WordPress Web Design Services
Custom WordPress sites built on native block themes rather than a page builder and eleven plugins — because the plugin stack you inherit decides your speed, your security and your bills for years afterwards.
Four reasons people come to us about WordPress
Find yours. The scope, timeline and price are different for each.
A custom-designed WordPress site on a native block theme, with a deliberately small plugin list and content your team can edit without breaking the layout.
An owned store with no platform revenue share — products, payments, shipping, tax and a checkout designed to convert, on infrastructure you control.
Usually a builder-and-plugin weight problem rather than a hosting problem. We measure against Google's thresholds on real devices and cut what isn't earning its keep.
If your site is structurally fine and only conversion is weak, a rebuild is the expensive answer — conversion rate optimization or landing page optimization costs a fraction of one. And if you're weighing WordPress against a hosted platform, our e-commerce platform comparison puts five of them side by side honestly.
What actually changed for WordPress in 2026
Five things that decide whether a WordPress site is cheap or expensive to own. Most agencies won't raise the first two.
Block theme or page builder is the decision that sets your costs for years
Everything else on this page follows from this choice. A page builder — Elementor, WPBakery, Divi and the rest — gives you drag-and-drop editing today at the cost of a permanent dependency: the builder's markup, its addon plugins, its subscription, and a site that cannot be moved off it without rebuilding every page. A native block theme uses WordPress's own editor and theme.json, so the layout tooling is core software rather than a third-party product, and there is nothing to renew.
The old argument for builders was that core couldn't do enough. That gap has been closing fast. WordPress 7.1, due 19 August 2026, brings responsive styling and pseudo-state styling — hover, focus and active — into the Site Editor for both global styles and individual blocks, which means the two things people most often installed a builder for can now be done natively without writing CSS. New Table of Contents, Tabs and Playlist blocks are slated for the same release, replacing three more common plugin installs.
The trap: assuming a builder is reversible. It isn't. Builder markup is stored in your content, so migrating away means rebuilding pages by hand. Choose deliberately at the start; this is the single most expensive decision to change later.
Your plugin stack is your attack surface — and premium plugins are worse, not better
Patchstack's State of WordPress Security in 2026 counted 11,334 new vulnerabilities across the WordPress ecosystem during 2025, a 42% increase year on year. Of those, 91% were in plugins and 9% in themes. WordPress core had six, all low priority. So "is WordPress secure?" is the wrong question. The right question is what you installed on it.
The finding that should change how you buy: premium and freemium components made up 29% of valid vulnerability reports, but 76% of the flaws found in them were exploitable in real attacks, and premium components carried three times more known exploited vulnerabilities than free ones. Paid does not mean safer — it often means less scrutinised, because researchers can't easily read the code. Marketplace theme bundles with a dozen bundled addons are exactly this risk profile.
The practical rule: every plugin is a permanent liability with a maintenance cost. We justify each one during the build, prefer native block functionality where the two overlap, and treat "we might need it later" as a no.
"Our host handles security" is false comfort, and the numbers say so
Patchstack pentested common hosting defences — internal web application firewalls, Cloudflare and similar — against real WordPress vulnerability exploits. In the broader test, only 26% of attacks were blocked; in the narrower one focused on known exploited vulnerabilities, just 12%. Identical-looking setups performed very differently across hosts, largely down to WAF configuration.
Update discipline alone doesn't close the gap either. The weighted median time from public disclosure to first observed exploitation is five hours, roughly half of high-impact vulnerabilities are attacked within 24 hours, and 46% of vulnerabilities had no vendor patch at the moment of disclosure. Attackers also keep hammering old flaws: only four of 2025's ten most-attacked vulnerabilities were published that year, which means the sites getting hit are the ones nobody updated. Malicious uploads also nearly tripled in November and December, when traffic is high and staffing is thin.
What this changes: security is a monitored process, not a plugin or a hosting tick-box. That's what a care plan is for, and why we cap the plugin count in the first place.
WordPress 7.0 shipped the plumbing for AI and collaboration — not the finished features
WordPress 7.0 "Armstrong" was released on 20 May 2026. It landed the foundations: an AI Client in core for running AI programmatically inside WordPress, a connectors framework for authenticating to external services, the SVG Icon API, and collaboration infrastructure. WordPress 7.1 continues it with Notes gaining suggestion mode and emoji reactions, an AI Client iteration adding generation streaming and embeddings, and a new Guidelines feature that lets you encode editorial rules and brand voice into WordPress so AI assistance stays on-brand.
Be careful with what you read elsewhere, though. Several 2026 roundups state that real-time collaborative editing shipped in 7.0. It did not — it was pulled from the release over concerns about surface area, race conditions, server load and memory efficiency, and core is still deciding how it should work. Treat it as coming, not present.
Why it matters for a build: if AI-assisted editing is on your roadmap, build on core's editor now rather than a builder's proprietary canvas, because that's where these capabilities are landing.
Speed is measured on your visitors' phones, and most of the web still fails
HTTP Archive's Web Almanac found only 48% of mobile websites had good Core Web Vitals in 2025, against 56% on desktop. The bar is largest contentful paint within 2.5 seconds, interaction to next paint under 200 milliseconds, and low layout shift, assessed on the 75th percentile of real page loads — not a lab test on your laptop.
On WordPress the usual culprits are predictable: a page builder shipping heavy CSS and JavaScript on every page, a theme bundle loading sliders and icon fonts you never use, unoptimised hero images, and four plugins each adding their own scripts sitewide. Fewer moving parts is the cheapest performance strategy there is, which is the same argument as sections 01 and 02 arriving from a different direction. WordPress 7.1 also improves speculative loading defaults on sites with object and page caching, so navigation feels faster without extra plugins.
Four ways to build a WordPress site
Scroll horizontally on mobile. We build all four and recommend based on your team, not our convenience.
| Native block theme | Page builder | Classic custom theme | Headless | |
|---|---|---|---|---|
| Layout tooling | WordPress core + theme.json | Third-party plugin | PHP templates | Your front-end framework |
| Ongoing licence cost | None | Subscription | None | Hosting + build |
| Who can edit layout | Your team, in the Site Editor | Your team, in the builder | Developer | Developer |
| Front-end weight | Lightest | Heaviest | Light | Depends on build |
| Plugin dependency | Low | High | Low | Low |
| Lock-in if you leave | Minimal | Rebuild pages | Retheme | Rebuild front end |
| Gets WP 7.x editor features | Yes, natively | Partly | Partly | Editor only |
| Best for | Most business sites | Teams already fluent in one | Bespoke logic, tight design control | App-like front ends, multi-channel |
| Weakest at | Very unusual layouts | Speed, portability, cost over time | Self-service layout editing | Cost, complexity, editor preview |
Characteristics verified against WordPress core documentation and the 7.1 release roadmap, 29 July 2026. If you already run a builder site and it works, we won't insist on a rebuild — we'll tell you what it's costing you and let you decide.
Custom WordPress Design & Build
A designed site on a native block theme, with a plugin list you could read aloud.
We design the pages that carry your business, then build them as a block theme with theme.json controlling typography, colour, spacing and layout — so the design system is enforced by the site rather than by whoever edits it last. Your team gets editable sections and patterns for everyday changes, without the ability to accidentally break the layout. Every plugin is justified in writing, and native block functionality wins wherever the two overlap. Structure, headings and metadata are built for search from the architecture up, not retrofitted.
What you get
Designs approved before code, a block theme you own outright with no subscription, a documented plugin list, analytics and conversion tracking wired before launch, and a walkthrough so your team can run it. Design thinking comes from our UI/UX practice; copy from our copywriting team if you need it.
What it's not
Not a drag-anything-anywhere canvas. Block themes trade unlimited freedom for consistency and speed, and if your team genuinely wants pixel-level freedom on every page, a builder may suit you better — we'll say so rather than sell you something you'll fight. Also not a traffic service: a well-built site that nobody markets stays quiet.
Best for: businesses that want a fast, owned, low-maintenance site and can live inside a design system.
WooCommerce Store Design & Development
An owned store with no platform revenue share on your orders.
Product structure and attributes built properly so filtering and feeds work later, payment gateways configured for your regions, shipping and tax rules that produce correct totals, and cart and checkout designed against the friction that actually loses orders. WooCommerce's advantage over hosted platforms is structural: no per-order platform fee, no app-store dependency, and full control of the checkout — which is exactly what hosted platforms restrict. The trade is that the maintenance is yours, or ours.
What you get
A store you own end to end, clean product data ready for search and AI-surface visibility, and conversion thinking from our e-commerce UX practice built into the templates rather than added later.
What it's not
Not lower-effort than a hosted platform. You take on hosting, updates, security and backups — real work, and the reason our care plan exists. If you'd rather someone else carried that, Shopify is an honest recommendation and we build those too. Extension costs also add up: WooCommerce is free, but subscriptions and bookings usually aren't.
Best for: merchants who want ownership, content and commerce on one install, and no revenue share.
WordPress Redesign & Migration
Modernise or move without handing your rankings to a competitor.
Two jobs live here. Redesigning an existing WordPress site — often migrating off a page builder onto a block theme — and migrating onto WordPress from Wix, Squarespace, Shopify or a legacy custom build. Both start with a baseline and a full URL inventory, because that crawl is simultaneously the measurement record and the redirect map. Content parity is checked page by page so nothing that was ranking gets quietly deleted in the name of a cleaner layout.
What you get
A recorded baseline, a crawl-tested redirect map you keep, metadata carried across, and post-launch monitoring for 404s and index coverage. This is the same discipline described in detail on our website redesign page.
What it's not
Not free of fluctuation. Google says a medium site takes a few weeks to reindex after significant change, and no agency controls that. Builder migrations are also genuinely laborious — builder markup lives in your content, so pages get rebuilt rather than converted, and we price that honestly rather than pretending it's a theme swap.
Best for: sites three or more years old, builder sites that have become slow and expensive, and businesses leaving a closed platform.
Speed & Core Web Vitals Optimisation
Diagnosing why a WordPress site is slow, then fixing the causes in order.
We start from field data rather than a lab score, because Core Web Vitals are assessed on your real visitors. The audit inventories what's loading and where it comes from: builder CSS and JavaScript, theme bundle assets, plugin scripts running sitewide for features used on one page, unoptimised and wrongly sized images, render-blocking fonts, and leftover code from plugins removed months ago. Then we fix in impact order and re-measure against the baseline.
What you get
A prioritised findings document ranked by impact against effort, before-and-after field measurements on mid-range mobile hardware, and a written note of anything we recommend against fixing because the cost outweighs the gain.
What it's not
Not a plugin install. Caching helps, but no caching plugin fixes a builder shipping 400KB of CSS on every page — that's an architecture problem. Where the honest answer is that the site needs rebuilding rather than tuning, the audit says so and you keep the document either way. We also don't chase a perfect PageSpeed score; we target Google's actual thresholds.
Best for: sites failing Core Web Vitals, and anyone who has already bought a caching plugin and a faster host without much changing.
Custom Development & Integrations
Custom blocks, plugins and connections to the systems that run your business.
Custom blocks and patterns so editors get exactly the components your content needs, bespoke post types and taxonomies for structured content, private plugins for logic no marketplace product handles properly, and integrations to CRM, ERP, inventory, accounting and marketing systems over the REST API. Where an off-the-shelf plugin genuinely does the job, we use it — writing code you'll maintain forever to replace a well-supported plugin is not craftsmanship, it's cost.
What you get
A written technical scope before we quote, code in versioned theme files or a private plugin rather than pasted snippets, and documentation for whoever maintains it next. Related: CRM, inventory management and business automation.
What it's not
Not free of future obligation. Custom code carries maintenance as WordPress, PHP and dependencies version — WordPress 7.1 alone brings a React 19 upgrade and starts deprecating the Classic block, both of which touch custom work. We state that cost before you commit rather than after.
Best for: businesses whose requirements have outgrown plugins, and teams tired of re-typing data between systems.
WordPress Care Plan
Maintenance, security monitoring and support for sites that can't afford to break.
Core, theme and plugin updates applied on a staging copy first, off-server backups on a schedule, uptime and Core Web Vitals monitoring, vulnerability watch against your actual installed versions, hardening, and content or design changes as needed. The case for this is in the data rather than in fear: 91% of vulnerabilities are in plugins, 46% have no patch when they become public, the median time to exploitation is around five hours, and host defences blocked only 26% of attacks in testing. None of that is manageable by installing something and hoping.
What you get
A named contact, first response within 24 hours on business days, updates tested before production, a monthly summary of what was done and what was found, and a documented recovery path. Can extend to SEO, content or blogging if you want one team across the stack.
What it's not
Not a guarantee you'll never be compromised — anyone promising that is selling something. Attackers weaponise flaws within hours and nearly half arrive unpatched, so the honest promise is fast detection, tested backups and a rehearsed response, not immunity. Nor is it unlimited development hidden in a support fee: larger changes are scoped separately so the retainer stays predictable.
Best for: any WordPress site that generates revenue or leads, and every store.
In every WordPress site we build
Baseline, not upsells.
| Area | What it means in practice |
|---|---|
| Justified plugin list | Every plugin documented with why it's there and what it costs. Native block functionality preferred wherever it overlaps, because each plugin is a permanent liability. |
| Owned block theme | A theme you own outright with no licence to renew, with typography, colour and spacing governed by theme.json so the design system holds after handover. |
| Speed to the thresholds | Built and tested against LCP ≤2.5s, INP ≤200ms and low CLS on mid-range mobile hardware, using field data rather than a single lab score. |
| Mobile-first design | Designed for the phone first, then scaled up, since that's where most visitors and Google's assessment live. |
| Search-ready structure | Clean URL and heading structure, indexable architecture, structured data and metadata built in from the architecture stage, not bolted on. |
| Editable without a developer | Patterns and sections your team can rearrange for everyday updates, without the ability to break the layout. |
| Security basics | SSL, hardened configuration, least-privilege user roles, off-server backups configured and a restore actually tested before launch. |
| Analytics before launch | Tracking and conversion goals installed and verified pre-launch, so you have baseline data from day one rather than a gap. |
| Handover you can use | Written documentation plus a walkthrough session, all credentials transferred, and nothing held hostage to a retainer. |
From first call to handover
The architecture decisions come before the pretty ones, because they're the expensive ones to undo.
- Free scoping call. Thirty minutes on what the site must do, who edits it, and what exists today. If you don't need a new site, you hear that here.
- Build approach recommendation. Block theme, builder, classic or headless, in writing, with the trade-offs and the cost over three years rather than three months.
- Written scope and fixed quote. What's included, what's excluded, timeline, price. No work starts from a verbal brief.
- Architecture. Page structure, URL strategy, content model and the plugin list agreed before design begins.
- Design. Templates for the pages that matter, reviewed on real devices and signed off before code.
- Build on staging. Developed on a password-protected staging site you can review throughout, not revealed at the end.
- Pre-launch checklist. Real-device testing, speed verified against the thresholds, forms and payments tested with live low-value transactions, redirects crawl-tested if we're migrating, backups taken and a restore rehearsed, staging crawl blocks removed.
- Launch and watch. Go-live in a low-traffic window, then active monitoring for errors, 404s and performance regressions.
- Handover and support window. Documentation, training and credentials, then a post-launch support window stated in your contract, followed by an optional care plan.
What we verified, and what we won't claim
This page cites specific numbers. Here's exactly where each came from, and where our commitments stop.
Verified on 29 July 2026. The WordPress usage figures — 41.2% of all websites and a 59.1% share among sites using a detectable CMS — are W3Techs readings dated 28 July 2026. Every security figure comes from Patchstack's State of WordPress Security in 2026 whitepaper, data updated 25 February 2026: 11,334 new vulnerabilities in 2025 and the 42% year-on-year rise, the 91%/9% plugin-to-theme split with six low-priority core issues, premium components at 29% of reports with 76% exploitable and three times the known exploited vulnerabilities of free ones, 46% unpatched at disclosure, the five-hour weighted median to first exploitation, the 26% and 12% host-defence block rates, and the Q4 upload spike. Core Web Vitals pass rates (48% mobile, 56% desktop in 2025) are from HTTP Archive's Web Almanac, and the thresholds from Google's web.dev documentation. WordPress 7.0 "Armstrong" released 20 May 2026 per WordPress's own version documentation; the 7.1 date of 19 August 2026 and its planned features come from the official core roadmap.
Where we corrected the record. Several 2026 articles claim WordPress 7.0 shipped real-time collaborative editing as part of Gutenberg Phase 3. It didn't — the feature was removed from the release, and core is still resolving how it should work. We've described 7.0 as shipping the underlying infrastructure, which is what actually happened, and flagged the discrepancy rather than repeating the convenient version. Roadmap features for 7.1 are plans: WordPress states plainly that what's shared may not all make the final release.
Not independently verified. Timelines on the service cards are typical ranges from past projects, not commitments; yours goes in your scope document. The 24-hour first-response target is our own service commitment on business days, not a contractual SLA unless your agreement says so. The build-approach comparison table reflects our engineering judgement alongside documented platform behaviour — the licence, lock-in and feature rows are factual, but "front-end weight" and "best for" are informed opinion, and we've labelled them as such rather than dressing them up with invented percentages.
What we will not claim. We do not promise a conversion, traffic or ranking increase from a website build. We do not guarantee you will never be hacked — with a five-hour median to exploitation and 46% of flaws unpatched at disclosure, nobody honestly can. We do not publish prices, because a five-page site and a 2,000-product WooCommerce store aren't the same job; you get a fixed written quote after the free call with exclusions named. And we recommend against WordPress when it's wrong for you — a lean team that wants zero maintenance is usually better served by a hosted platform, and we'll say so on the call rather than after the invoice.
What we removed from this page. Earlier versions recommended named hosting companies and offered 3D and AR product configuration. Hosting recommendations date faster than we can maintain them and depend entirely on your stack, so we make them privately during scoping instead. The 3D/AR work sat outside what this page is about. Neither omission reflects a change in what we can build for you.
WordPress web design FAQs
What comes up most often on scoping calls.
Is WordPress still the right choice in 2026?
For most business websites, yes. W3Techs measures WordPress on 41.2% of all websites and 59.1% of those running a detectable CMS, which means the talent pool, plugin ecosystem and documentation are unmatched, and you own your code and data outright with no platform revenue share. Its real weakness isn't capability, it's responsibility: hosting, updates, security and backups are yours to manage. If your team is small and wants none of that, a hosted platform like Shopify is a legitimate answer and we build those too. WordPress wins when you want control, content and commerce on one install, and search-led growth.
Should you build my site with Elementor or a block theme?
A native block theme, in most cases. A page builder introduces a permanent dependency — subscription, addon plugins, and markup stored in your content that means leaving requires rebuilding every page rather than switching themes. Block themes use WordPress's own editor and theme.json, so there's nothing to renew and the front end is far lighter. The historic argument for builders was that core couldn't do enough, and that gap is closing: WordPress 7.1 brings responsive styling and hover/focus/active state styling into the Site Editor without CSS, plus Table of Contents, Tabs and Playlist blocks. That said, if your team is already fluent in a builder and productive in it, forcing a change can cost more than it saves — we'll give you the three-year cost comparison and let you decide.
Is WordPress secure?
WordPress core is. What you install on it is the risk. Patchstack's 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem during 2025 — 91% in plugins, 9% in themes, and just six in core, all low priority. The counter-intuitive finding is that paid components aren't safer: 76% of vulnerabilities found in premium and freemium products were exploitable in real attacks, and they carried three times more known exploited vulnerabilities than free ones, largely because researchers can't easily audit closed code. So security is mostly a procurement and maintenance question. Keep the plugin count low, prefer well-maintained components, apply updates on staging promptly, keep tested off-server backups, and monitor against your actual installed versions.
Doesn't my host handle WordPress security?
Far less than the marketing suggests. Patchstack pentested common hosting defences — internal WAFs, Cloudflare and similar — against real WordPress exploits and found only 26% of attacks were blocked in the broader test, and 12% in one focused on known exploited vulnerabilities. Identical-looking setups performed very differently between hosts depending on WAF configuration. Relying on updates alone doesn't close the gap either: the weighted median time from disclosure to first exploitation is about five hours, and 46% of vulnerabilities have no vendor patch when they go public. Good hosting is necessary and not sufficient — the layer that actually protects you is a small plugin surface plus monitored, staged maintenance.
How much does a WordPress website cost?
It depends on page count, design complexity, whether you're selling, how much content needs writing or migrating, and what has to integrate with what. A focused brochure site and a 2,000-product WooCommerce store with ERP integration are different projects by an order of magnitude. We quote after a free scoping call, itemized and fixed-scope, with exclusions written down. Budget for the ongoing costs too, because they're where cheap builds get expensive: hosting, any plugin or builder subscriptions, and maintenance. A block-theme build with a short plugin list is usually the lowest total cost of ownership even when it isn't the lowest quote.
How long does a WordPress site take to build?
Typical ranges from past projects: four to eight weeks for a custom design and build, five to nine for a WooCommerce store, five to ten for a redesign or migration, and one to two weeks for a speed audit. What decides whether those hold is how quickly we get your material — copy, images, brand assets, product data in a usable export, and access to hosting, DNS, analytics and any systems we're integrating — plus timely sign-off at each approval point. Projects slip waiting on content and decisions far more often than on development, which is why the scope document names who owns each input and by when.
Can I edit the site myself afterwards?
Yes, and that's a design goal rather than an afterthought. We build with patterns and editable sections so your team can change text, images, banners and page order in the Site Editor without touching code or risking the layout. Typography, colour and spacing are governed by theme.json, which means edits stay on-brand by default — you get freedom within a system rather than freedom to make the site inconsistent. Every build includes a walkthrough session and written documentation, and you receive all credentials at handover. Nothing about your site requires you to come back to us.
Can you move my site off a page builder?
Yes, and it's one of the more common requests we get, usually driven by speed or subscription cost. Be prepared for real effort though: builder markup is stored inside your post content rather than in the theme, so pages get rebuilt rather than converted. We scope it page by page, prioritise the templates and pages that carry traffic and revenue, and preserve URLs and metadata throughout with a crawl-tested redirect map where anything moves. It's genuine work, and we quote it as such — anyone describing a builder migration as a quick theme swap hasn't done one.
Do you build WooCommerce stores, and how does it compare to Shopify?
Yes, and the honest comparison comes down to ownership against convenience. WooCommerce has no per-order platform fee, gives you full checkout control, and keeps content and commerce on one install with WordPress's SEO strengths intact — but hosting, updates, security and backups are your responsibility, and paid extensions add up. Shopify handles all the infrastructure and launches faster, at the cost of subscription plus app fees, limited checkout customisation below its top tier, and building on rented land. Broadly: choose WooCommerce if you want ownership and search-led growth, Shopify if you want speed and low maintenance. Our platform comparison page covers five options side by side.
What's new in WordPress 7.0 and 7.1, and does it affect my site?
WordPress 7.0 "Armstrong" arrived on 20 May 2026 with foundational work rather than headline features: an AI Client in core, a connectors framework for external services, the SVG Icon API, and collaboration infrastructure. WordPress 7.1 is scheduled for 19 August 2026 and adds responsive and pseudo-state styling in the Site Editor, richer Notes for asynchronous review, a Guidelines feature for encoding brand voice into AI-assisted editing, new Table of Contents, Tabs and Playlist blocks, a React 19 upgrade and the start of Classic block deprecation. One correction worth knowing: despite what several articles claim, real-time collaborative editing did not ship in 7.0 — it was pulled from the release. For most site owners the practical effect is that core keeps absorbing what used to need plugins, which is a good reason to build on the block editor rather than a proprietary canvas.
Tell us what your site needs to do
Thirty minutes, no obligation. We'll recommend a build approach with the three-year cost attached — and say plainly if WordPress isn't the right platform for you.
Book a free consultationSources
- Usage statistics and market share of content management systems — WordPress at 41.2% of all sites, 59.1% CMS share (W3Techs, 28 July 2026)
- State of WordPress Security in 2026 — vulnerability counts, plugin/theme/core split, premium component findings, exploitation timing, host block rates (Patchstack)
- Version 7.0 — WordPress 7.0 "Armstrong" released 20 May 2026 (WordPress.org documentation)
- Roadmap to 7.1 — release date, responsive and pseudo-state styling, Guidelines, AI Client, new blocks, React 19 (Make WordPress Core)
- WordPress project roadmap (WordPress.org)
- Performance chapter — Core Web Vitals pass rates by device (Web Almanac, HTTP Archive)
- Core Web Vitals thresholds and the 75th-percentile assessment rule (web.dev, Google)
- Global settings and styles with theme.json (WordPress Developer Resources)
