Skip to content

WordPress, built to be edited and handed over

WordPress Development Servicesthemes, plugins, stores and care, chosen on evidence

WordPress development services cover everything involved in building and running a site on WordPress: custom and block themes, plugins, WooCommerce stores, headless and multisite set-ups, migrations and redesigns, performance and security work, and ongoing maintenance.

Read more

A buyer’s guide: when a page builder is enough, which WordPress and PHP versions matter in 2026, how plugins are vetted, what moves the price, and where WordPress is the wrong tool.

  • 7+Years in digital marketing
  • 120+Brands served
  • 55+Team members
  • 250+Projects delivered
  • 100+Certifications held

Why The Adroit

  • A site you can run without us

    A well-run project leaves you with everything needed to run the site without us: the code, documentation, accounts and a plain-language guide for editors.

  • We say when WordPress is the wrong tool

    Outside that zone it gets awkward and sometimes expensive. We say so before a proposal, not after.

  • Every step ends in something to review

    Progress is reported monthly, and scope or cost changes are raised before work continues.

  • A quote after discovery

    We quote after discovery, once the content model, integrations and approach are known.

  • Security without guarantees

    These controls reduce risk; none is a guarantee, and anyone promising a site cannot be hacked is selling something.

  • A dedicated account manager

    One person to talk to, with a maximum 12-hour turnaround time (TAT).

What we build

Twelve work packages, usually scoped in combination. These six cover most projects.

  • Custom and block themes

    A theme written for your design, carrying only the templates and scripts the site uses. Editors fill structured fields.

    All twelve work packages
  • Plugin development

    Custom plugins for business logic that should outlive any theme: post types, workflows, imports and integrations.

    How plugins are vetted
  • WooCommerce

    Catalogues, checkout, payments, shipping, tax invoices and B2B price lists, with extensions chosen one by one.

    Is WooCommerce enough?
  • Headless WordPress

    WordPress as editing back end and content API (REST or WPGraphQL) with a Next.js or React front end.

    Builder, theme or headless?
  • Migrations and redesigns

    Moves from Wix, Shopify, Drupal, Joomla or older WordPress, and redesigns that must keep search visibility.

    Moving without losing rankings
  • Maintenance and support

    Updates, backups with restore tests, monitoring, small fixes and a monthly report.

    Security and maintenance

How a project runs

Eight steps, each ending in something you can review, shown here in four groups.

  1. Discovery and architecture

    We agree what the site must do, who edits it, which systems it touches and how success is measured. We map pages, content types, URLs and redirects, and decide the build approach from the table above.

  2. Design system and build

    Wireframes become components and patterns, with colours, type and spacing held in tokens. Theme, plugins and integrations are built in version control on a private staging site.

  3. Content, integrations and QA

    Content is migrated or loaded, forms and CRM connections are wired and tested. Device and browser tests, accessibility checks, performance against budgets and security checks.

  4. Launch, hand-over and care

    Redirects, DNS, analytics and monitoring are switched on with a rollback plan ready. Documentation and editor training, then maintenance with a monthly report if you choose it.

One head office, teams in more cities

Head office is in Navi Mumbai, with teams in Mumbai, Bangalore, Delhi. Projects run remotely; each page below covers the work that location sees most.

Send the current site, or just the goal. We will tell you whether a builder, a custom theme, a block theme or something else makes sense, and what it is likely to involve.

Start a conversation

Awards and Recognition

Digital Agency Network — Verified AgencyTop Clutch Web Design Company Government IndiaTop Clutch Wix Web Designers India 2026
In short

WordPress development services are the design, build, extension and upkeep of websites and stores on WordPress: custom or block themes, plugins, WooCommerce, headless and multisite set-ups, migrations, speed and security work. WordPress runs 40.2% of all websites (W3Techs, checked Oct 2026), so the real question is which build approach fits. Head office is in Navi Mumbai, with teams in Mumbai, Bangalore, Delhi.

What we build

What do WordPress development services include?

A WordPress project is rarely one thing. A marketing site, a large content archive and a B2B ordering portal run on the same core software yet need different decisions on theme architecture, plugins, hosting and governance. These are the twelve work packages we scope, usually in combination.

01

Custom themes

A theme written for your design, carrying only the templates and scripts the site uses. Editors fill structured fields.

You get: Theme code in a repository, style guide, template map

02

Block themes and patterns

Design choices held in theme.json plus block patterns, so editors assemble pages from approved parts.

You get: theme.json, pattern library, editor guide

03

Plugin development

Custom plugins for business logic that should outlive any theme: post types, workflows, imports and integrations.

You get: Plugin, inline documentation, test notes

04

WooCommerce

Catalogues, checkout, payments, shipping, tax invoices and B2B price lists, with extensions chosen one by one.

You get: Store configuration, extension list, payment test log

05

Headless WordPress

WordPress as editing back end and content API (REST or WPGraphQL) with a Next.js or React front end.

You get: API contract, front-end app, preview set-up

06

Multisite networks

Related sites sharing users, themes and governance: regions, departments, franchises, institution groups.

You get: Network architecture, role model, shared theme

07

Migrations and redesigns

Moves from Wix, Shopify, Drupal, Joomla or older WordPress, and redesigns that must keep search visibility.

You get: Redirect map, URL inventory, cutover plan

08

Performance engineering

Core Web Vitals audits, caching layers, image, font and script budgets, database clean-up.

You get: Before and after report, budget sheet

09

Security hardening

Least-privilege roles, two-factor sign-in, firewall rules, hardened permissions and tested backups, applied in the build.

You get: Hardening checklist, access register

10

Maintenance and support

Updates, backups with restore tests, monitoring, small fixes and a monthly report.

You get: Monthly report, change log

11

Integrations and APIs

CRM, ERP, payment and analytics connections through REST endpoints, webhooks and vendor APIs.

You get: Integration map, field mapping, error handling

12

Accessibility

A WCAG 2.2 AA target built into components and forms, checked with tools and by hand.

You get: Audit notes, fix list

If the real need is a bespoke application rather than a content or commerce site, our PHP development services and web development services cover Laravel, Symfony and other stacks.

Versions and requirements

Which WordPress and PHP versions should a site run in 2026?

Run the current WordPress release on a supported PHP version, with HTTPS, on a host that lets you update both. WordPress.org states that only the latest version is officially supported, so leaving a site as it is is a security decision.

FactPosition as of 2 Oct 2026Source (checked Oct 2026)
Latest releaseWordPress 7.1.2, released 22 Sep 2026 as a security fixwordpress.org/download/releases
Recent majors7.1 on 19 Aug 2026; 7.0 on 20 May 2026wordpress.org release announcements
Support policyOnly the latest version is officially supported; older branches receive backported fixes as a courtesywordpress.org/about/security
Next major7.2 is proposed for 9 Dec 2026 (a proposed date, not final)make.wordpress.org/core
Recommended serverPHP 8.3 or newer, MariaDB 10.11+ or MySQL 8.0+, HTTPSwordpress.org/about/requirements
Market positionWordPress is on 40.2% of all websites and 58.7% of sites with a known CMSW3Techs
EcosystemElementor is on 31.5% of WordPress sites; WooCommerce on 19.8%W3Techs

PHP support dates that matter to WordPress owners

Dates from php.net/supported-versions.php (checked Oct 2026).

PHP versionSupport statusWhat it means for a WordPress site
PHP 8.5Released 20 Nov 2025; active support to 31 Dec 2027, security to 31 Dec 2029Newest option. Move only after theme and every plugin are tested on it.
PHP 8.4Active support to 31 Dec 2026, security to 31 Dec 2028Sensible target for new builds with maintained plugins.
PHP 8.3Security fixes to 31 Dec 2027WordPress.org's recommended minimum; a safe floor for hosting.
PHP 8.2Security-only until 31 Dec 2026Plan the move now; support ends this year.
PHP 8.1 and olderEnd of lifeNo security fixes. Upgrade before anything else on the site.
PHP support windows relevant to WordPress sitesTimeline from 2026 to 2029. PHP 8.5: active support to 31 Dec 2027, security to 31 Dec 2029. PHP 8.4: active to 31 Dec 2026, security to 31 Dec 2028. PHP 8.3: security fixes to 31 Dec 2027. PHP 8.2: security-only to 31 Dec 2026. PHP 8.1 and older: end of life. Marker shows 2 Oct 2026.2026202720282029PHP 8.5Released 20 Nov 2025Active to 31 Dec 2027Security to 31 Dec 2029PHP 8.4New-build targetActive to 31 Dec 2026Security to 31 Dec 2028PHP 8.3Recommended minimumSecurity fixes to 31 Dec 2027PHP 8.2Plan the move nowSecurity-onlyuntil 31 Dec 2026PHP 8.1 and olderEnd of lifeNo security fixes. Upgrade before anything else on the site.2 Oct 2026Active supportSecurity fixes only PHP support windows relevant to WordPress sitesTimeline from 2026 to 2029. PHP 8.5: active support to 31 Dec 2027, security to 31 Dec 2029. PHP 8.4: active to 31 Dec 2026, security to 31 Dec 2028. PHP 8.3: security fixes to 31 Dec 2027. PHP 8.2: security-only to 31 Dec 2026. PHP 8.1 and older: end of life. Marker shows 2 Oct 2026.2026202720282029PHP 8.5Released 20 Nov 2025Active to 31 Dec 2027Security to 31 Dec 2029PHP 8.4New-build targetActive to 31 Dec 2026Security to 31 Dec 2028PHP 8.3Recommended minimumSecurity fixes to 31 Dec 2027PHP 8.2Plan the move nowSecurity-only to 31 Dec 2026PHP 8.1 and olderEnd of lifeNo security fixesActive supportSecurity fixes onlyLine: 2 Oct 2026
The PHP table above, read as a timeline (dates from php.net/supported-versions.php, checked Oct 2026). PHP 8.5 was released 20 Nov 2025, so its bar starts at the left edge.

Practical rule: ask your host for PHP 8.3 or newer, keep a staging copy, and test every upgrade there first. For a deeper view of PHP itself, see our PHP development services page.

Process

How does a WordPress project run, step by step?

Eight steps, each ending in something you can review. Progress is reported monthly, and scope or cost changes are raised before work continues.

  1. Discovery and goals

    We agree what the site must do, who edits it, which systems it touches and how success is measured.

    Deliverables: Brief, success measures, risk list

  2. Content and architecture

    We map pages, content types, URLs and redirects, and decide the build approach from the table above.

    Deliverables: Sitemap, content model, URL inventory

  3. Design system

    Wireframes become components and patterns, with colours, type and spacing held in tokens.

    Deliverables: Designs, pattern list, theme.json plan

  4. Build on staging

    Theme, plugins and integrations are built in version control on a private staging site.

    Deliverables: Staging site, repository, plugin register

  5. Content and integrations

    Content is migrated or loaded, forms and CRM connections are wired and tested.

    Deliverables: Populated site, integration test log

  6. Quality assurance

    Device and browser tests, accessibility checks, performance against budgets and security checks.

    Deliverables: QA report, fix list, performance results

  7. Launch

    Redirects, DNS, analytics and monitoring are switched on with a rollback plan ready.

    Deliverables: Launch checklist, post-launch review

  8. Hand-over and care

    Documentation and editor training, then maintenance with a monthly report if you choose it.

    Deliverables: Guides, access register, monthly report

Want this for your business? Talk to Us

Questions

FAQs

A WordPress development company designs, builds, extends and maintains sites on WordPress. That covers custom or block themes, plugins, WooCommerce stores, headless and multisite set-ups, migrations from other platforms, performance and security work, and ongoing updates. It also advises on what not to build, such as when a page builder is enough or another technology fits better. Good agencies hand over documentation and access.

WordPress.org provides the free, open-source software that you install on your own hosting. You control the code, plugins, themes and data, and you are responsible for updates, backups and security. WordPress.com is a hosted service that runs WordPress for you, with plans that limit which plugins and code changes are allowed. Custom development, WooCommerce and integrations nearly always use the self-hosted version.

Avoid WordPress when the workflow is the product, such as booking engines with complex rules, financial ledgers or collaborative real-time tools; when you hold very large, highly relational datasets; or when you want a native mobile app. A rarely changing one-pager may suit static HTML, which has less to patch and costs less to host. We will say so honestly during discovery rather than after a proposal.

It depends on scope, so we quote after discovery rather than guess. The main drivers are the number of unique templates, the content model, custom functionality, commerce rules, migration volume, integrations, performance and accessibility targets, languages, and hosting requirements. A site built from a few reusable patterns costs far less than one with many bespoke layouts. The cost table on this page shows what pushes the price up or down.

Typical ranges, which depend on scope and how quickly content and approvals arrive, are about 4 to 8 weeks for a focused marketing site, 8 to 14 weeks for a content site with custom post types and integrations, 8 to 16 weeks for a WooCommerce store, and 12 to 24 weeks for a headless build. Late content is the most common cause of delay.

There is no magic number. Each plugin adds an update to test, a vendor to trust and code on every request, so each needs a clear purpose. We check when it was last updated, active installs, support responsiveness, vulnerability history, overlap with core or other plugins, and how much code it loads. We keep a register of every plugin.

We can limit avoidable losses, but nobody can promise rankings will not move after a change. A careful migration crawls the old site, builds a one-to-one 301 redirect map, keeps titles, canonicals and structured data, tests forms and tracking, handles DNS and email cutover, and blocks staging from search. Afterwards we check Search Console for errors.

We plan to Google's good Core Web Vitals thresholds at the 75th percentile of real visits: Largest Contentful Paint 2.5 seconds or less, Interaction to Next Paint 200 milliseconds or less, and Cumulative Layout Shift 0.1 or less. Field data from Search Console or PageSpeed Insights decides pass or fail, while lab tools help find causes. We fix causes, not scores.

More questions (6)

We apply least-privilege roles, two-factor sign-in for admins, firewall and rate limiting, hardened file permissions, vetted plugins, staged updates and tested backups. These reduce risk but cannot guarantee safety. If your site is already hacked, contain it, restore a clean backup, change every password, key and salt, find the entry point (often an outdated plugin), then update everything and check search and email warnings.

A good plan typically covers core, theme and plugin updates, backups with restore tests, uptime and security monitoring, small fixes, and a monthly report of what changed. Check what is excluded, such as new features, emergency clean-up or third-party licence fees. What is included in our plans is set out in the proposal, and we report monthly.

Go headless when the front end is app-like, serves several channels, or is owned by a JavaScript team; accept that you will run two systems and rebuild previews and some plugin features. Choose Multisite when you manage related sites that share users, themes and governance, such as regions or departments. For a single marketing site, a standard install is simpler.

WordPress is open source, and the aim of a good project is that you can run the site without the agency. Our recommendation is that your domain, hosting account and plugin licences are in your name. The hand-over list, which typically includes code in a repository, documentation, admin accounts and editor guidance, is set out in the proposal so there are no surprises.

Yes, for the right projects. W3Techs reports WordPress on 40.2% of all websites and 58.7% of sites with a known CMS (checked Oct 2026), and WordPress 7.1.2 arrived on 22 Sep 2026. It suits content, marketing and commerce sites that several people edit. It is a weaker choice when custom application logic or real-time features are the core of the product.

Use a page builder when non-developers must rearrange layouts often and the design is fairly standard. Choose a custom or block theme when content is repeatable, the design is strict, or performance and long-term maintenance matter most. Elementor is on 31.5% of WordPress sites (W3Techs, checked Oct 2026), but builders tie pages to the builder. We say so plainly when the cheaper option is enough.

Read the full guide

14 sections with the detail behind this page

The detail behind this page, section by section. Open any heading to read it; everything stays on this page.

Page builder, custom theme, block theme or headless: which one fits?

Decision guide

This is one of the costliest decisions to reverse in a WordPress project. Elementor is used on 31.5% of WordPress sites (W3Techs, checked Oct 2026), so a page builder is a defensible choice, just not the only one.

ApproachChoose it whenEditing experienceSpeed and controlMain risk
Page builder (Elementor, Divi-style)Non-developers must rearrange pages often, designs are fairly standard, and budget is tight.Visual drag and drop with the widest layout freedom.Heavier markup and scripts by default; needs disciplined settings and caching.Pages become tied to the builder, so leaving it later means rebuilding them.
Classic custom theme with structured fieldsContent is repeatable, the design is strict, and editors should fill fields, not rearrange layouts.Safe and simple: editors cannot break the design.Highest control over HTML, CSS and scripts.New layouts need a developer.
Block theme with patternsEditors need layout freedom inside a defined design system, using core features over add-ons.Block editor with approved patterns and style controls.Lean when core blocks do most of the work.Needs pattern governance and training; some older plugins assume classic themes.
Headless (WordPress plus Next.js or React)The front end is app-like, serves several channels, or is owned by a JavaScript team.Familiar WordPress admin; live preview must be built.Static or edge rendering is possible; delivery is yours to design.Two systems to host; plugins that print front-end output do not carry over.

Question 1: who changes layouts?

If marketing rebuilds landing pages weekly without a developer, a builder or pattern-based block theme earns its place. If not, structured fields are cheaper and safer.

Question 2: how repeatable is the content?

Dozens of similar items (properties, doctors, courses) call for custom post types. A few one-off pages favour patterns or a builder.

Question 3: who owns the front end?

A team that ships React apps may prefer headless. A small marketing team usually should not carry that second system.

Illustrative decision path for choosing a WordPress build approachThree questions: who changes layouts, how repeatable the content is, and who owns the front end. Each answer points to a page builder or block theme, a classic custom theme, custom post types, patterns, or headless.QUESTIONANSWER AND WHERE IT POINTS1Who changeslayouts?YESMarketing rebuilds landing pages often, without a developerPage builder, or a block theme with patternsNOEditors fill fields and do not rearrange layoutsClassic custom theme with structured fields2How repeatable isthe content?YESDozens of similar items: properties, doctors, coursesCustom post typesNOA few one-off pagesPatterns or a builder3Who owns the frontend?YESA team that ships React appsHeadless may suit itNOA small marketing teamUsually should not carry a second system Illustrative decision path for choosing a WordPress build approachThree questions: who changes layouts, how repeatable the content is, and who owns the front end. Each answer points to a page builder or block theme, a classic custom theme, custom post types, patterns, or headless.1Who changes layouts?YESMarketing rebuilds landing pagesoften, without a developerPage builder, or a block themewith patternsNOEditors fill fields and do notrearrange layoutsClassic custom theme withstructured fields2How repeatable is the content?YESDozens of similar items:properties, doctors, coursesCustom post typesNOA few one-off pagesPatterns or a builder3Who owns the front end?YESA team that ships React appsHeadless may suit itNOA small marketing teamUsually should not carry a secondsystem
Illustrative. The three questions above, drawn as a path. Hybrids are common, such as a block theme with a few custom blocks.

We will tell you if the cheaper option is enough. Hybrids are common: a block theme for most pages and a few custom blocks for complex components. If search visibility drives the decision, read SEO and AI-search readiness first.

When is WordPress not the right tool?

Honest limits

WordPress handles publishing, marketing sites and conventional commerce well. Outside that zone it gets awkward and sometimes expensive. We say so before a proposal, not after.

Usually a poor fit

  • Application logic is the product. Booking engines with complex availability rules, ledgers, underwriting or anything where the workflow is the value. Use a framework such as Laravel or Rails; see PHP development and Ruby on Rails.
  • Real-time and collaborative features. Live dashboards, chat and multi-user editing at the centre of the product are better served by purpose-built back ends.
  • Heavy relational data. Millions of interlinked records with complex reporting outgrow posts and metadata tables.
  • Native mobile experiences. A WordPress site can feed an app through its API, but the app itself is a separate build; see mobile app development.

Usually a good fit

  • Marketing and brand sites that several people edit.
  • Content-heavy sites, blogs and knowledge bases.
  • Stores with a normal catalogue and common payment gateways.
  • Membership and directory sites built from maintained plugins.
  • Sites handed to an in-house team or another vendor, because WordPress skills are widely available.

A one-page brochure that changes twice a year may not need a CMS at all. A static page is cheaper to run and has less to patch.

How do you vet a WordPress plugin, and how many is too many?

Plugins

Every plugin is code you did not write, with access to your database. The useful question is not a number but a justification: what does it do, who maintains it, and could core or thirty lines of code do the same?

CheckWhat we look atRed flag
Last updatedLast release date and tested-up-to WordPress version.Long gaps, or lagging behind each WordPress major.
Active installs and ageHow widely it is used and how long it has been maintained.New plugin, few installs, security-sensitive job.
Support responsivenessWhether the author answers and fixes bugs.Unanswered threads.
Vulnerability historyPublic advisories (Patchstack, WPScan) and how fast fixes followed.Repeated serious issues or unpatched flaws.
OverlapWhether core, the theme, or another plugin already does the job.Three plugins, three slider engines.
Code and loadScripts, styles and queries added to every page; nonce and capability checks.Site-wide assets for a one-page feature.
Licence and update channelUpdate source and who holds the licence.Nulled copies; licence in a developer's personal account.
Illustrative plugin funnel from proposal to register entryA plugin is proposed, then checked: could core or thirty lines of code do it, does it pass the seven checks, is it a standard need or a unique rule. What survives is entered in the plugin register with purpose, vendor, licence holder and removal plan.A plugin is proposedWhat does it do, and who maintains it?Could core or thirty lines of code do it?If yes, no plugin is addedDrops out: core or theme alreadydoes itDoes it pass the seven checks?Updated, installs and age, support, vulnerabilities,overlap, code and load, licenceDrops out: red flags such asnulled copies or unpatched flawsStandard need, or a rule unique to you?Standard: maintained plugin. Unique: custom plugin,never inside the themeEntered in the plugin registerPurpose, vendor, licence holder, removal plan Illustrative plugin funnel from proposal to register entryA plugin is proposed, then checked: could core or thirty lines of code do it, does it pass the seven checks, is it a standard need or a unique rule. What survives is entered in the plugin register with purpose, vendor, licence holder and removal plan.A plugin is proposedWhat does it do, and who maintainsit?Could core or thirty linesof code do it?If yes, no plugin is addedDrops out: core or theme already does itDoes it pass the sevenchecks?Updated, installs and age, support,vulnerabilities, overlap, code andload, licenceDrops out: red flags such as nulled copiesor unpatched flawsStandard need, or a ruleunique to you?Standard: maintained plugin. Unique:custom plugin, never inside thethemeEntered in the pluginregisterPurpose, vendor, licence holder,removal plan
Illustrative. The vetting table and the buy-or-build table, combined into one filter. Every plugin that stays gets a register entry.

So, how many plugins is too many?

There is no safe number, only a cost per plugin: another update to test, another vendor to trust, more code on every request. A focused marketing site often runs well on a handful; a store uses more, which is fine if each has a clear job and an owner.

What it looks like when there are too many

Updates nobody dares run, two plugins fighting over one feature, and pages loading scripts for features they do not show. We keep a plugin register for every build listing purpose, vendor, licence holder and removal plan.

Buy or build?

SituationUse a maintained pluginBuild a custom plugin
Standard need (SEO, forms, caching, backups)Yes. Mature plugins are tested by many sites.Rarely worth it.
Rule unique to you (pricing, approvals, ERP import)Only if it matches without workarounds.Yes. One-job code is easier to maintain.
Needs to survive a theme changeEither.Yes, as a plugin, never inside the theme.

How fast should a WordPress site be, and how is it measured?

Performance

We plan to Google's “good” Core Web Vitals thresholds, assessed at the 75th percentile of real visits. Field data (Search Console, PageSpeed Insights) decides whether you pass; lab tests such as Lighthouse help find causes.

Loading2.5s or lessLargest Contentful Paint: when the main content appears.
Responsiveness200ms or lessInteraction to Next Paint: delay between a tap or click and the next visual update.
Stability0.1or lessCumulative Layout Shift: how much the layout jumps while loading.

Thresholds: Google Core Web Vitals documentation, checked Oct 2026. Mobile and desktop are reported separately, so we test both.

Method we follow

  1. Baseline first. Record field and lab results for the key templates (home, article or product, checkout) before touching anything.
  2. Fix the cause, not the score. Slow servers, big images, blocking scripts and heavy plugins need different remedies.
  3. Set budgets. Agree limits for images, fonts and scripts so the site does not drift.
  4. Re-measure. Field data takes weeks to update, so we report lab results at hand-over and field results monthly.

Caching layers and what each does

LayerWhat it storesNotes for WordPress
Browser cacheStatic files on the visitor's deviceLong cache lifetimes with versioned file names.
CDN or edgeStatic files, sometimes full pages, close to the visitorCheck that logged-in users, carts and checkout bypass page caching.
Full-page cacheFinished HTML for anonymous visitorsBiggest single win for content sites; exclude cart, checkout and account pages.
Object cache (Redis or Memcached)Results of repeated database lookupsHelps logged-in, WooCommerce and large admin workloads.
OPcacheCompiled PHP codeServer setting; confirm it is on and sized sensibly.
DatabaseQueries and tablesFix slow queries and autoloaded options; do not cache around a bad query.
Illustrative path of a request through WordPress caching layersA request moves from the visitor through browser cache, CDN or edge, full-page cache, OPcache, object cache and the database. Each layer stores something different, and cart, checkout and account pages bypass page caching.NEAREST TO THE VISITORMOST WORK PER REQUESTVisitorAsks for a pageBrowsercacheStatic files onthe visitor'sdeviceCDN or edgeStatic files,sometimes fullpagesFull-pagecacheFinished HTMLfor anonymousvisitorsOPcacheCompiled PHPcodeObjectcacheResults ofrepeateddatabase lookups(Redis orMemcached)DatabaseQueries andtablesCart, checkout and account pagesbypass page cachingA hit ends the request early.A miss passes it one layer deeper. Illustrative path of a request through WordPress caching layersA request moves from the visitor through browser cache, CDN or edge, full-page cache, OPcache, object cache and the database. Each layer stores something different, and cart, checkout and account pages bypass page caching.VisitorAsks for a pageBrowsercacheStatic files on thevisitor's deviceCDN or edgeStatic files, sometimes fullpagesFull-pagecacheFinished HTML for anonymousvisitorsOPcacheCompiled PHP codeObject cacheResults of repeated databaselookups (Redis or Memcached)DatabaseQueries and tablesCart, checkout and account pagesbypass page cachingA hit ends the request early.A miss passes it one layer deeper.
Illustrative. The caching-layers table drawn as the route one request can take. Order varies by host; the point is what each layer stores.

Working budgets for images, fonts and scripts

Starting rules, tuned per project, not guarantees.

Budget itemStarting rule we applyWhy
Main image (often the LCP element)One image, modern format, sized to its box, not lazy-loadedLazy-loading it delays it.
Images below the foldLazy-loaded with width and height setReserved space prevents layout shift.
FontsFew families and weights, self-hostedFewer requests, less shift.
JavaScriptLoaded only where used; third-party tags reviewed one by oneScripts usually cause poor interaction scores.

How do you keep a WordPress site secure?

Security

By removing easy routes in, limiting what a stolen account can do, and recovering quickly. These controls reduce risk; none is a guarantee, and anyone promising a site cannot be hacked is selling something.

ControlWhat we do in a buildWhy it matters
Least-privilege rolesEditors get only the capabilities they need; few administrators.A stolen editor login should not mean full control.
Two-factor sign-inRequired for administrators, offered to every user.Stolen or guessed passwords are a common way in.
Firewall and rate limitingA web application firewall at host or edge, with login and request limits.Cuts brute-force and bot traffic before WordPress runs.
Hardened filesRestrictive permissions and dashboard file editing disabled.A compromised admin cannot simply edit code.
Limited, vetted pluginsOnly plugins that pass the checks above, with a register and removal plan.Plugins are a frequent source of known vulnerabilities.
Staged updatesTested on staging for critical sites, then applied to production.Security fixes should not wait for fear of breakage.
Tested backupsOff-site copies and periodic restore tests.A backup you have never restored is a hope, not a control.
Secrets and access hygieneKeys outside the repository, unique logins, access removed when people leave.Shared passwords make incidents impossible to trace.
Illustrative layers of WordPress security controlsThree rings. Outer ring: keep easy routes closed with firewall and rate limiting, two-factor sign-in, hardened files, vetted plugins and staged updates. Middle ring: limit what a stolen account can do with least-privilege roles and access hygiene. Centre: recover quickly with tested backups.123Recover1Keep easy routes closedFirewall and rate limitingTwo-factor sign-inHardened filesLimited, vetted pluginsStaged updates2Limit what a stolen account can doLeast-privilege rolesSecrets and access hygiene3Recover quicklyTested backups, with restore testsIf hacked: contain, restore, rotate Illustrative layers of WordPress security controlsThree rings. Outer ring: keep easy routes closed with firewall and rate limiting, two-factor sign-in, hardened files, vetted plugins and staged updates. Middle ring: limit what a stolen account can do with least-privilege roles and access hygiene. Centre: recover quickly with tested backups.1231Keep easy routes closedFirewall and rate limitingTwo-factor sign-inHardened filesLimited, vetted pluginsStaged updates2Limit what a stolen account can doLeast-privilege rolesSecrets and access hygiene3Recover quicklyTested backups, with restore testsIf hacked: contain, restore, rotate
Illustrative. The security table grouped by the job each control does. These controls reduce risk; none is a guarantee.

What a good maintenance plan includes

  • Core, theme and plugin updates, with a view on which are urgent.
  • Backups with restore tests.
  • Uptime and security monitoring.
  • Small fixes and content help within an agreed allowance.
  • A periodic review of user accounts, so people who left lose access.
  • Advice on host-level issues such as PHP version and HTTPS certificates.
  • A monthly report of what changed and what needs attention.

Note: this is what to expect from any good plan. What is included in our plans is set out in the proposal.

If your site is already hacked

  1. Contain. Put the site in maintenance mode and take a snapshot for evidence.
  2. Restore. Return to a backup from before the compromise, then update everything.
  3. Rotate. Change all passwords, database credentials, API keys and salts, and remove unknown users.
  4. Find the way in. Check logs and outdated plugins, or the problem returns.
  5. Re-check search and email. Ask Google to review warnings; check that your domain is not on spam lists.

Can you move my site to WordPress without losing rankings?

Migration

We can limit avoidable loss, but no one can promise rankings will not move, because search engines re-evaluate any changed site. A careful migration removes the self-inflicted damage.

RiskWhat goes wrongHow we handle it
URL parity and redirectsOld addresses return errors; rankings and backlinks are lost.Crawl the old site, build a one-to-one 301 map, test on staging, check Search Console after launch.
Serialized dataA careless domain search-and-replace corrupts serialized settings.Use serialization-aware tools such as WP-CLI search-replace on a copy first.
DNS and email cutoverEmail stops when DNS records change.Lower TTL early, document MX, SPF and DKIM records, verify mail after cutover.
Forms and analyticsLeads go to the old inbox; tracking is missing or doubled.Test every form, re-tag analytics and consent, compare counts.
MediaBroken paths, oversized images, lost alt text.Move media into the library, regenerate sizes, keep alt text.
SEO metadata and indexingTitles, canonicals and schema vanish; or staging gets indexed.Export metadata, map it, block staging from search, re-submit sitemaps.
RollbackA failed launch has no way back.Keep the old site intact until the new one is verified.
Illustrative migration track with a rollback railFive stages: crawl and map, copy and test, prepare the switch, cut over, verify. A rollback rail underneath keeps the old site intact until the new one is verified.1Crawl and mapCrawl the old site andbuild a one-to-one 301map2Copy and testSerialization-awaresearch-replace on acopy; test forms,media and metadata onstaging3Prepare the switchLower TTL early;document MX, SPF andDKIM; block stagingfrom search4Cut overSwitch DNS withanalytics and consentre-tagged5VerifyCheck mail, forms andanalytics counts;Search Console; re-submit sitemapsRollback railKeep the old site intact until the new one is verified Illustrative migration track with a rollback railFive stages: crawl and map, copy and test, prepare the switch, cut over, verify. A rollback rail underneath keeps the old site intact until the new one is verified.1Crawl and mapCrawl the old site and build a one-to-one 301 map2Copy and testSerialization-aware search-replaceon a copy; test forms, media andmetadata on staging3Prepare the switchLower TTL early; document MX, SPFand DKIM; block staging from search4Cut overSwitch DNS with analytics andconsent re-tagged5VerifyCheck mail, forms and analyticscounts; Search Console; re-submitsitemapsRollback railKeep the old site intact until thenew one is verified
Illustrative order. The migration risk table drawn as one track, with each risk handled where it arises.

The same checklist applies whichever platform you leave. Where search traffic matters, we pair the move with our SEO services so redirects, metadata and tracking are reviewed by the same people.

Is WooCommerce good enough for a growing store?

WooCommerce

For many stores, yes. WooCommerce runs on 19.8% of WordPress sites (W3Techs, checked Oct 2026) and you own the data. It asks more than a hosted store: you manage hosting, updates and security.

What we plan for

  • Extensions chosen deliberately. One job per extension, tested together on staging.
  • Dynamic pages. Cart, checkout and account pages cannot use the same full-page caching as articles, so they are excluded and tuned separately.
  • Compatibility before upgrades. Before WooCommerce or PHP updates, we check payment, shipping and order-related extensions on staging.
  • Checkout testing. Real transactions, failed payments, refunds, tax and emails, on mobile first.

When another platform may be simpler

If you want a standard store with no hosting or plugin management, a hosted commerce platform can be less work. Choose WooCommerce when content and commerce live together, when you need custom rules, or when ownership and flexibility outweigh convenience.

A useful test: if nobody can be named to handle updates, backups and payment-extension changes, budget for a maintenance plan or pick a hosted platform.

Store needUsually covered byNotes
Catalogue, variants, basic checkoutWooCommerce coreFine for most small and mid-sized catalogues.
Local payment gateways, UPI, cardsGateway extension from the providerTest live-mode transactions, refunds and failures.
GST-friendly invoicesExtension or small custom codeInvoice fields and tax display depend on your accountant's requirements.
Wholesale price lists, minimum quantitiesExtension, sometimes custom pluginCovered in depth on our Navi Mumbai page.
ERP, shipping or CRM syncIntegration plugin or custom connectorPlan for failed syncs and retries.
Where each WooCommerce store need is usually coveredA matrix of five store needs against WooCommerce core, extensions and custom code. Catalogue and basic checkout sit in core. Payment gateways are an extension. GST invoices and wholesale price lists are extensions, sometimes with custom code. ERP, shipping or CRM sync uses an integration plugin or a custom connector.WooCommercecoreExtensionCustom codeUsually covered byCatalogue, variants, basiccheckoutWooCommerce coreLocal payment gateways, UPI,cardsGateway extension from theproviderGST-friendly invoicesExtension or small custom codeWholesale price lists, minimumquantitiesExtension, sometimes custompluginERP, shipping or CRM syncIntegration plugin or customconnectorUsual routeSometimes, or an alternative Where each WooCommerce store need is usually coveredA matrix of five store needs against WooCommerce core, extensions and custom code. Catalogue and basic checkout sit in core. Payment gateways are an extension. GST invoices and wholesale price lists are extensions, sometimes with custom code. ERP, shipping or CRM sync uses an integration plugin or a custom connector.CoreExt.CustomCatalogue, variants,basic checkoutWooCommerce coreLocal paymentgateways, UPI, cardsGateway extension from the providerGST-friendly invoicesExtension or small custom codeWholesale price lists,minimum quantitiesExtension, sometimes custom pluginERP, shipping or CRMsyncIntegration plugin or custom connectorUsual routeSometimes, or an alternative
The store-need table as a matrix: how far each need usually sits from WooCommerce core. Invoice fields and tax display depend on your accountant’s requirements.

How much does a custom WordPress website cost?

Cost and engagement

It depends on scope, and a price before discovery is a guess. We quote after discovery, once the content model, integrations and approach are known. The table shows what moves the number, so two quotes can be compared fairly.

Cost driverPushes cost upKeeps cost down
Design and templatesMany unique layouts and custom animation.A small set of reusable patterns.
Content modelMany content types, relationships and custom fields.A few well-defined post types.
FunctionalityCustom plugins, calculators, member areas, workflows.Mature plugins that match the need without workarounds.
CommerceSubscriptions, B2B rules, ERP sync.Standard catalogue and a common gateway.
Migration volumeThousands of pages, many redirects.Clean exports and a pruned content list.
IntegrationsSeveral systems with two-way sync, or multiple languages.One-way lead push to a single CRM.
Performance and accessibility targetsStrict budgets across many templates.Targets set early so they shape the build.
Hosting and complianceHigh availability, data residency.Managed WordPress hosting.

Engagement models

General descriptions; terms for a project are agreed in the proposal.

ModelHow it worksFits whenWatch out for
Fixed scopeAgreed deliverables for an agreed fee.Requirements are clear and unlikely to change.Changes need a change request.
Time and materialYou pay for the effort used, within an agreed budget range.Scope will evolve.Needs active prioritisation on your side.
Dedicated team or retainerSet capacity over months.Continuing roadmap, maintenance and growth work.Value depends on a steady backlog.

How long does a WordPress build take?

Typical industry ranges, not promises.

Project typeTypical range (scope-dependent)What stretches it
Focused marketing site on a custom or block themeAbout 4 to 8 weeksLate content, many stakeholders.
Content site with custom post types and integrationsAbout 8 to 14 weeksArchive migration, CRM work.
WooCommerce storeAbout 8 to 16 weeksCustom pricing, ERP sync.
Headless buildAbout 12 to 24 weeksPreview and two codebases.
Migration of an existing mid-sized siteAbout 3 to 8 weeksRedirects, content quality, tracking.
Typical WordPress build durations in weeks, by project typeRange bars on a 0 to 24 week scale: focused marketing site 4 to 8 weeks; content site 8 to 14; WooCommerce store 8 to 16; headless build 12 to 24; migration of a mid-sized site 3 to 8.04812162024WeeksFocused marketing site on a customor block themeAbout 4 to 8 weeksContent site with custom post typesand integrationsAbout 8 to 14 weeksWooCommerce storeAbout 8 to 16 weeksHeadless buildAbout 12 to 24 weeksMigration of an existing mid-sizedsiteAbout 3 to 8 weeks Typical WordPress build durations in weeks, by project typeRange bars on a 0 to 24 week scale: focused marketing site 4 to 8 weeks; content site 8 to 14; WooCommerce store 8 to 16; headless build 12 to 24; migration of a mid-sized site 3 to 8.04812162024Focused marketing site on a custom orblock theme4 to 8 weeksContent site with custom post types andintegrations8 to 14 weeksWooCommerce store8 to 16 weeksHeadless build12 to 24 weeksMigration of an existing mid-sized site3 to 8 weeks
The duration table as range bars. Typical industry ranges, scope-dependent, not promises.

Is WordPress SEO-friendly, and is it ready for AI search?

What accessibility standard do you build to?

Accessibility

Our target is WCAG 2.2 level AA. It is a target we design and test for, not a certification claim, because automated tools find only part of the problems and real conformance depends on content added after launch.

Accessibility is cheapest when it shapes components from the start.

What gets checked

  • Keyboard use of menus, forms, sliders and modals.
  • Visible focus and a skip link.
  • Colour contrast in text, buttons and states.
  • Alt text, captions and form labels with clear errors.
  • Target size and the new WCAG 2.2 criteria, such as accessible authentication and consistent help.
  • Screen-reader spot checks on key journeys.

Do I own the code, theme and content, and can I leave?

Ownership

You should be able to. WordPress is open source, and a well-run project leaves you with everything needed to run the site without us: the code, documentation, accounts and a plain-language guide for editors. The exact hand-over list is set out in the proposal.

Our recommendation is that the domain, hosting account and plugin licences are registered in your name from day one, so nothing depends on a vendor's personal login.

Hand-over checklist, as typically agreed

  • Theme and custom plugin code in a repository you can access.
  • Documentation of structure, patterns and integrations.
  • Admin accounts, hosting, DNS and licence details transferred to you.
  • Plugin register with vendors and renewal dates.
  • Editor training or a recorded walkthrough.
  • Backup and restore instructions.
What you receive at hand-overSix hand-over items: code in a repository, documentation, accounts and licences, plugin register, editor training and backup and restore instructions. Domain, hosting account and plugin licences are recommended to be in your name from day one.IN YOUR NAME FROM DAY ONE (OUR RECOMMENDATION)Domain · hosting account · plugin licencesHANDED OVER, AS TYPICALLY AGREEDCodeTheme and custom plugin codein a repository you canaccessDocumentationStructure, patterns andintegrationsAccounts and licencesAdmin, hosting, DNS andlicence details transferredto youPlugin registerVendors and renewal datesEditor trainingTraining or a recordedwalkthroughBackup and restoreInstructions for backing upand restoring What you receive at hand-overSix hand-over items: code in a repository, documentation, accounts and licences, plugin register, editor training and backup and restore instructions. Domain, hosting account and plugin licences are recommended to be in your name from day one.IN YOUR NAME FROM DAY ONE(our recommendation)Domain, hosting account, plugin licencesHANDED OVER, AS TYPICALLY AGREEDCodeTheme and custom plugin code in arepository you can accessDocumentationStructure, patterns andintegrationsAccounts and licencesAdmin, hosting, DNS and licencedetails transferred to youPlugin registerVendors and renewal datesEditor trainingTraining or a recorded walkthroughBackup and restoreInstructions for backing up andrestoring
The hand-over checklist as a package. The exact list is set out in the proposal.

Which industries do you build WordPress sites for?

Industries

The Adroit has worked with 120+ brands, and the list below shows the patterns we see most. See the work we have published and our clients page.

Education and institutions

Catalogues, department networks, publishing.

Healthcare

Directories, appointment enquiries, accessible content.

Real estate

Listing templates, enquiry routing, map search.

Manufacturing and B2B

Catalogues, downloads, quote requests.

Media and publishing

Editorial workflows, large archives.

Professional services

Service pages, insights hubs, lead capture.

Retail and D2C

WooCommerce stores, campaign pages.

Associations and nonprofits

Memberships, events, donations.

Software and SaaS

Marketing sites, documentation, headless.

Not sure which approach fits?

Send the current site, or just the goal. We will tell you whether a builder, a custom theme, a block theme or something else makes sense, and what it is likely to involve.

Start a conversation

Where is the WordPress team based?

Locations

Head office is in Navi Mumbai, with teams in Mumbai, Bangalore, Delhi. Projects run remotely; each page below covers the work that location sees most.

Schematic of the WordPress team locationsNavi Mumbai is the head office, linked to teams in Mumbai, Bangalore, Delhi. Projects run remotely anywhere in India.New DelhiMumbaiTeamNavi MumbaiHead officeBangaloreNavi Mumbai: head officeCatalogue sites, quote forms and B2B ordering;the engineering team works from hereMumbaiContent-heavy sites with editorial workflowsBangaloreHeadless WordPress, design systems and SaaSmarketing sitesNew DelhiMultisite networks, approval workflows andaccessible publishing Schematic of the WordPress team locationsNavi Mumbai is the head office, linked to teams in Mumbai, Bangalore, Delhi. Projects run remotely anywhere in India.Navi Mumbai (head office)New DelhiMumbaiBangaloreNavi Mumbai: head officeCatalogue sites, quote forms and B2Bordering; the engineering team works fromhereMumbaiContent-heavy sites with editorial workflowsBangaloreHeadless WordPress, design systems and SaaSmarketing sitesNew DelhiMultisite networks, approval workflows andaccessible publishing
Schematic, not to scale. Head office in Navi Mumbai, with teams in Mumbai, Bangalore, Delhi; projects run remotely.

Not sure which approach fits?

Send the current site, or just the goal. We will tell you whether a builder, a custom theme, a block theme or something else makes sense, and what it is likely to involve.

Talk to UsCall +91 91521 91510

What's More

How Are We Different?

Dedicated Account Manager

SEO Enabled Websites

Responsive Websites

Site Security Upgrades & Maintenance

Website Speed & Performance Optimization

Timely Delivery

Easy to use CMS

Google PSI Score Above 80

Maximum 12 Hours TAT

Secured & Optimised Website Delivery

15 Days Cooling Period

Your Success, Our Reputation

120+ brands have trusted us with their marketing and websites over 7+ years.
Here are some of the clients we have worked with.

Latest and Greatest Posts

View All blog posts

The Adroit Reviews

Rated 5.0 from 19 client reviews on Clutch. Read our Clutch profile

Contact Us for More

We've worked with clients of all sizes, all across the World. Starting from enterprises to startups. Let's talk about your project and how we can help provide value to it on Digital.

Work That Works

A selection of recent campaigns, websites, reels and emailers delivered for our clients.

Related work from our portfolio:

Last updated:

Hello!

We'd love to show you how you can get more traffic and leads

WhatsApp us