Skip to main content
Fugen Services logo

Software Engineering

WordPress done properly, or an honest reason to leave it

WordPress powers a large share of the web for good reasons: the editor is genuinely easy, the ecosystem is enormous, and content teams already know it. It also accumulates problems faster than any other platform, because every plugin is someone else’s code running with full access to your site.

Indicative

Audit from £1,200; theme from £4,500

Fixed price agreed in writing before any build starts.

Get a quote+44 7488 265083

The problem this solves

The usual state of a neglected WordPress site is the same everywhere: thirty-odd plugins where four would do, a page builder generating a megabyte of markup, three caching layers fighting each other, and an admin account with a weak password and no rate limiting. Each was a reasonable decision at the time; together they are why the site takes six seconds to load.

What you get

Custom themes, not page builders

Built from your design with native blocks and clean templates. Page builders make the first edit fast and every subsequent change slow, and they are the single biggest cause of poor Core Web Vitals on WordPress.

Plugin reduction

Each plugin audited for whether it is used, maintained and worth its cost in load time and attack surface. Replacing five plugins with fifty lines of theme code is a common and very good trade.

Real performance work

Query profiling, image handling, caching that is configured once and correctly, and Core Web Vitals measured on a mid-range Android over 4G — not on a desktop with fibre.

Security hardening

Login rate limiting, two-factor for admins, file permissions, disabled file editing, and XML-RPC closed unless something needs it. Most WordPress compromises are brute force or an abandoned plugin, and both are preventable.

Editor experience that fits the team

Custom blocks and field groups so content can be edited safely, without anyone being able to break the layout. A CMS the team is afraid of stops being used.

Technical SEO put right

Canonical tags, schema, sitemaps and the thin auto-generated archives most WordPress sites publish by accident — tag pages, author pages, date archives — dealt with deliberately.

How we work

  1. Audit

    Plugins, theme, performance, security and SEO, with findings written down and ordered by impact.

  2. Stay-or-move recommendation

    A straight answer on whether WordPress remains the right platform for what you are doing, with the costs of each option.

  3. Staging environment

    A clone to work in, because nobody should be experimenting on a live site.

  4. Fix in priority order

    Security first, then performance, then the editor experience.

  5. Deploy and verify

    Released with measurements before and after, so the improvement is a number.

  6. Maintenance handover

    Update schedule, backup and restore procedure, and what to do when a plugin update breaks something.

What you should expect

  • Load time cut by removing work rather than adding another cache
  • Fewer plugins, so a smaller attack surface and fewer update conflicts
  • Content editable without anyone being able to break the layout
  • A clear, costed answer on whether to stay on WordPress

Built with

  • WordPress
  • PHP
  • ACF
  • WooCommerce
  • Gutenberg
  • MySQL
  • MariaDB
  • Redis
  • LiteSpeed Cache
  • Cloudflare
  • WP-CLI
  • Next.js

Mainstream, well-supported technology — chosen so you can hire for it and so another team could take the project over.

WordPress Development — your questions

Including the ones about cost, which most agencies leave off the page.

Stay if your site is mostly content, the team relies on the editor, and the problems are fixable — which they usually are. Rebuild when the site is really an application wearing a CMS: complex user accounts, custom workflows, heavy integrations. Those fight WordPress at every step, and the fighting gets more expensive over time.

An audit is £1,200 to £2,500. A custom theme from an existing design starts around £4,500. Performance and security remediation is typically £2,500 to £8,000 depending on what the audit finds. Maintenance runs from £250 per month.

Usually, substantially, and rarely by adding a plugin. The wins are almost always removing work: dropping a page builder, fixing unindexed queries, serving properly sized images, and untangling caching layers that are invalidating each other. We measure before and after so you can see what changed.

Yes. The order matters: contain, preserve evidence, find the entry point, then clean and patch. Restoring a backup without finding how they got in just reinstates the vulnerability — we have seen sites reinfected the same day that way.

It means keeping the WordPress editor but rendering the front end with something like Next.js. It buys real performance and flexibility at the cost of a more complex stack and losing live preview unless you build it. Worth it for content-heavy sites with a serious performance requirement; overkill for a ten-page brochure site.

We maintain sites that use them, but we do not build new ones that way. The markup and script they generate is the main reason page-builder sites struggle with Core Web Vitals, and the lock-in is real — the content becomes difficult to move anywhere else.

Talk to someone who has built this before

A short call is usually enough to tell you whether this is the right service for your situation — including when it is not.