WordPress Developer — Themes, Plugins, WooCommerce & Security.
Custom themes and plugins, WooCommerce stores, malware removal, performance work and ongoing maintenance. 50+ plugins built, 700+ sites delivered.
WordPress powers a huge share of the web and most of those sites are slower, less secure and harder to edit than they need to be. The pattern is familiar: a heavy multipurpose theme, thirty plugins where six would do, no update discipline, and a page builder that produces markup nobody can maintain.
I build WordPress the way it works best — a purpose-built theme, custom functionality in small focused plugins rather than a pile of third-party ones, and a genuinely editable content structure so you are not calling a developer to change a headline.
And when something has already gone wrong — malware, a white screen, a site that takes eight seconds to load — that is fixable too, usually faster than people expect.
All WordPress work.
Custom theme development
Purpose-built themes with clean markup, real editability and no page-builder debt.
Plugin development
Custom functionality in focused, well-scoped plugins that survive core and theme updates.
WooCommerce stores
Full ecommerce builds — payments, shipping, tax, subscriptions and checkout optimisation.
Malware removal
Infected sites cleaned, de-listed from blacklists and hardened against the same entry point.
Performance optimisation
Core Web Vitals work — caching, query tuning, asset diets and image pipelines.
Security hardening
Access control, file permissions, plugin auditing and monitoring that catches problems early.
Migrations
Host moves, domain changes and platform migrations with no lost content or broken URLs.
Maintenance & support
Updates applied safely, backups verified, issues fixed — ongoing rather than emergency-only.
How I approach it.
Fewer plugins, better site
Every plugin is code you did not write, running on every page load, with its own update cycle and its own vulnerability history. Replacing six plugins with a hundred lines in one custom plugin usually makes a site faster, safer and easier to maintain simultaneously. Plugin count is one of the most reliable predictors of how much trouble a WordPress site is in.
Page builders are a debt, not a shortcut
Builders make the first version fast and every version after it slow. The markup is heavy, the content is locked into the builder's format, and switching later means rebuilding. I use native blocks and custom fields instead, which stay editable without holding your content hostage.
Editability is a design requirement
A site the client cannot edit goes stale, and a stale site stops ranking. Content structure gets designed alongside the visual design, so text, images and sections are all editable without breaking layout — and without giving a non-technical editor enough rope to destroy the page.
Updates are a routine, not an event
The reason sites get hacked is almost never a sophisticated attack. It is a known vulnerability in a plugin that had a fix available for eight months. A regular tested update routine removes most of your real risk, and it takes very little time when it is done consistently.
The process.
Listen
A 30-minute call to understand the problem behind the brief. The fix is often not what you first ask for.
Quote
A real number tied to a real scope — never a copy-paste price list. Sent within 24 hours.
Build
I work in staging, in your repo, with commits you can audit. I send a daily update so you are never wondering.
Deliver
Smoke test together, document, deploy. Then I stick around to catch the edge cases.
How I work.
- Staging environment for every change, never edits on live
- Minimal plugin footprint with custom code where it is cleaner
- Native blocks and custom fields instead of builder lock-in
- Content structure designed for real editability
- Performance measured before and after, not assumed
- Documentation and a short handover walkthrough
Questions, answered.
Can you work on my existing WordPress site?
Yes — most of my WordPress work is on existing sites. I start with a short audit so we both know what state it is in before deciding what to change.
Do you use Elementor, Divi or WPBakery?
I can work with them when a site already uses one, but I do not build new sites on them. They produce heavy markup and lock your content into a proprietary format. Native blocks with custom fields gives you the same editing freedom without the debt.
How fast can a hacked site be cleaned?
Usually within 24 hours, often the same day for a straightforward infection. Blacklist removal from Google can take an extra day or two after the cleanup, since that depends on their re-review.
Will you look after the site after launch?
If you want. Ongoing maintenance covers updates, backups, monitoring and fixes. Plenty of clients take the site and manage it themselves, which is fine — the handover includes what you need to do that.
Related services.
WordPress Web Design & Custom Theme Development
Custom WordPress web design and theme development. Fast, mobile-first, genuinely editable sites built to rank — no bloated themes, no page-builder lock-in.
Read moreWooCommerce Development & Store Optimisation
WooCommerce development and optimisation. Fast product pages, short checkout, correct tax and shipping, subscriptions, abandoned-cart recovery and GA4 tracking.
Read moreWordPress Security Hardening & Audit
WordPress security hardening and audit. Access control, plugin vulnerability auditing, file permissions, firewall rules and file integrity monitoring.
Read moreWordPress Maintenance & Care Plans
WordPress maintenance plans: tested updates via staging, verified off-site backups, uptime and error monitoring, security alerts and small fixes included.
Read moreNeed this built?.
Tell me what you need. I send a real quote based on your specific project — never a fixed price for a problem I have not heard.
Or book a slot directly — cal.com/