EC2 compute, storage, and data transfer. These appear on the same AWS invoice. The size you pick sets both the software rate and the compute cost.
Am I charged the hourly software fee when the instance is stopped?
The software fee meters running time. A fully stopped instance does not accrue the hourly software charge. You may still pay AWS storage fees for the attached volume while the instance is stopped. Charges resume when you start the instance again.
If I move to a larger instance, does the software itself change?
No. Every instance type runs the same hardened WordPress image. Moving to a larger size only changes your hourly rate, since bigger instances provide more CPU, memory, or specialized resources. You pay the rate for whichever instance is running at that time.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Version 2 - Initial Release
Madarson WordPress V2 is a full rebuild of the Madarson hardened WordPress AMI, introducing enterprise security tooling, AI-assisted workflows, and a deterministic Security Posture scoring system as core platform features.
WHAT'S NEW IN V2
Security Hardening Stack (active from first boot, no configuration required)
AIDE: File-integrity monitoring - baselines the system at build time and flags unexpected changes, with a guided re-baseline command for legitimate updates.
auditd: Audit logging - tracks all changes to sudoers, SSH configuration, and WordPress's own configuration files.
ClamAV: Malware scanning - scheduled scans of the WordPress directory run automatically.
Security Posture Score
WordPress core and plugin versions are checked against the WPScan Vulnerability Database (bring your own free or paid token).
Combined with live OS hardening state checks into a single deterministic 0-100 score computed by fixed rules - never estimated by AI.
Scans run automatically every week and on demand from the AI Copilot dashboard.
AI Copilot (powered by your own Anthropic API key)
Content Assist: SEO meta description and image alt-text suggestions generated directly inside the block editor.
Site-Health Chat: Plain-English diagnostics grounded in real logs and system state.
Security Analyst and Security Auditor RBAC roles for scoped team access without full Administrator rights.
Base OS
Built on Madarson Hardened Ubuntu 26.04 LTS.
Apache, PHP, MySQL, and WordPress core pre-installed and running at first boot.
Staging Environment
WP Staging pre-downloaded for safe testing of changes before they go live.
Optional AWS Integrations
AWS Secrets Manager: Source the Anthropic API key from Secrets Manager via your instance's IAM Role instead of entering it in wp-admin.
Amazon CloudWatch Logs: Centralized log visibility for audit and operational monitoring.
Integrations are opt-in, controlled via /etc/madarson/madarson.env.
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
Allow inbound web access in your security group on TCP ports 80 and 443
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the EC2 with the default username: "ubuntu"
To access your site and complete the setup wizard: http://your-instance-ip/
Support for Madarson IT WordPress V2 provided via email at info@madarsonit.com. Contact us for assistance with deployment, configuration, Security Posture or Secrets Manager setup, hardening feature questions, or troubleshooting.
How to Submit a Request
When contacting support, please include:
Your EC2 instance ID
A description of the issue or question
Any relevant error messages or log output
Providing this information helps us diagnose and resolve your issue efficiently.
Private Offers and Custom Licensing
For private offers, volume licensing, or custom deployment arrangements, contact info@madarsonit.com with details about your requirements and expected usage.
About Madarson IT
Madarson IT certified images are always up to date, secure, and follow industry standards. Every image is designed to help organizations establish a strong security baseline and reduce risk exposure to common cyber threats. Madarson IT offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Hardened image with security baselines applied at first boot. This is a repackaged open source software product wherein additional charges apply for custom operational agents. Includes WAF rules, malware scanning, brute-force protection, and uptime monitoring. Secure WordPress hosting on Ubuntu 22 LTS from first boot.
Hardened image with security baselines applied at first boot. This is a repackaged open source software product wherein additional charges apply for custom operational agents. Includes WAF rules, malware scanning, brute-force protection, and performance caching. Deploy a secure, optimized WordPress site on the latest Ubuntu LTS.
This is a repackaged open source software product wherein additional charges apply for custom operational agents. Includes web application firewall rules, malware scanning, brute-force login protection, and uptime monitoring. Launch a hardened, production-ready WordPress site in minutes.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. Wordpress on Ubuntu 26 provides a robust and secure environment for hosting your blogs and websites in the AWS EC2 cloud. With its pre-configured settings, users can quickly deploy Wordpress on Ubuntu 26, ensuring optimal performance and security out of the box. Scale effortlessly to meet traffic demands while benefiting from the enhanced security features of the hardened image. Ideal for developers and businesses looking to streamline deployment, Wordpress on Ubuntu 26 supports easy updates and maintenance, making it an excellent choice for any Wordpress-powered project.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.