Skip to content
Digital Security Consulting

Services

WordPress Development

Custom builds, hardening, and cleanup for sites that have been hacked or abandoned.

What you get

  • Custom theme and plugin development, no page-builder bloat
  • Malware removal and post-compromise cleanup with a root-cause report
  • Security hardening, WAF configuration and ongoing patch management
  • Performance optimisation, caching strategy and Core Web Vitals work
  • Migration, staging environments and safe deployment workflows
  • Maintenance retainers with monitoring, backups and tested restores

Outcomes

  • A site that loads fast and stays clean
  • Known root cause for a compromise, not just a removed payload
  • Updates applied on a schedule instead of after an incident
  • Backups that have been restored at least once, on purpose

Capabilities

Hacked WordPress cleanup

Malware and backdoor removal, reinfection prevention, blocklist and search-console recovery, and a written explanation of how they got in.

Custom theme and plugin development

Purpose-built code instead of a stack of plugins fighting each other. Lean, documented, and maintainable by the next developer.

WordPress security hardening

File permissions, user and role audit, login protection, secrets handling, dependency updates, and removal of the abandoned plugins doing the most damage.

Performance and Core Web Vitals

Caching layers, database cleanup, asset optimisation and hosting configuration. Measured before and after, not asserted.

Migration and hosting

Moves between hosts with rehearsed cutover, working staging environments, and deployment that does not involve editing files over FTP.

Maintenance and monitoring

Scheduled updates applied against staging first, uptime and integrity monitoring, offsite backups, and periodic restore drills.

A security firm that also builds WordPress sites

That combination is deliberate. The overwhelming majority of WordPress problems we are called about are security problems wearing a web-design costume: a site that got hacked, a site running plugins abandoned by their authors in 2019, a host nobody has logged into for two years.

Fixing the visible symptom without addressing that is billable, but it is not helpful.

Hacked site recovery

Our sequence:

  1. Preserve and assess. Snapshot the current state before changing anything, so there is evidence to work from.
  2. Find the entry point. File integrity comparison, log analysis, user and plugin audit. This step is the one most cleanup services skip, and it is the reason sites get reinfected.
  3. Clean. Remove malware, backdoors, injected content and unauthorised accounts. Replace core and plugin files from known-good sources rather than attempting to disinfect them.
  4. Close the vector. Patch or remove the vulnerable component, rotate every credential, fix the permissions or host configuration that allowed it.
  5. Recover reputation. Blocklist removal, Search Console reconsideration, and cleanup of any spam content that got indexed.
  6. Report. A written explanation of what happened and what changed.

Building new

We build custom themes and plugins rather than assembling a tower of third-party components. Every plugin is a dependency you are responsible for patching forever, and the ones that get abandoned are precisely the ones that become the entry point.

Lean code, documented, with a deployment workflow that does not involve editing files on a live server.

When WordPress is the wrong answer

Sometimes it is, and we will say so.

If your site is genuinely a brochure — services, articles, a contact form, no logins — a statically generated site is faster, cheaper to host, and has essentially no server-side attack surface to maintain. There is no database to breach and no plugin to leave unpatched. This very site is built that way.

WordPress earns its place when you need non-technical people publishing regularly, or when you need the plugin ecosystem for something specific like e-commerce or memberships. We are happy to build either. We would rather you have the right one.

Frequently asked questions

Our WordPress site was hacked. Can you clean it?

Yes, and importantly we also find the entry point. Removing the payload without closing the vector just means it comes back in a few weeks. Typical causes are an outdated plugin, a reused administrator password, a compromised hosting account, or a stale theme with a known vulnerability.

Why does WordPress get hacked so often?

Not because the core is weak, but because it is the most-deployed CMS on the internet and its plugin ecosystem has enormously variable quality. Most compromises we investigate trace to an out-of-date third-party plugin or a weak credential, not to WordPress itself.

Should we use a page builder like Elementor or Divi?

For a simple brochure site with no developer, they are defensible. If you care about page speed, maintainability or security surface, purpose-built code wins clearly. Page builders add substantial weight and another dependency to keep patched.

Can you take over a site built by someone else?

Yes. We audit what is there first — plugin inventory, custom code, host configuration, backup state — and give you a written assessment before quoting the work, so you know what you actually own.

Do you offer ongoing maintenance?

Yes, on retainer: scheduled updates tested against staging, monitoring, offsite backups and periodic restore drills. Given how most WordPress compromises happen, the maintenance is usually more valuable than the build.

Cybersecurity

Incident response, ransomware recovery, and hardening that holds up under audit.

Learn more

Software Engineering

Architecture, subscription platforms and data pipelines — built to be maintained.

Learn more

Infrastructure & Backup

Servers, clusters and backups designed so that failure is survivable and boring.

Learn more

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.