A website is not finished when it launches. It is only started.
We look after sites that are already live — updates, hardening, monitoring, backups that have actually been restored, speed and the small repairs nobody else gets round to. And when a site is down, defaced or infected, we are the people who get it back.
You do not have to host with us, and we did not have to build it.
What we do
Twelve things a live website needs, and one place to get them.
Most of these are dull, and that is the point: they are the work that stops the interesting kind of afternoon from ever happening.
Website maintenance
The standing arrangement the other eleven sit inside. Somebody whose job it is to look at your site on a schedule, rather than when you notice something.
CMS, plugin and theme updates
Applied on a copy first, with a restore point taken before anything is touched — so an update that breaks the site is a ten-minute problem instead of a lost day.
Hardening
Admin paths, file permissions, database users, disabled editors, security headers, and the accounts nobody has used since 2019. Closing doors is cheaper than watching them.
Attack protection
Rate limits on the login, bot and brute-force filtering, blocked enumeration, and the request patterns that only ever precede something worse.
Malware cleanup
Injected scripts, spam pages, redirect chains, backdoors left behind for later. Removed at the source rather than hidden, and the way in closed in the same pass.
Automatic backups
Files and database, on a schedule, kept somewhere other than the server they came from. A backup on the same machine as the site is a copy, not a backup.
Monitoring
Is it up, is it fast, is the certificate about to expire, has the DNS changed, has a page started returning something it did not return yesterday. Checked continuously, not on request.
Performance work
Measured first — images, queries, caching, blocking scripts, the plugin doing forty things to render a menu. Then fixed, then measured again, and you see both numbers.
Bug fixing
The form that stopped sending, the layout that only breaks on one phone, the checkout that fails for one payment method. Reproduced before it is fixed, so it is fixed once.
Site migration
Moving a site between hosts, domains or platforms without it going dark in between. Old addresses keep working, and mail and certificates move with it rather than after it.
Hacked site repair
Defacement, a browser warning, a blocklisting, mail going out in your name. Contained first, cleaned second, and the review requests filed once it is genuinely clean.
Restore after an incident
Getting the site back from a restore point when repairing in place would take longer than rebuilding — including from backups that were never yours to begin with.
Not sure which of these you need? Describe the site and we will tell you what it is actually missing.
Ask us — free quoteWhat actually happens
Care is a schedule, not an adjective.
Anybody can write "we keep your site secure". This is the part that is hard to write down, which is exactly why it is written down.
Continuously
Watched
- Reachability, from more than one place
- Response time, and when it changes
- Certificate validity and expiry
- DNS records, against what they were
- Pages that start answering differently
Every day
Taken and checked
- Backup of files and database, kept off the server
- Malware and integrity scan
- New accounts and role changes
- Error and failed-login volume
Every month
Applied and reported
- Core, plugin and theme updates, staged first
- A restore actually performed from a backup
- Broken links and redirect chains
- A written note of what changed and what we found
Every quarter
Reviewed
- Permissions, users and unused accounts
- Performance measured against last quarter
- Abandoned plugins and dead code removed
- The hardening list, gone through again
Which of these applies to your site is written into your agreement rather than promised here, because a schedule on a sales page is decoration and a schedule in an agreement is a commitment. Nor do you get a grade or a dial out of us: you get the findings, dated, with what we did about each. A score that flatters is a score nobody can stand behind.
Right now
Your site is down, defaced or infected.
Then the rest of this page is not what you came for. This is the part that is, and the first thing worth knowing is that almost all of it is recoverable.
If any of this is happening
- The site shows somebody else's page, or a message in a language you do not publish in
- The browser warns visitors before it will open it
- Google has flagged it, or it has dropped out of search entirely
- It redirects to somewhere you have never heard of, but only sometimes
- Customers are getting mail from your domain that you did not send
- It is timing out, or the host has suspended it
- You cannot log in, and the password reset goes to an address that is not yours
- A plugin update took it down and there is no backup you trust
What happens when you write
-
Contain
Stop the damage spreading before anything is investigated: sessions cut, credentials rotated, the site taken to a holding page if it is actively harming visitors.
-
Preserve
A full copy of the site as found, before a single file is changed. Cleaning first and looking second is how you lose the only evidence of how they got in.
-
Find the way in
Logs, file timestamps, modified core files, accounts created out of hours. A site cleaned without this is a site that will be cleaned again next month.
-
Clean and rebuild
Injected code removed, backdoors found and deleted, compromised components replaced from source rather than patched. Sometimes the honest answer is to rebuild from a clean restore point.
-
Reopen and watch
Back online with the hole closed, then watched closely for a while — and the blocklisting and browser-warning reviews filed, because a clean site nobody has re-checked is still a warning to your visitors.
-
Tell you what happened
What got in, how, what it did, what we changed, and what would stop it happening again. In writing, in plain words, whether or not you stay with us afterwards.
Write from the form at the foot of this page and say it is urgent — the first question we will ask is for the address, so send that too.
Report an emergencyHow we work
The things that make the difference, done as a matter of course.
None of the following is a tier, an add-on or a line on the quote. They are what we think looking after a site means.
A restore point before every change
Taken automatically, kept off the server, and the reason an update that goes wrong is an inconvenience rather than an incident.
Backups that have been restored
A backup nobody has ever restored is a hypothesis. We restore one on a schedule and tell you the date it last worked.
Updates staged, not fired
Applied on a copy and looked at by a person before they reach the site your customers are on.
Findings, not a score
What was checked, what it said, and what we did. No grade, no letter, no dial that is always green until the day it is not.
Named access, never shared logins
Each of us has an account of our own, with only the permissions the work needs, removed the day the work ends. One shared password is one password nobody can revoke.
Your site stays yours
Hosted wherever you like, on the platform you already have. You can stop, and nothing you need is held anywhere you cannot reach.
How it starts
Five stages, and the first one costs you nothing.
Taking over a site somebody else built is most of what we do. This is how it goes, including the part where we tell you what we found.
- 01 Look We go over the site as it stands — versions, accounts, backups, certificates, what is actually installed.
- 02 Report What we found and what it would take, in writing. Free, and yours to act on with somebody else.
- 03 Secure The urgent things first: backups working, the obvious doors shut, anything already compromised dealt with.
- 04 Settle Updates brought current on a copy, then applied. Monitoring connected. The schedule starts.
- 05 Keep The routine runs, you get the note each month, and you have somebody to write to when something is wrong.
Straight answers
The questions worth asking before you write to us.
No, and most of the sites we look after were built by somebody else. We do not need the original developer, their files or their goodwill — access to the site and the hosting is enough to start.
No. We work on the hosting you already have, including hosting we do not sell and cannot see the inside of. If moving would genuinely fix something we will say so and explain what, but it is never a condition of the work.
Not from this page, and neither can anybody else — a score on a marketing page is a guess dressed up as a measurement. What we can do is look at the actual site and send you what we found, item by item, with what each one would take to fix. That review costs nothing and you can act on it without us.
Almost never. The usual outcome is a site back online the same day or the next, cleaned at the source rather than patched over, with the way in closed so it does not happen again in a fortnight. The cases that take longer are the ones with no usable backup and a compromise that has been sitting there for months — and those are still recoverable, they just cost more time.
Usually not. Most of the work happens on a copy, and the live site only goes to a holding page if it is actively harming visitors — serving malware, sending mail in your name, or carrying a browser warning that is costing you more than an hour of downtime would.
Because we restore one, on a schedule, to somewhere that is not your live site, and the date of the last successful restore is in the note you get. An untested backup is a hypothesis, and the day you find out is the worst possible day to find out.
Updates are applied to a copy first and looked at by a person before they reach anybody's customers, and a restore point is taken before the live site is touched. When something does break — it happens, and anybody who tells you otherwise has not done this long — putting it back is minutes, and then we find out why on the copy.
An administrator account on the site and, where the work needs it, the hosting control panel — each of us with an account of our own rather than a shared login, because a shared password is one nobody can revoke. Every account is removed the day the work ends, and you can remove them yourself at any point without asking us.
A redesign, new features, new pages built from scratch, and anything that is really a development project wearing a maintenance hat. We will say so rather than let it drift into the routine, and quote it separately. Third-party licences and the hosting itself are yours either way.
Free review
Tell us about the site. We will tell you what it needs.
A few lines and the address is enough. You get a real answer from the person who would do the work — not a calendar link and a discovery call.