Your managed host updates your plugins. It won't fix the one that breaks your site — and it won't audit the code underneath. I do. A read-only security and maintenance audit, a prioritized report, and a fixed-price quote. Then I fix the code and manage the plugins, every change shown to you first and your database backed up before anything is applied.
I run a read-only audit across your WordPress install, classify every finding by real risk — not just "vulnerable plugin found" — and deliver a prioritized remediation report with a fixed-price quote:
The report isn't where it ends. I fix the code and manage the plugins — starting with the Fix Today items, every change shown to you for approval first. Your database is backed up before any change that affects it.
Page-builder breakage — Elementor or Divi layouts stored as data in your database, not code — is surfaced in the report. Where it's fixable, it's done under the same backup-first rule: backed up, reviewed, then applied.
No false-positive dump. No plugin to install. No changes you didn't approve.
Start with a read-only audit. If you accept the quote, I fix the code and manage the plugins — every change shown for approval first, with your database backed up before any change that affects it.
Just want to know where you stand? The full read-only audit, the triage, a prioritized remediation report, and a fixed-price quote — no obligation to proceed.
The audit, then I fix the code and manage the plugins — the Fix Today list first, every change shown for approval. Your database is backed up before any change that affects it.
The audit is read-only. The easiest path: you grant read-only SSH and I pull the database dump and wp-content myself — no technical work on your end. Prefer to keep access closed for now? Send a database dump and wp-content zip and I'll audit from that. To remediate, I need SSH access to the site, and to your Git repository if you manage source there. All credentials are scoped, time-bound, and revocable by you at any moment.
A mutual NDA is signed before any access is granted.
Your database is backed up before anything changes, and every planned change — code or database — is reviewed with you before it's applied. Nothing reaches your live site without your approval, and nothing happens without a rollback path. Plugin updates, removals, and activations do affect your database; that's why the backup and review come first.
Harvey Ramer has spent more than 20 years building and architecting software — from solo client engagements to systems that have to stay up. Stack Restore is that engineering discipline turned on a problem nobody owns: WordPress sites that drift into disrepair and the maintenance debt no one will touch.
He audits before he quotes, backs up before he changes anything, and shows you every diff before it ships. You're hiring an engineer who treats your site like production. It is production.
What site owners usually want to know before they hand anyone access.
Not on a managed host. They run the infrastructure and keep your plugins updated — Kinsta even restores a backup automatically if an update fails its regression check — but fixing the code, auditing it, or changing how a plugin behaves is the developer's job, not the host's. Kinsta's own support page lists "code audits" and "any code editing" as out of scope. That's the gap I fill.
A scanner lists problems and walks away. Wordfence, Sucuri, WPScan — they'll tell you a plugin is vulnerable and leave you to fix it. I run a read-only audit, judge which findings are real and which are noise, hand you a prioritized report with a fixed-price quote, and then fix the code. The scan is a list. This is a list, a price, and the work.
Only when a change requires it, and never without a backup first. Plugin updates, removals, and activations write to the database — options, activation state, sometimes schema. So I back up your database before any change that affects it, show you what I plan to do, and apply it only after you approve. I don't do bulk round-trips that overwrite your live orders or users.
It can be. The default is a one-time audit and a fixed-price remediation — but I take monthly retainers too: I run the audit on a cadence and remediate what it finds, same backup-first, review-before-write rule. What I don't sell is the flat-fee "unlimited edits" care plan with a published monthly price. The quote is still set by what the audit turns up, once or every month. Tell me which you want and I'll quote it.
Read-only access is enough for the audit. The easy path: you grant read-only SSH and I pull the database dump and wp-content myself. Prefer to keep access closed? Send me a database dump and a wp-content zip and I'll audit from that. A mutual NDA comes first. To remediate, I need SSH access, and access to your Git repo if you manage source there. All credentials are scoped, time-bound, and revocable by you.
Managed hosts only, for now — Kinsta, WP Engine, Cloudways. Shared and cPanel hosting is where the messiest sites live, but it's also the slow case, and I'd rather nail one host at a time than do it badly everywhere.
Have a question I didn't answer here? Email me — I'll answer it directly.