← All projects
Professional consultancy

A PHP upgrade rehearsed on a copy, and a site rebuilt as evidence

The site ran on a PHP version that no longer gets security fixes, with plugins that break on anything newer. Upgrading blind risks the live site. Not upgrading is the slower risk.

Sector
Education consultancy
Engagement
Upgrade and rebuild
Status
Upgrade proven on a copy, rebuild in progress
Our role
Upgrade, rebuild, staging process

What it does

A WordPress site on an end-of-life PHP version, upgraded only after the whole thing had been proven on a copy, and its pages rebuilt to show a track record.

An upgrade proven before it was applied

A full local copy of the site ran on each candidate PHP version, with the front end and the admin exercised on all of them.

  • Front end, admin, editors, forms and the two-factor login all tested
  • Plugin code that fails on newer PHP patched and each patch recorded
  • Every live file checksummed beforehand, so any drift or rollback is verifiable

A site that reads like a company

The aim was credibility with people deciding whether the business is real, so the evidence moved to the front.

  • Track record grouped and named rather than buried in one paragraph
  • Unneeded slider and search plugins removed, along with their attack surface
  • Styles and graphics held as real files so a visual edit cannot strip them

A safe way to ship changes

Work happens on a copy, then moves to live through a staging step that matches the real server.

  • Files pushed directly, database changes handled separately and carefully
  • Staging on the same host, so server-only bugs show up before launch

The hard parts

The problems that decided how this was built. They are the reason it works the way it does rather than the obvious way.

Upgrading plugins nobody maintains any more

The problem

Several plugins had no upgrade path to current PHP, and a routine update would overwrite any patch applied.

What we did

Each fix was kept as a patch file with its reason, and the obsolete plugin was removed rather than propped up.

The result

A short, documented list of what to re-check after any plugin update.

Built with

WordPressPHPDockerStaging environment

We don’t publish screenshots, logos or client names for this work. Much of it runs inside a business and handles sensitive data, so we describe what was built rather than who it was built for. We’re happy to walk through the detail on a call.

Ask a question

Tell us what your version of this needs to do and we’ll come back within one business day with scope, approach and a price.

What is your question about? (required)

Need something like this?

Every build on this page started as a workflow that off-the-shelf software nearly handled. Tell us where the gap is and we’ll scope what it takes to close it.