Services
WordPress Development
Custom builds, hardening, and cleanup for sites that have been hacked or abandoned.
What you get
- Custom theme and plugin development, no page-builder bloat
- Malware removal and post-compromise cleanup with a root-cause report
- Security hardening, WAF configuration and ongoing patch management
- Performance optimisation, caching strategy and Core Web Vitals work
- Migration, staging environments and safe deployment workflows
- Maintenance retainers with monitoring, backups and tested restores
Outcomes
- A site that loads fast and stays clean
- Known root cause for a compromise, not just a removed payload
- Updates applied on a schedule instead of after an incident
- Backups that have been restored at least once, on purpose
Capabilities
Hacked WordPress cleanup
Malware and backdoor removal, reinfection prevention, blocklist and search-console recovery, and a written explanation of how they got in.
Custom theme and plugin development
Purpose-built code instead of a stack of plugins fighting each other. Lean, documented, and maintainable by the next developer.
WordPress security hardening
File permissions, user and role audit, login protection, secrets handling, dependency updates, and removal of the abandoned plugins doing the most damage.
Performance and Core Web Vitals
Caching layers, database cleanup, asset optimisation and hosting configuration. Measured before and after, not asserted.
Migration and hosting
Moves between hosts with rehearsed cutover, working staging environments, and deployment that does not involve editing files over FTP.
Maintenance and monitoring
Scheduled updates applied against staging first, uptime and integrity monitoring, offsite backups, and periodic restore drills.
A security firm that also builds WordPress sites
That combination is deliberate. The overwhelming majority of WordPress problems we are called about are security problems wearing a web-design costume: a site that got hacked, a site running plugins abandoned by their authors in 2019, a host nobody has logged into for two years.
Fixing the visible symptom without addressing that is billable, but it is not helpful.
Hacked site recovery
Our sequence:
- Preserve and assess. Snapshot the current state before changing anything, so there is evidence to work from.
- Find the entry point. File integrity comparison, log analysis, user and plugin audit. This step is the one most cleanup services skip, and it is the reason sites get reinfected.
- Clean. Remove malware, backdoors, injected content and unauthorised accounts. Replace core and plugin files from known-good sources rather than attempting to disinfect them.
- Close the vector. Patch or remove the vulnerable component, rotate every credential, fix the permissions or host configuration that allowed it.
- Recover reputation. Blocklist removal, Search Console reconsideration, and cleanup of any spam content that got indexed.
- Report. A written explanation of what happened and what changed.
Building new
We build custom themes and plugins rather than assembling a tower of third-party components. Every plugin is a dependency you are responsible for patching forever, and the ones that get abandoned are precisely the ones that become the entry point.
Lean code, documented, with a deployment workflow that does not involve editing files on a live server.
When WordPress is the wrong answer
Sometimes it is, and we will say so.
If your site is genuinely a brochure — services, articles, a contact form, no logins — a statically generated site is faster, cheaper to host, and has essentially no server-side attack surface to maintain. There is no database to breach and no plugin to leave unpatched. This very site is built that way.
WordPress earns its place when you need non-technical people publishing regularly, or when you need the plugin ecosystem for something specific like e-commerce or memberships. We are happy to build either. We would rather you have the right one.
Frequently asked questions
Our WordPress site was hacked. Can you clean it?
Yes, and importantly we also find the entry point. Removing the payload without closing the vector just means it comes back in a few weeks. Typical causes are an outdated plugin, a reused administrator password, a compromised hosting account, or a stale theme with a known vulnerability.
Why does WordPress get hacked so often?
Not because the core is weak, but because it is the most-deployed CMS on the internet and its plugin ecosystem has enormously variable quality. Most compromises we investigate trace to an out-of-date third-party plugin or a weak credential, not to WordPress itself.
Should we use a page builder like Elementor or Divi?
For a simple brochure site with no developer, they are defensible. If you care about page speed, maintainability or security surface, purpose-built code wins clearly. Page builders add substantial weight and another dependency to keep patched.
Can you take over a site built by someone else?
Yes. We audit what is there first — plugin inventory, custom code, host configuration, backup state — and give you a written assessment before quoting the work, so you know what you actually own.
Do you offer ongoing maintenance?
Yes, on retainer: scheduled updates tested against staging, monitoring, offsite backups and periodic restore drills. Given how most WordPress compromises happen, the maintenance is usually more valuable than the build.
Related services
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreSoftware Engineering
Architecture, subscription platforms and data pipelines — built to be maintained.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.