Rebuild
How Do I Stop My Website From Getting Hacked? | sosSTEVIE
Most sites aren't targeted, they're found by bots scanning for known holes. What actually closes them — and the architecture that removes them entirely.
You need a rebuild when the foundation is broken and a redesign when only the surface is. The honest test: if your site is invisible in search, dangerously outdated, structurally insecure, or built on something nobody can maintain, rebuild it. If it's found, fast, secure and simply looks tired, that's a redesign — and it's a fraction of the cost. sosSTEVIE diagnoses which one you're actually in before quoting either, then builds speed-first in 4 to 6 weeks.
Key takeaways
- The visible problem and the expensive problem are almost never the same problem.
- Rebuild when the foundation is broken. Redesign when only the surface is. Different purchases.
- A full custom build takes 4 to 6 weeks now, not three months. AI genuinely compressed the production work.
- The new risk is speed: sites shipped in days with dependencies nobody audited and code nobody read.
- Any agency that quotes a rebuild before diagnosing is selling you a rebuild because rebuilds are what they sell.
Do I Actually Need a New Website, or Just a Fixed One?
Most redesigns fix the thing the owner looks at every day. That’s rarely the thing that’s broken.
The story
Every redesign inquiry I get starts with a symptom the owner has been staring at for months.
“It looks dated.” “It’s not mobile friendly.” “I hate the header.” “It doesn’t reflect who we are now.”
And sometimes that’s genuinely the problem. But more often than not, when I go and look, the site is invisible, or slow, or quietly leaking every inquiry through a contact form that stopped delivering email in March. The design is fine. It’s just that nobody’s seeing it, and the four people who do can’t get a message through.
Here’s the trap: you look at your homepage every day. You’ve had eighteen months to develop strong feelings about that hero image. You have never once looked at your canonical tags, and you never will, because looking at canonical tags isn’t a thing normal people do.
So the thing you can see becomes the thing you buy. And the thing that’s actually costing you money doesn’t have a face, so it survives the rebuild untouched — and then you blame the new site.
Here’s the direct answer
You need a rebuild when the foundation is broken and a redesign when only the surface is. The honest test: if your site is invisible in search, dangerously outdated, structurally insecure, or built on something nobody can maintain, rebuild it. If it’s found, fast, secure and simply looks tired, that’s a redesign — and it’s a fraction of the cost. sosSTEVIE diagnoses which one you’re actually in before quoting either, then builds speed-first in 4 to 6 weeks.
Key Takeaways
- The visible problem and the expensive problem are almost never the same problem.
- Rebuild when the foundation is broken. Redesign when only the surface is. Different purchases.
- A full custom build takes 4 to 6 weeks now, not three months. AI genuinely compressed the production work.
- The new risk is speed: sites shipped in days with dependencies nobody audited and code nobody read.
- Any agency that quotes a rebuild before diagnosing is selling you a rebuild because rebuilds are what they sell.
The four honest reasons to rebuild
There are only four. If you’re not in one of these, you probably want a redesign, and I’ll tell you so.

1. The foundation is broken beyond economical repair. Built on a dead platform, an abandoned theme, a pile of plugins duct-taped by four different developers over a decade. At some point the cost of untangling exceeds the cost of starting again. This is a real threshold and it’s further away than most agencies claim.
2. It can’t be found. Structurally unindexable, or invisible to the answer engines now mediating a growing share of buying decisions. Sometimes this is fixable in a morning — that’s the technical audit. Sometimes the architecture itself is the problem and no amount of tuning saves it.
3. It’s a security liability. Unmaintained code, abandoned dependencies, a platform that stopped receiving patches. If your site can’t be secured, it can’t be kept. I know how that ends.
4. The business changed and the site didn’t. You sell something different now. The site describes a company that no longer exists. This one’s real, and it’s the only one on the list where “it doesn’t reflect who we are” is the actual diagnosis rather than a symptom.
Notice that “I don’t like it” isn’t on the list. That’s not me being dismissive — your taste matters and a site you’re embarrassed by is a genuine business problem. But it’s a redesign problem, and it costs a quarter as much.
Speed is not a feature
Most agencies treat performance as something you optimize at the end, if there’s budget left. That’s backwards, and it’s why so many new sites are slow within a year.
Speed is an architectural decision made on day one. It’s what you don’t install, how the templates are structured, whether your images are handled properly, whether the theme drags in 400KB of JavaScript to render a heading. You can’t bolt it on afterwards — you can only tune what you already built, and there’s a ceiling.
I build speed-first. Fewer plugins by default, because every plugin is both a performance cost and a security door. Lightweight templates. Proper image handling. Caching and CDN as part of the design, not a fix.
And where it fits the client, I build static: WordPress as a private publishing engine pushing pre-built HTML to Cloudflare’s edge. Nothing to compute, nothing to query, no PHP render — just files, served from a machine near the visitor. That architecture is both the fastest and the most secure option available, which is a rare case of not having to choose.
This matters more than it used to. Your speed is now a ranking input, a conversion input, and — increasingly — a factor in whether automated systems can crawl and process you efficiently enough to bother.
What AI actually changed
Let me be straight about this, because the market is full of nonsense in both directions.
What genuinely changed: building got much faster. Scaffolding, components, boilerplate, migrations, test coverage, accessibility passes, the tedious 60% of any build — that work compressed enormously. A build that took twelve weeks takes four to six now, and the quality floor went up, not down.
What didn’t change: none of that was ever the hard part.
The hard part is knowing what to build. What this business actually sells, who’s buying, what they need to see in the first four seconds, what’s failing now and why. AI made the typing fast. The typing was never the bottleneck — the thinking was, and it still is.
What got worse: speed created a whole new category of broken site. Sites shipped in days on dependencies nobody vetted, with code nobody read, by people who couldn’t debug it if it broke — and it will break. They look completely finished. They pass a glance. They’re a security liability with a nice hero section, and I’m starting to get calls from people who bought one, and the calls are of a type I recognize.
The gap between “looks finished” and “is finished” got much wider this year. That gap is where I lost my business, and it’s now being manufactured at scale.
So: I use AI heavily, every day, and it makes me faster and better. But nothing ships that I haven’t read, understood, and could fix at 2am. That’s not craftsmanship posturing. It’s the only thing separating a site from a liability, and you should demand it from whoever you hire, including me.
The Foundation First method
Four phases. The order is the point — it’s the same order as the Diagnostic, because it’s the order the money is in.

1. Diagnose before designing. What’s broken, what’s costing you, what’s actually fine. Half of what you were about to pay for usually turns out to be fine.
2. Build the foundation. Speed, security, crawlability, structure, schema, clean maintainable code. Nobody has ever complimented a client on their canonical tags. It’s where every dollar of results actually comes from.
3. Build for two audiences. Humans and machines. Your site is now read by answer engines that will describe you to a buyer who never visits. If it’s not structured to be read that way, you’re invisible in a conversation you can’t see happening.
4. Then make it beautiful. Genuinely — design matters, trust is visual, and an ugly site loses. But design applied to a broken foundation is a nice coat of paint on a car with no engine.
Most agencies run this backwards: design first, foundation as an afterthought, structure never. That’s why so many beautiful sites don’t ring.
Frequently Asked Questions
How do I know if I need a rebuild or just a redesign? Rebuild if the foundation is broken: unmaintainable code, structurally unfindable, insecure, or on a dead platform. Redesign if the site is found, fast and secure but simply looks tired. The reliable test is whether your problem has a visual cause — if inquiries stopped but the design didn’t change, the cause almost certainly isn’t visual, and a redesign will cost a lot to teach you that.
How long should a website take to build in 2026? My full custom builds run 4 to 6 weeks, down from the three months this used to take, because AI genuinely compressed the production work. If someone quotes you three months for a standard business site, ask what’s taking the time. If someone quotes three days, ask who’s reading the code — that’s usually the answer nobody wants to give.
Is a website built with AI any good? It depends entirely on whether a competent person read what was produced. AI writes good code and bad code with identical confidence, and it will happily pull in a dependency with a known vulnerability without mentioning it. Used well, AI makes a build faster and often better. Used as a substitute for judgment, it produces sites that look finished, pass a glance, and can’t be maintained or defended.
Should I just use a website builder instead? For a simple brochure site with a modest budget, honestly, sometimes yes — and I’ll tell you when that’s the right call rather than take the project. Builders fall down when you need real search visibility, custom functionality, integrations, genuine speed, or the ability to move later without starting again. If you’re spending real money on being found, the platform stops being incidental.
Will a new website fix my traffic problem? Only if your traffic problem was caused by your website, and often it isn’t. A rebuild fixes structural invisibility. It doesn’t fix a broken Google Business Profile, a manual penalty, a compromised domain, or the fact that you stopped publishing anything four years ago. This is exactly why I diagnose before quoting — a rebuild aimed at the wrong cause is expensive and it fails quietly.
Look before you buy
The homepage you hate might be fine. The thing that’s costing you might be a broken tag, an unreadable structure, or a form that hasn’t sent an email since March.
You’ll never spot it, because it doesn’t have a face. That’s not a failure on your part. It’s just what invisible problems are like.
Five days of diagnosis before you spend five figures on a guess.
Start with the $997 Diagnostic →
About Stevie
I built websites for a living for years. Then mine was quietly turned into a spam farm and I had to take it down.
I learned the expensive way that a site can look perfect and be fundamentally broken at the same time. Now I look at foundations first, every time, on every project.
sosSTEVIE — for when your digital presence is broken, invisible, or about to be. (754) 302-4631
Also in Rebuild
Stop guessing.
Five days. One diagnosis. A ranked list of what's broken, what it's costing you, and what to do in what order — yours to keep whether you hire me or not.
About Stevie
Three years ago my own website was taken over. It looked completely normal in my browser while tens of thousands of spam pages ran underneath it. I found out when the calls stopped, and I had to take the whole thing down.
I diagnose before I quote, because I know exactly what it costs to be certain about the wrong thing. The whole story is here.