Skip to main content

Professional services

A business owner afraid to touch their own WordPress site

The site had been built years earlier with a page builder, a stack of plugins, and a theme that stopped updating. Every small change required a developer, and every plugin update risked breaking the layout.

This is an illustrative engagement scenario based on the type of work we do. It intentionally contains no client names, quotes, or performance statistics.

The problem

  • Simple text changes had to go through a freelancer who was no longer responsive.
  • Plugin updates caused broken forms, missing images, or a white screen of death.
  • The owner had no clear login, no backups, and no idea what was actually running the site.

What we did

  1. 01

    Audited the existing site: plugins, theme, hosting, logins, and what was actually being used.

  2. 02

    Rebuilt the site on a clean, maintainable stack with version control and automated backups.

  3. 03

    Matched the existing content and URLs so search rankings and customer links stayed intact.

  4. 04

    Documented how to edit pages, publish blog posts, and request help when something is beyond the owner.

What changed

  • The owner can make routine edits without calling a developer.
  • Updates are tested and applied safely instead of avoided.
  • A clear ownership record so the site is never lost again.

In detail

The longer version

How a site gets to this state

Almost nobody sets out to build something fragile. It happens gradually. A site gets built on WordPress with a page builder because that's what was affordable at the time. A plugin gets added for a contact form, another for a slider, another for SEO, another for backups that were never tested. The theme gets customized directly rather than through a child theme, so updating it would erase the customizations.

Then the person who built it moves on. Three years later the owner has a website they're legally responsible for, technically dependent on, and functionally locked out of.

The specific fear

What stood out in this case wasn't that things were broken — it's that the owner had learned not to touch anything. A previous plugin update had taken the site down mid-morning. After that, updates stopped entirely.

That's the worst possible outcome, because unpatched plugins are exactly how small business sites get compromised. The site wasn't stable; it was frozen. Every month it sat unpatched, the risk went up while the appearance of stability stayed the same.

What the audit turned up

Twenty-plus active plugins, several abandoned by their developers years earlier. Two doing the same job. One premium plugin whose license had lapsed, meaning it would never receive another security fix.

No working backups. The backup plugin was installed and had been silently failing for over a year because its destination credentials had expired. Nobody had ever tried a restore, which is the only way anyone finds out.

No documented ownership. The domain registrar login, the hosting login, and the site admin were spread across a former employee's email, a freelancer, and a sticky note. Reconstructing that chain took longer than the technical work.

Rebuild versus repair

We don't automatically recommend rebuilding. When a site's structure is sound, cleaning up plugins and getting updates back on schedule is cheaper and less disruptive.

Here the arithmetic went the other way. Untangling a page builder's markup, replacing abandoned plugins one at a time, and testing each change against a theme that couldn't be safely updated would have cost more than starting clean — and would have left the owner with the same underlying dependency.

So the site was rebuilt on a maintainable stack, with the existing content and URLs preserved exactly so that search rankings and links customers had bookmarked kept working.

The part that actually solved it

The technical rebuild removed the risk. What removed the fear was changing who is responsible for the site.

The owner doesn't update plugins now, because there's nothing for them to update — we host it, patch it, back it up, and verify the backups restore. When something needs to change on the site, they text us and it's done that day. No login to remember, no update prompt to be afraid of.

That's the difference between a website you own and a website that owns you.

If this sounds like your site

Three questions worth answering today: Do you know where your domain is registered and who can log in? When was the last time anyone confirmed a backup actually restores? And is there any update currently sitting unapplied because someone is afraid of it?

Any 'no' or 'I don't know' is worth fixing before it becomes an emergency at the worst possible moment.

If this is close to your situation, tell us where yours differs. The first conversation costs nothing.