For site owners whose WordPress installs have grown faster than their maintenance.

Your managed host updates your plugins. It won't fix the one that breaks your site — and it won't audit the code underneath. I do. A read-only security and maintenance audit, a prioritized report, and a fixed-price quote. Then I fix the code and manage the plugins, every change shown to you first and your database backed up before anything is applied.

Get an Audit & Quote Our Trust Model

Turn the audit into a prioritized action list — then fix what it finds.

I run a read-only audit across your WordPress install, classify every finding by real risk — not just "vulnerable plugin found" — and deliver a prioritized remediation report with a fixed-price quote:

  • ✔ Fix Today: Confirmed live vulnerabilities and abandoned critical plugins.
  • ✔ Fix This Week: Outdated themes and lower-impact issues with clear remediation.
  • ✔ Log and Ignore: Confirmed noise, inactive code, and cosmetic items.

The report isn't where it ends. I fix the code and manage the plugins — starting with the Fix Today items, every change shown to you for approval first. Your database is backed up before any change that affects it.

Page-builder breakage — Elementor or Divi layouts stored as data in your database, not code — is surfaced in the report. Where it's fixable, it's done under the same backup-first rule: backed up, reviewed, then applied.

No false-positive dump. No plugin to install. No changes you didn't approve.

Sample report — illustrative PDF
High: Fix Today
plugin: wpforms-lite ≤1.9.5 (CVE-2025-3794, Stored XSS)
Warning: Fix This Week
theme: storefront 3.9.0 (Outdated, 2 releases behind)
Noise: Log & Ignore
inactive: hello.php (Default, not active)
Then: Review & Apply
fix: themes/ + plugins/ (DB backed up, changes you approve)

The Offer

Start with a read-only audit. If you accept the quote, I fix the code and manage the plugins — every change shown for approval first, with your database backed up before any change that affects it.

Baseline Audit

One-time · read-only · typically within a week

Just want to know where you stand? The full read-only audit, the triage, a prioritized remediation report, and a fixed-price quote — no obligation to proceed.

  • ✔ Deep scan of plugins, themes & core
  • ✔ Page-builder state (Elementor/Divi)
  • ✔ Options-table bloat & autoload health
  • ✔ Human-judged noise filtration
  • ✔ Prioritized remediation report
  • ✔ Fixed-price quote
Request a baseline
Recommended

Audit + Remediation

One-time · fixed price from the report

The audit, then I fix the code and manage the plugins — the Fix Today list first, every change shown for approval. Your database is backed up before any change that affects it.

  • ✔ Everything in the Baseline Audit
  • ✔ Code patches + plugin updates/removals
  • ✔ Every change shown for approval before applied
  • ✔ Database backed up before any DB-affecting change
Request audit & remediation

Trust-First Access Model

Safe & Scoped Access

The audit is read-only. The easiest path: you grant read-only SSH and I pull the database dump and wp-content myself — no technical work on your end. Prefer to keep access closed for now? Send a database dump and wp-content zip and I'll audit from that. To remediate, I need SSH access to the site, and to your Git repository if you manage source there. All credentials are scoped, time-bound, and revocable by you at any moment.

A mutual NDA is signed before any access is granted.

The Backup-First Guarantee

Your database is backed up before anything changes, and every planned change — code or database — is reviewed with you before it's applied. Nothing reaches your live site without your approval, and nothing happens without a rollback path. Plugin updates, removals, and activations do affect your database; that's why the backup and review come first.

Harvey Ramer

Who's behind Stack Restore

Harvey Ramer has spent more than 20 years building and architecting software — from solo client engagements to systems that have to stay up. Stack Restore is that engineering discipline turned on a problem nobody owns: WordPress sites that drift into disrepair and the maintenance debt no one will touch.

He audits before he quotes, backs up before he changes anything, and shows you every diff before it ships. You're hiring an engineer who treats your site like production. It is production.

Questions from site owners

What site owners usually want to know before they hand anyone access.

Will my host fix a plugin that breaks my site?

Not on a managed host. They run the infrastructure and keep your plugins updated — Kinsta even restores a backup automatically if an update fails its regression check — but fixing the code, auditing it, or changing how a plugin behaves is the developer's job, not the host's. Kinsta's own support page lists "code audits" and "any code editing" as out of scope. That's the gap I fill.

How is this different from a WordPress security scan?

A scanner lists problems and walks away. Wordfence, Sucuri, WPScan — they'll tell you a plugin is vulnerable and leave you to fix it. I run a read-only audit, judge which findings are real and which are noise, hand you a prioritized report with a fixed-price quote, and then fix the code. The scan is a list. This is a list, a price, and the work.

Do you touch my database?

Only when a change requires it, and never without a backup first. Plugin updates, removals, and activations write to the database — options, activation state, sometimes schema. So I back up your database before any change that affects it, show you what I plan to do, and apply it only after you approve. I don't do bulk round-trips that overwrite your live orders or users.

Is this a monthly maintenance plan?

It can be. The default is a one-time audit and a fixed-price remediation — but I take monthly retainers too: I run the audit on a cadence and remediate what it finds, same backup-first, review-before-write rule. What I don't sell is the flat-fee "unlimited edits" care plan with a published monthly price. The quote is still set by what the audit turns up, once or every month. Tell me which you want and I'll quote it.

What do you need from me to start?

Read-only access is enough for the audit. The easy path: you grant read-only SSH and I pull the database dump and wp-content myself. Prefer to keep access closed? Send me a database dump and a wp-content zip and I'll audit from that. A mutual NDA comes first. To remediate, I need SSH access, and access to your Git repo if you manage source there. All credentials are scoped, time-bound, and revocable by you.

Do you work on any WordPress host?

Managed hosts only, for now — Kinsta, WP Engine, Cloudways. Shared and cPanel hosting is where the messiest sites live, but it's also the slow case, and I'd rather nail one host at a time than do it badly everywhere.

Have a question I didn't answer here? Email me — I'll answer it directly.