WordPress custom plugin and theme rescue
For bespoke WordPress builds where the original developer has gone and the site is held together by custom code.
Most WordPress problems are solved by updating plugins and keeping things tidy. This page is for the other kind: a site built on a custom plugin, a heavily modified theme or a bespoke build, where nobody knows how it works, PHP has moved on, and an update could take the site down.
I'm not a general WordPress support service. I rescue the difficult ones.
Book a free conversationLegacy System Assessment, from £2,500
Does this sound like your site?
- A custom plugin does something important, such as bookings, memberships, pricing or integrations, and nobody understands it
- The site breaks on newer PHP, or your host is dropping the version. Host ending PHP support
- It's too risky to update WordPress or plugins, because last time something broke
- Plugins you rely on have been abandoned
- The developer who built the theme has left
- The site has been hacked, and keeps being hacked. Hacked site cleanup
- It's slow, and nobody knows why
- It holds personal data or takes payments, and nobody has reviewed the code
- A security review or insurer has flagged it
What I do
1. Inventory
I list every plugin and theme, separate third-party from custom, and check each for abandonment, known vulnerabilities and PHP compatibility. I also review the server and hosting. AI-assisted analysis speeds this up greatly, and every finding is checked on the real site. How I use AI
2. Make it safe to change
A verified backup, a staging copy and, for the custom code that matters, tests that capture how it behaves today. Then updates and fixes stop being a gamble.
3. Fix PHP compatibility
I find what breaks on modern PHP, and fix it in the custom plugin or theme, then test on a copy first. PHP upgrades
4. Review the custom code for security
Custom WordPress code is a common source of weakness. I look for the usual problems:
- Unsafe database queries
- Output that isn't escaped, which allows script injection
- Forms and actions without proper checks (nonces and permission checks)
- Insecure file uploads
- Exposed settings, keys and test files
- Over-powerful user roles
5. Replace what's abandoned
For abandoned plugins, I replace, update or rebuild, depending on what the plugin did and what the best option is.
6. Tidy and speed up
Slow queries, heavy options tables, runaway scheduled tasks, and plugins that do more than needed.
7. Document and hand over
Notes on what the custom code does, how it's deployed and what to watch. Documentation
8. Keep it maintained (optional)
Regular updates and monitoring, tested on staging before they reach the live site. Ongoing care
What typically goes wrong
- Custom code written for old PHP, with functions and patterns that no longer work
- Plugins that depend on other plugins, so one update cascades
- Direct changes to a third-party plugin or theme, which are lost on update
- Business logic buried in the theme, instead of a plugin
- Page builders and shortcodes that lock content into a tool
- Many unused plugins and users left installed
- No backups, or backups never tested
- Admin access shared, with no multi-factor authentication
When I'd say "this isn't a rescue job"
- A normal site that just needs updates. A standard WordPress support provider is cheaper and more suitable.
- The custom code is small. It may be simpler to replace it with a well-maintained plugin.
- The build no longer fits the business. Sometimes a different approach is right. Rewrite vs refactor vs upgrade
I'll tell you honestly after a first conversation.
What it costs
Fixed price, after assessment.
- Free conversation
- Legacy System Assessment, from £2,500, covering the plugins, theme, custom code, PHP, server and security
- Fixed-price quote for the work
What affects cost: amount of custom code, test coverage, number of plugins to replace, integrations and how out of date PHP and WordPress are. Direct day rate is £950; urgent work from £1,300 per day. Pricing
For agencies
A client's custom WordPress build that your team can't maintain? I can take it white-label, or direct with you as referrer. Agency terms
Frequently asked questions
Can you just update everything for me?
Not safely, on a custom build, without a safety net. I make a backup and staging copy, test the custom code, then update in steps.
Is it worth rescuing, or should we rebuild?
Often a rescue is cheaper and safer. Occasionally a rebuild is right. I'll tell you which, with evidence.
Will you lose our content?
No. Content stays where it is. The work is on code, configuration and the server.
Our site's been hacked repeatedly. Why?
Usually because the way in was never found and closed. Cleaning alone doesn't stop re-infection. Hacked site cleanup
Do you handle ordinary WordPress support, content or SEO?
No. I focus on custom code, PHP compatibility, security and rescue.
Do you need access to our live data?
Usually not. How I handle access
Tell me what you've inherited.
Tell me what the custom code does, what's broken and who built it. I'll tell you honestly whether it's a rescue job.
Book a free conversationLegacy System Assessment, from £2,500