The #apparmor for #wordpress on #apache webserver was a moderate success.
It is in complain mode and I need to do more tests like upload an image but it is reasonably simple to setup.
I think I'll lock off theme and plugin updates by default and switch them on when needed.
What is a worry is the non WordPress WSGI stuff just works with no rules. I'm not sure why.