Frequently Asked Questions

The questions I get asked most often, grouped the way buyers actually ask them. Every answer has its own link, so you can send someone straight to the one that matters.

Getting Started

How engagements begin, who you work with, and what kind of businesses are a fit.

What services does Kevinleary.net provide?

I provide senior WordPress, analytics and AI expertise embedded directly in your team, on retainer, for the long term. The work covers custom WordPress development, enterprise CMS and headless builds, analytics and tag management, SEO and AI visibility, security and performance, privacy and consent compliance, accessibility, BigQuery data engineering, custom eCommerce and digital growth consulting. All of it is done by one senior engineer rather than split across vendors or handed between departments.

Is the initial consultation free?

Yes. The first conversation is a short consultation to understand your goals and confirm the work is a fit. Deeper reviews such as theme audits, GTM container audits or a BigQuery warehouse diagnostic are paid engagements, and you receive a written assessment and roadmap from those whether or not we continue together.

How is this different from hiring an agency?

With an agency you get layers: an account manager relaying updates, junior developers doing the work and a senior person reviewing it occasionally. With me you work directly with the senior engineer doing the work, which means faster decisions, clearer communication and no handoffs between strategy and implementation. The scope is comparable to an agency; the overhead is not.

What kinds of businesses do you work with?

Mostly organizations whose website is business-critical and often audited: banking and credit unions, insurance, fintech, healthcare and pharma, publishers and subscription media, universities, B2B software and manufacturers with compliance obligations. The common thread is a marketing or product team that needs a senior technical partner they can rely on for years rather than a vendor for one project.

Is my company too small, or too large, to work with you?

Size matters less than the shape of the need. The best fit is a team that has real technical work every month across WordPress, analytics, security or data, and wants one senior person accountable for all of it. Very small sites with occasional needs are usually better served by a maintenance plan from their host; very large organizations tend to work with me as a fractional specialist alongside their in-house teams.

Do you take on one-off projects, or only ongoing retainers?

Most of my client relationships are monthly retainers, and that is the model I recommend because the work compounds: security, compliance, analytics and performance all decay without upkeep. Standalone projects such as a rebuild, a migration, an audit or a consent implementation do happen, and many of them turn into retainers once the launch is behind us.

How soon can you start?

It depends on current commitments. I deliberately limit the number of clients I support at once so every engagement gets real attention, which means start dates vary. Urgent, well-defined work such as a security finding or a launch deadline can often be fit in quickly; a new retainer or a full rebuild is scheduled around existing obligations. The intro call is the fastest way to get a real answer.

Do you work with agencies?

Yes. The most common arrangement is building custom WordPress themes from an agency's detailed Figma designs: pixel-accurate implementation of layout, typography and components, the animation and interaction work, an ACF block system so the client's editors can compose pages after launch, and performance, accessibility and security handled as part of the build rather than fixed afterward. I work in the agency's repositories and tools, hit their launch dates and hand off documented code. Direct client relationships remain the core of the practice, so agency projects are scheduled around retainer commitments.

Do you work on platforms other than WordPress?

WordPress is the core of the practice, but not the limit of it. I build headless stacks with Strapi, Payload, Ghost or Craft behind Next.js or React frontends, custom PHP and Laravel applications, and the analytics, warehouse and advertising systems around any website regardless of platform. Hosted page builders such as Wix or Squarespace are not something I build on, though I can integrate tracking and data around them.

Retainers & Working Together

How the retainer model works, communication, response times, reporting and team integration.

How does a monthly retainer work?

A retainer reserves a standing block of my time each month for your business, scoped to the estimated level of effort your site and stack need. It covers the recurring work (update cycles, monitoring, security scans, compliance checks) plus whatever else comes up that month: new features, fixes, tracking changes, performance work or urgent same-day requests. You get a senior engineer who knows your codebase and your goals, available on a predictable basis, without hiring a full-time employee.

What does a WordPress maintenance retainer include?

A typical month includes plugin, theme, WordPress core and PHP update cycles applied locally, verified on staging and then deployed to production; daily vulnerability scanning with every alert reviewed by hand; error log triage before notices become outages; backup verification and a tested restore path; uptime, SSL and vulnerability monitoring with real alert triage; and a written monthly report of what changed, what was found and what I recommend next. Remaining time goes toward whatever else you need that month.

What are your response times, and do you offer an SLA?

Retainer clients get defined response windows written into the agreement, and same-day turnaround on urgent, time-sensitive items such as a legal page change, a promo swap or a broken checkout is normal work rather than an escalation. Proactive monitoring catches most problems before anyone on your side notices them, which is what keeps genuine emergencies rare.

How do we communicate day to day?

In whatever your team already uses. I join Slack channels, work tickets in Asana, Jira, ClickUp or Linear, submit pull requests to your repositories and attend standups or marketing syncs when they are useful. For questions that need a written answer, email works well; for anything urgent, a message or a call reaches me directly.

What happens if the site goes down at 2am?

Uptime, error log and vulnerability monitoring are configured so problems surface as a notification to me rather than a phone call from your CEO, and most incidents are caught and handled before they affect visitors. When something urgent does happen I respond quickly. Everything I build is also documented and stable enough that your own team can act in an emergency if I am unreachable.

How do you report on the work you do?

Retainer clients receive a written monthly report covering what changed, what was found and what I recommend next, in plain language a marketing lead or executive can read. Compliance and security findings are reported the same way, and for larger initiatives I provide progress updates against the agreed roadmap. Analytics and warehouse work is often reported through automated dashboards or scheduled email reports built as part of the engagement.

Isn't it risky to depend on one person?

It can be, which is why process and documentation are built into every engagement. Code lives in your repositories with clean Git history, GTM containers follow standard, self-documenting patterns, server-side code and pipelines are documented, and deployment runbooks and CMS editing guides are written for your team. I have transitioned clients to in-house teams when they were ready, with no black boxes and no vendor lock-in.

What if we later want to bring the work in-house?

That is a supported outcome, not a threat. Knowledge transfer is part of the offboarding process: theme and pipeline documentation, environment runbooks, version control setup for multi-developer teams and walkthroughs for whoever takes over. Because the work was built on standard patterns from the start, a competent developer can pick up where I left off.

Do you deliver strategy, or only implementation?

Both, from the same person. Most consultants hand over a deck or an audit PDF and leave implementation to someone else; I write the recommendation, build it, wire up the measurement and read the results myself. The strategy is better because it is informed by what is actually possible in your codebase, and the implementation is better because it was designed by the person who understands the goal.

How do you handle sensitive data and compliance requirements?

I have worked on systems with HIPAA, PCI, SOC 2, ITAR and GDPR obligations and follow secure development practices throughout: authenticated integrations, PII-free logging, credentials managed in configuration rather than code, least-privilege access and verified backup policies. I also respond to vendor security questionnaires, penetration test findings and audit reports as part of the engagement.

Do you offer 24/7 support?

On a large enough retainer with a dedicated block of time, yes. In practice that means early or late hours on business days, weekend work during crunch periods such as launches or migrations and occasional holiday coverage where the business type calls for it, such as publishing or eCommerce. Critical alerts reach me by text message with ringtones that bypass quiet hours, so a security incident or a broken checkout gets a response outside normal hours. Smaller retainers get business-hours coverage with proactive monitoring filling the gaps.

What is your typical turnaround time for requests?

It depends on the request, but turnaround for retainer clients is now very rapid. Requests from Slack, Linear, ClickUp, Google Sheets, email and other task tools are consolidated into a single queue that lands in front of me immediately with push notifications, so nothing waits in an inbox. Small fixes and content changes are often same-day; larger work is scheduled and communicated up front. For security incidents and other business-critical issues, text alerts with ringtones that bypass silent hours are used so the response is immediate.

Pricing, Billing & Contracts

How work is priced and invoiced, commitments, ownership and paperwork.

How do you price your work?

Retainers are priced as a flat monthly fee based on the estimated level of effort your site and stack require, agreed up front after reviewing what is in scope. Standalone projects such as rebuilds, migrations and audits are scoped and estimated after an initial review so the number reflects your actual codebase and requirements rather than a generic package. Pricing is discussed on the intro call once I understand the work.

Is there a minimum commitment?

Retainers are month-to-month agreements with an initial term set in the contract, because meaningful security, compliance and analytics work needs more than a few weeks to show results. Standalone projects are scoped to a defined deliverable. There is no lock-in beyond the agreed term, and clients stay because the work keeps paying off, not because of the paperwork.

How does invoicing work?

Invoices are issued monthly and include a plain-language summary of the work completed. Retainer invoices are activity summaries rather than timesheets, and payment terms are stated on the invoice and in the agreement. Larger standalone projects may be invoiced in milestones agreed at the start.

Do you offer paid audits or diagnostics?

Yes, and they are often the best first step. I offer theme and code audits of sites built by other developers, GTM container and tracking audits, cookie and consent audits, accessibility triage and a BigQuery warehouse diagnostic. Each one produces a written assessment and a prioritized roadmap you own regardless of whether we continue, and nearly every long-term engagement started this way.

Who owns the code and work product?

You own the custom work built for your business: your theme, your integrations, your tracking configuration, your data models. I retain ownership of my own reusable tooling such as starter frameworks, internal libraries and build and deployment scripts, and you receive a perpetual license to use them on your properties. Open-source and third-party components stay under their own licenses. The specifics are spelled out in the agreement.

Do you sign NDAs, MSAs and vendor agreements?

Yes. I work under a standard consulting agreement that covers scope, confidentiality, IP, term and termination, and I regularly sign client NDAs, data processing agreements and vendor onboarding paperwork. I operate as a Massachusetts LLC, carry commercial general liability insurance and can provide a certificate of insurance and W-9 on request for procurement.

Custom WordPress Development

Themes, plugins, block systems, cleanup, migrations, integrations and editorial support.

What kinds of WordPress work do you do?

Custom theme development from scratch or from Figma designs, browser-based website design for teams without a design file, ACF-powered block and page-builder systems, plugin development, multisite networks, headless and REST API builds, WooCommerce and custom eCommerce, hosting migrations and launches, legacy code cleanup, PHP upgrades, performance and Core Web Vitals, security hardening, third-party API integrations and ongoing maintenance retainers. If it runs on WordPress and matters to your business, it is in scope.

Do you build custom themes from scratch or from our designs?

Either. If you have Figma designs, I build a custom theme directly from them, including the frontend animation and interaction work. If you do not have a design file, I shape layout, typography and components directly in the browser and then build that as the theme. Themes are built on modern frameworks with performance, accessibility and maintainability as defaults rather than afterthoughts.

Do you use page builders like Elementor, Divi or WPBakery?

Not for new builds. Heavy visual builders add plugin dependency, performance overhead and markup your team cannot control. Instead I build modular, ACF-powered block systems tailored to your content team, which gives editors a structured, frustration-free way to compose pages without a developer, and it sets the site up for a far more AI-driven content process than Gutenberg does. I do support and stabilize existing builder-based sites, and where a builder is genuinely the right fit for a self-managed site I will say so.

What is an ACF block builder system?

It is a set of purpose-built, reusable content blocks defined with Advanced Custom Fields, each with exactly the fields your editors need and nothing they do not. Editors assemble pages from those blocks inside the WordPress editor, the markup stays clean and consistent, and the design system holds because nobody can drag a stray column width into production. It is a structured alternative to raw Gutenberg and to heavy visual builders.

Can you fix or clean up a site built by another developer or agency?

Yes, and it is a large share of my work. I start with a paid theme audit covering code quality, performance and security, delivered as a prioritized fix list. From there I refactor and stabilize what is worth keeping, and where a rebuild is the cheaper path I will tell you plainly. Sites that arrive full of bugs, plugin conflicts, white screens and slow admin screens leave stable and documented.

Do you develop custom WordPress plugins?

Yes. I create custom plugins for functionality that does not belong in the theme, and I support, fix and improve plugins built by other agencies or programmers. The guiding principle is fewer plugins, not more: I solve problems with lightweight, maintainable code where that is the better approach and only reach for a third-party plugin when it is the right fit for your stack.

Is WordPress secure enough for a bank, healthcare organization or regulated business?

Yes, when it is built and operated properly. WordPress is targeted more often because it is the most widely used CMS, but the platform itself is sound; problems come from poor-quality plugins, neglected updates and bad practices. With hardened configuration, a minimal plugin footprint, daily vulnerability scanning, Cloudflare in front, security headers and a tested update cycle, WordPress meets the expectations of monthly external audits and compliance programs.

Can WordPress scale to high traffic and complex requirements?

Yes. WordPress powers some of the largest publishers and enterprises on the web, and I have built and supported it for sites with millions of monthly visitors, tens of thousands of paying subscribers and multi-country content networks. The keys are a clean theme, correct caching layers, a tuned database, sensible architecture for high-volume data and hosting matched to the load. Scale problems on WordPress are almost always build problems, not platform problems.

Which third-party systems can you integrate with WordPress?

I have connected WordPress to hundreds of platforms, including HubSpot, Salesforce, Marketo, Pardot, Stripe, Shopify, BigQuery, Segment, Mixpanel, Twilio, Mailgun, Customer.io, Zapier, n8n, Veeva Vault, Zoho, SOAP services and internal client APIs secured with enterprise authentication such as Microsoft Entra and SAML. If a system has an API, it can be wired in cleanly and securely.

Why do our WordPress emails land in spam, and can you fix it?

Almost always because mail is sent straight from the web server with no authentication behind it. The fix is to route all WordPress mail through authenticated infrastructure such as SendGrid, Mailgun, Microsoft 365, Google Workspace or a verified SMTP relay, then publish SPF, DKIM and DMARC records in DNS so receiving servers can prove the mail is really from you. That also protects your domain from spoofing and satisfies vendors that now require a DMARC policy.

What is your approach to custom theme development?

Simple, minimal and effective. I pick the simplest approach that fits the site and the team that will run it, and most of the time that is conventional, time-tested WordPress theme development rather than a framework layered on top. I know the major frameworks well and use them when a client's team has standardized on one; when the choice is mine, I keep the codebase lean because lean themes are the easiest to test, monitor, hand off and maintain, and that matters more every year.

What does a modern WordPress web stack look like?

Cloudflare in front for DNS, performance and security. Managed hosting such as Kinsta, with a staging environment on a subdomain so tracking, GTM container updates and code changes can be fully verified before production. Cookie consent wired through to Google Consent Mode v2, using an open-source banner when you know what you are doing or a platform such as CookieYes when the business wants a CMP. WordPress itself runs with minimal plugins, typically an SEO plugin and ACF Pro for advanced CMS controls, which I recommend over Gutenberg because it supports a far more AI-driven content process going forward. Uptime monitoring runs through Cloudflare or a worker with rules that verify key parts of the site actually work, not just an HTTP status. Client-side and server-side errors are captured cleanly, with no tolerance for PHP notices, warnings or fatals, because a handful of users hitting a broken lead form on one mobile browser costs real money and nobody sees it without error tracking. Pre-deploy testing of key flows, now much stronger with AI, and GitHub for all code changes with pull requests whenever more than one developer is involved.

Enterprise CMS & Headless

Enterprise content management, headless architectures, platform migrations and SSO.

What do you mean by enterprise CMS development?

Web content management built for organizations where editors need to move fast, engineering needs stability and the business needs governance. That means structured content models, custom post types and taxonomies, editorial workflows with approvals and embargoes, role-based permissions, audit trails and the integrations around the CMS such as SSO, CRM and data warehouse. I build this on WordPress or on headless stacks depending on the requirements.

When does a headless CMS make sense?

When one content source needs to feed several channels: a website, native iOS and Android apps, internal tools or partner systems. In that case an API-first CMS with a Next.js or React frontend is the right call, and I have shipped them at enterprise scale. When you only have a website, a well-built traditional WordPress theme is simpler, cheaper to run and easier for your team to own. Headless is a tool, not a default, and I will tell you which one you need.

Security & Performance

Cloudflare, hardening, scanning, audit remediation, Core Web Vitals, caching and database work.

What does your security work include?

Cloudflare configuration as the front door (DNS, WAF, bot protection, rate limiting, edge caching), security headers including Content Security Policy delivered at the edge, daily vulnerability scanning with manual alert verification, login and access hardening, remediation of audit and penetration test findings in code, enrollment in government scanning programs where applicable and ongoing monitoring. It is delivered as continuous engineering rather than a one-time hardening pass.

How do you use Cloudflare?

As an active security and performance layer, not a switch that gets flipped once. I handle DNS migrations and record management, write WAF rules from real firewall event data, deploy Turnstile in place of reCAPTCHA, configure bot and DDoS mitigation, rate-limit login and admin URLs, tune edge cache and page rules with automatic purging, deliver security headers through a Cloudflare worker and troubleshoot origin certificate and SSL issues. Every tightening is tested against the forms, payment frames and ad scripts it could break.

How does vulnerability scanning and patching work?

Scans run daily against MITRE CVE data and the wpscan.io database, with alerts routed to a real person rather than a dashboard. Every alert is verified by hand before it is dismissed or fixed, and plugin, theme and core patches are applied on a schedule after testing on staging. Uptime, error log and third-party script monitoring run alongside so changes are noticed when they happen.

Can you remediate findings from our penetration test or security audit?

Yes. I work through monthly external audits, web application penetration test reports, security scorecard results and third-party scan findings item by item, in the codebase, until they close. That includes cross-site scripting, injection, tab-nabbing and header findings, CSP configured to your audit's grading requirements and SSL or DNS findings resolved with your IT team. Findings come back as code and configuration changes with a written record, not a PDF that sits in a folder.

What is the CISA scanning program and can you enroll us?

CISA offers a free vulnerability scanning service for public-facing domains that produces recurring reports on exposed services and known weaknesses. I have enrolled client domains in the program and triage and remediate the resulting reports alongside your compliance team, which gives regulated organizations an independent, government-run signal on top of commercial scanning.

How do you fix Core Web Vitals and site speed?

At the source, not behind another caching plugin. I profile the actual bottleneck and fix LCP, CLS and INP in the theme and template layer: hero image handling, layout shift, render-blocking CSS and JavaScript, third-party script deferral, images resized to their rendered dimensions and served as WebP, fonts loaded conditionally, HTML minified for TTFB and video embeds converted to click-to-load previews. Improvements are verified against field data and tracked over time, not a single lab run.

How should caching be configured on a WordPress site?

Edge, full-page, object and browser caches all interact, and misconfigured they fight each other: stale prices, logged-in users seeing cached pages or a cart cookie bypassing the edge on every request. I configure them together: Cloudflare cache and page rules, s-maxage headers separating browser from edge cache, Redis or host-level object caching, transient caching for expensive queries and menus, and automatic purges when content is published. Caching goes on top of a fast site, not in front of a slow one.

Our site keeps hitting memory limits and the admin is slow. Can you fix that?

Yes. This is the work hosting support escalates rather than solves, and the cause is usually in the database or host configuration: memory exhaustion and fatal errors, postmeta and options table bloat, orphaned revisions, transients and meta, missing indexes, slow queries and excessive query counts in hot templates. I diagnose it, clean it up, repair and optimize the tables and reconfigure object caching so the problem does not return.

Do you help with vendor security questionnaires and compliance programs?

Yes. I answer the engineering side of vendor security questionnaires, document what the site does today and support compliance programs including HIPAA, ITAR, PCI, SOC 2 and GDPR with the controls those frameworks expect: security headers, authenticated integrations, PII-free logging, access restrictions on admin, tested backups and a written change record.

How do you protect the WordPress login and admin?

The overwhelming majority of attacks are automated attempts at the login screen and the REST API, and they are cheap to shut down. I rate-limit wp-login and wp-admin, mitigate brute force at the edge, block author and REST API user enumeration, roll out MFA, review credentials and roles, restrict admin behind Cloudflare Access or VPN where appropriate and block write attempts to upload directories.

What are security headers and a Content Security Policy, and do we need them?

Security headers tell browsers what your site is allowed to do. A Content Security Policy controls which scripts can run at all, which is how you stop an injected third-party script from exfiltrating form data, and HSTS, referrer-policy and permissions-policy close other gaps. Audits and security questionnaires routinely require them. I roll CSP out in report-only mode, whitelist assets from real traffic, then enforce it, delivered through a Cloudflare worker so it is centrally managed, and fix rather than exempt the payment frames and embeds it initially blocks.

What do you monitor on an ongoing basis?

Uptime and downtime, error logs, SSL expiry, daily vulnerability scan results, redirect loops and layout shift, new or changed third-party scripts loading on the site, Cloudflare firewall events and, for compliance clients, consent behavior and GTM container changes. Alerts go to me for triage so problems surface as a notification instead of a customer complaint.

Analytics & Tag Management

GTM, GA4, server-side tracking, conversion APIs, attribution and reporting.

What does a GTM and GA4 engagement include?

Clean, organized Google Tag Manager containers with clear naming and structure; accurate GA4 tracking of standard and custom events across sites and devices; conversion tracking for every ad platform you use; server-side tracking synchronized with browser pixels; cross-domain tracking; UTM standards; eCommerce and funnel tracking; consent gating on every tag; and reporting through Looker Studio, BigQuery or your BI tool. Audits of existing setups and full rebuilds are both common starting points.

Our GTM container is a mess. Can you clean it up?

Yes. Years of accumulated tags, paused experiments and inconsistent naming are the norm. I audit the container, identify what fires, what is redundant and what is missing consent controls, then rebuild it using a Provider-Action naming pattern, organized folders and documented consent classifications for every tag. The result is a self-documenting container any team member can understand on day one.

What is server-side tracking and why does it matter?

Ad blockers, iOS privacy restrictions and browser tracking prevention now stop a large share of browser-based conversion events from ever being recorded. Server-side tracking sends those events from your server directly to platforms such as Meta, Google, TikTok and LinkedIn through their conversions APIs, deduplicated against the browser pixel. It recovers conversions the browser misses and gives ad platforms the signal quality they need to optimize campaigns, while still respecting consent.

Which ad platforms can you set up conversion tracking for?

Google Ads, Meta (Facebook and Instagram), TikTok, LinkedIn, Reddit, Snapchat, Microsoft Ads and others, on both the browser and server side. That includes Meta Conversions API with proper deduplication and event matching, TikTok Events API, Google Ads offline and enhanced conversions and product feeds for shopping campaigns. Every platform receives the same events with shared IDs so the numbers reconcile.

Why do GA4, Google Ads and Meta all report different numbers?

Because each platform was wired separately, with different triggers, different definitions and no shared event identifiers. A unified event architecture fixes this at the root: one set of events defined in GTM, consistent naming conventions, shared event IDs for deduplication and a single source of truth flowing to every platform. Some variance is inherent to attribution windows, but the discrepancies that make nobody trust the data go away.

How do you handle attribution and reporting beyond standard GA4 reports?

GA4 data exported to BigQuery enables SQL-based analysis of user behavior, conversion paths and multi-touch attribution at any scale, and connected CRM data extends that to closed revenue. I build automated reporting pipelines from BigQuery into Looker Studio, Tableau or Power BI, plus scheduled email reports for executives who will never log into a dashboard.

Can you connect tracking to HubSpot, Salesforce or Marketo?

Yes. I wire website tracking, forms and lead data into HubSpot, Salesforce, Marketo and similar platforms so marketing and sales see the same journey, and I bring their tracking scripts under one consent management platform instead of their native banners. Offline conversion events from the CRM can be pushed back to ad platforms so campaigns optimize toward qualified leads and closed deals rather than form fills.

Privacy & Consent Compliance

Cookie consent, Consent Mode v2, GDPR and CCPA/CPRA implementation and documentation.

How do you prove the implementation actually works?

Every implementation ships with a test matrix, not just a working popup. For each consent state and region I verify which tags fire in GTM, whether GA4 loads and transmits hits, how ad units behave and what cookies are written, down to the network request. You get the passing matrix in writing plus a region preview switch so your own team and counsel can reproduce the results.

How do we handle CCPA and CPRA data subject requests?

You need a way for California residents to submit access and deletion requests and a process that actually answers them. On the website side I build the intake: a request form matching your design, conditional logic for request types, server-side validation, authenticated delivery into your privacy platform or internal queue and a request ID shown to the visitor on submission so both sides have a reference. API credentials are managed in the CMS rather than hardcoded.

What is Global Privacy Control and do we have to honor it?

Global Privacy Control is a browser-level signal that tells a site the visitor opts out of the sale and sharing of their personal information. Under CPRA, covered businesses must honor it, which means detecting the signal and applying the opt-out automatically without waiting for a banner interaction. It is a small piece of code and a frequently missed one, which is exactly why compliance scanners flag it. I wire it into the consent defaults along with the footer privacy choices link.

Can one site handle GDPR opt-in and CCPA opt-out visitors at the same time?

Yes. Server-side GeoIP determines the consent defaults before the page renders, so European visitors get denied-by-default and US visitors get the treatment their state requires, with no client-side flicker on first paint. Regional regimes such as GDPR, CCPA, CPRA, CPA, CTDPA and VCDPA run simultaneously on one implementation, and new state laws are added as they take effect.

We received a wiretapping or CIPA-style demand letter. Can you help?

Yes, on the engineering side. I have supported clients through active plaintiff claims by implementing banner and disclosure changes to outside counsel's exact specifications same-day, auditing every third-party script for exposure and monitoring the site with the same scanning tools plaintiff firms use to select targets. The implementation and its written documentation become part of your forward defense posture. The legal strategy itself belongs with your counsel.

Is privacy compliance a one-time project or ongoing?

Point-in-time compliance decays. Every new pixel, heatmap tool, vendor script, redesign or state law reopens exposure. Most of my privacy work runs inside an ongoing retainer: scheduled re-verification of consent behavior, cookie re-classification, GTM container change review so new tags are consent-gated before they ship, multi-tool scanning and findings reported into your existing weekly and quarterly cadence.

If a visitor rejects cookies, are the existing ones removed?

Only if you configured it. Most banners stop future scripts from loading but leave cookies already set by earlier visits sitting in the browser, which is exactly what a compliance scanner screenshots. I configure automatic clearing per category and then verify vendor by vendor that the cookies really disappear on reject rather than trusting library defaults.

Accessibility & WCAG

Audits, remediation in the theme, procurement reviews and keeping sites from regressing.

What is WCAG and which version applies to us?

WCAG is the Web Content Accessibility Guidelines, the technical standard nearly every accessibility requirement points at. It has three conformance levels: A, AA and AAA, and AA is the practical target referenced by most laws, procurement policies and settlements. WCAG 2.1 AA is the common baseline today, with 2.2 adding a small number of further criteria around focus appearance and dragging. Which version you are held to is a question for your counsel; building to 2.1 AA and picking up 2.2 additions as you go is the practical approach.

Can we just install an accessibility overlay widget?

No. Overlays sit on top of your site and try to patch accessibility at runtime, and they consistently fail to fix the underlying markup while breaking assistive technology that already works. Sites running them have been frequently targeted in accessibility litigation and screen reader users have publicly opposed them in large numbers. If a vendor promises compliance from a single script tag, that is the strongest signal to fix the site properly instead. Fixes belong in your markup and CSS.

How do you audit a site for accessibility?

Automated tooling first, because it is fast and finds real problems: Lighthouse and axe across representative templates rather than every page. Then manual testing, which is where the important failures show up: navigating by keyboard alone, checking focus visibility and order, reading the heading structure and testing forms end to end. The output is a triaged list where every finding gets a category, a recommendation and an effort estimate, and false positives are called out with the reason rather than quietly dropped.

Can automated tools catch every accessibility issue?

No, and that gap is why so many sites with clean scan reports are still unusable. Automated tooling reliably catches roughly a third of WCAG criteria: missing alt attributes, contrast ratios, form labels, empty links. It cannot judge whether alt text is meaningful, whether tab order matches visual order, whether a custom component behaves sensibly under a screen reader or whether an error message tells someone what went wrong. Those need a person.

Our scan report shows hundreds of issues. Is this a six-month project?

Usually not. Automated tools count every instance, so one bad component in a template repeated across two hundred pages reports as two hundred issues and takes one fix. Triage almost always collapses a frightening number into a much smaller set of real changes. For a typical corporate WordPress site the triaged list is days rather than months of work; custom interactive components, complex forms and video experiences take longer. The honest scope comes after triage, not before.

Will accessibility remediation require a redesign?

Almost never. Most remediation happens in the theme layer: focus styles, heading structure, labels, alt text, keyboard behavior and ARIA, none of which change how the site looks. Contrast is the one place design gets involved, and the usual answer is a slightly darker shade of a color you already use. I bring the measurements and options to your designers and implement whatever they choose consistently across the theme.

Will we be WCAG 2.1 AA compliant when the work is done?

I will not certify that, and you should be skeptical of anyone who does. What I deliver is remediation of every finding we agree to address, documented, plus a clear statement of what remains and why. Formal conformance claims and legal exposure are a conversation for your counsel and, if needed, a specialist auditor I am happy to work alongside.

Can you help with a VPAT or a customer accessibility review?

I supply the engineering side: what the site does today, what has been remediated, what remains and why, in language a reviewer can evaluate. That is normally what stalls these questionnaires. The formal VPAT document itself is typically completed by your team or a specialist accessibility auditor, and I work alongside them. I also publish and link the accessibility statement and contact route reviewers look for first.

What accessibility problems do you find most often?

The same handful on almost every site: focus indicators removed in CSS because they looked untidy, header menus that only open on hover and cannot be reached by keyboard, a skip link that is broken or points at nothing, heading levels used as styling so the structure jumps from h2 to h5, images with missing or auto-generated alt text, decorative icons announced to screen readers as content and form fields with placeholder text instead of a real label.

Is accessibility a one-time project or ongoing?

Both happen, but a one-time pass decays. Every redesign, new page template, new plugin and content push reintroduces problems and the site drifts back within a year. Inside a maintenance retainer, new templates get checked before they ship, alt text enforcement lives in the CMS so editors cannot publish an image without a description and periodic re-scans catch regressions while they are small. That is where the standard actually holds.

Does accessibility work help SEO?

A fair amount of it overlaps. Correct heading structure, meaningful alt text, descriptive link text and semantic markup all help crawlers and AI answer engines interpret a page, and several of those items show up in both my accessibility and SEO fix lists. It is a genuine side benefit rather than the reason to do the work.

SEO, AEO & AI Visibility

Technical SEO, structured data, LLM feeds, AI citation strategy and measurement.

What is AEO or GEO (AI search optimization)?

Answer engine optimization, also called generative engine optimization, is the practice of making your brand and content the source that AI tools such as ChatGPT, Claude, Gemini, Perplexity and Google's AI Overviews cite when answering relevant questions. It builds on SEO fundamentals but emphasizes factual accuracy, comprehensive coverage, clear entity relationships, structured data and machine-readable infrastructure that keeps LLMs supplied with current information about your business.

How is AEO different from traditional SEO?

SEO optimizes for ranking positions in search results. AEO optimizes for being cited as an authoritative source in AI responses. The tactics overlap, including structured data, content quality and authority signals, but AEO weights factual accuracy, information density and clear entity relationships more heavily than traditional factors like backlinks. Strong SEO fundamentals are the foundation; the work is extended, not replaced, and most businesses need both.

How do LLMs decide which content to cite?

They favor content that is factually accurate, comprehensive, well-structured and comes from sources with clear authority. Signals are similar to search engines but weighted differently: clarity, information density and consistency of facts across the web matter more than link counts. Consolidated, authoritative resources tend to outperform many thin pages targeting individual keywords.

Can you measure traffic and visibility from AI tools?

Yes, with the right setup. I implement custom tracking that identifies referrals from ChatGPT, Perplexity, Claude and other AI tools, and in many cases captures the specific prompts and questions that lead people to your site. Combined with monitoring of how your brand appears across LLMs for the questions that matter, that gives you a measurable view of AI visibility and how those visitors convert.

Should we add an llms.txt file?

It will not hurt, but do not expect it to do much. llms.txt is widely recommended, yet there is real evidence that major providers do not act on it. I will deploy one if you want the box checked, but what I recommend and have advocated from the start is a dynamic JSON API: endpoints that feed structured, always-current information about your business, products and frequently updated content directly to LLMs and AI agents. Unlike a static text file it keeps pace with content you publish daily.

How does structured data help with AI visibility?

Schema.org markup and structured data help LLMs understand what your content is about, who created it and how authoritative it is. Clear entity relationships connecting your brand to products, people and topics make it easier for AI to confidently cite you. I implement detailed structured data and go further with machine-readable feeds designed specifically for LLM consumption.

What type of content performs best for AI visibility?

Comprehensive, factually accurate content that directly answers specific questions. LLMs favor pages that cover a topic thoroughly over thin pages targeting individual keywords, so consolidating related content into authoritative resources often outperforms having many scattered pages. Understanding your product the way a customer would is what makes that precision possible; tools alone do not get you there.

Are there risks to using AI to create content?

Yes. LLMs can detect generic AI-generated content and may weight it less favorably, and the bigger risk is publishing inaccurate or diluted material that gets flagged during Google spam updates. What works is using AI to build solid templates and structures, then filling them with ideas that come from you and a full understanding of the business. Having AI generate the ideas themselves produces diluted content. Paired with genuine expertise and a review process, it increases output without degrading quality.

Do you still do traditional technical SEO?

Yes. Technical SEO audits, Search Console fixes, redirect mapping, content architecture, Core Web Vitals, image and metadata cleanup and schema markup remain core work, and they are the foundation AI visibility is built on. Consolidating low-value pages so the pages that matter take their place has produced more clicks from fewer impressions in Search Console for clients while AI visibility grew over the same period.

How do you handle AI crawlers and bots on our site?

Deliberately. I configure Cloudflare AI crawler and bot rules and robots.txt strategy so the crawlers you want to feed are allowed and the ones you do not are blocked or rate-limited, and where it makes sense I set up AI crawler licensing and monetization. The right policy depends on whether your content is a lead-generation asset or a product in itself.

What if the AI landscape changes completely?

The fundamentals of factual accuracy, comprehensive content, structured data and clear authority signals work across every LLM. Rather than optimizing for specific tools that may change, I focus on the principles that will matter regardless of which AI products dominate next year, and I keep measuring so strategy adapts as the signals do.

How do you measure SEO results and prove the work is producing positive outcomes?

With before-and-after comparisons in Google Search Console, supported by custom tooling such as AI Track for AI visibility. When an initiative begins, say six weeks of optimizations I recommended and implemented, I compare search performance for that window against the six weeks before it: positions, impressions and most importantly clicks through to the site, since impressions alone are not a result. It is rare for SEO firms to report this way because it shows whether the work actually moved anything, and most cannot guarantee that it will.

BigQuery & Data Engineering

Warehouses, GA4 pipelines, ETL, cost optimization and executive reporting.

What does a BigQuery or data engineering engagement include?

Google Cloud project setup with IAM controls, GA4 and Search Console exports, server-side tagging pipelines that feed the warehouse directly, ETL from CRM and marketing platforms through Fivetran, Airbyte or custom pipelines, version-controlled SQL modeling with Dataform or dbt, scheduled queries as the reporting engine, dashboards in Looker Studio, Tableau or Power BI, automated executive email reports, cost and performance optimization, monitoring and continuous documentation. I work as your fractional data engineer.

How does a BigQuery engagement start?

With a paid diagnostic of your existing setup: the warehouse you inherited, the GA4 export nobody modeled or the query bill that keeps climbing. You get a written assessment and a concrete roadmap either way, with datasets, transformations and deliverables defined up front so the project does not fail on scope creep. Nearly every long-term data engagement I have began this way.

Can you set up the GA4 export to BigQuery and make it usable?

Yes. The native export is the starting point, but raw event tables are not reporting-ready. I connect GA4 and Search Console, add server-side GA4 and GTM pipelines that capture more than the native export does, then model sessions, users, conversions and attribution into clean tables that scheduled queries and dashboards can rely on.

Our BigQuery bill keeps climbing. Can you reduce it?

Yes. Cost reduction comes from clustering and partitioning, query plan execution analysis, rewriting expensive queries, pruning unused scheduled jobs, choosing between on-demand and dedicated compute pricing correctly and configuring cost limits and forecasts so surprises stop. I have optimized terabyte-scale queries, and warehouse takeovers routinely lower the bill while fixing what was broken.

Which data tools do you work with?

Dataform and dbt for version-controlled SQL modeling, Fivetran and Airbyte for managed connectors, Google Cloud Functions and Pub/Sub for custom and streaming ETL, Looker, Looker Studio, Tableau and Power BI for visualization, BigQuery ML for forecasting and DuckDB or MotherDuck where a full BigQuery deployment is overkill. The stack is matched to the workload, not the trend.

What happens to the pipelines after launch?

A warehouse is not finished at handoff. Schemas drift, costs creep and scheduled queries break silently, so I set up monitoring and error notifications for every scheduled job and stay available after delivery to tune costs, fix breakages and extend what was built. Most organizations keep me on long-term for exactly that.

Custom eCommerce

Purpose-built checkout, subscriptions, paywalls and Stripe integrations on WordPress.

Do you work with WooCommerce?

Yes, and often. A large share of that work is performance audits and evaluations of existing WooCommerce stores: slow checkouts, database bloat from order and product meta, plugin conflicts, payment gateway configuration, product feeds to ad platforms and conversion pixels tied to real checkout events. For new builds with specific purchasing flows, subscription models or very high volume, I also build purpose-built systems that integrate directly with Stripe and use custom database schemas instead of a plugin stack. Which path fits depends on the product, the volume and the team running it, and I will recommend the one that does.

When is a purpose-built system a better fit than WooCommerce?

When the purchasing flow is specific to your product, when subscriptions or tiered pricing drive the business model or when order volume is high enough that WooCommerce's data model becomes the bottleneck. WooCommerce stores much of its data in wp_postmeta, so every order adds dozens of unindexed rows and reporting and admin slow down as volume grows, and a large plugin stack adds upgrade risk. For standard catalogs run by a small team, WooCommerce is the right tool and I keep it fast; beyond that, a lean application that happens to run on WordPress avoids the bloat and gives you a checkout designed around your product.

Can WordPress handle high volumes of customers and orders?

Yes, when high-volume data is kept out of the standard wp_users and wp_posts tables. I handle custom user and order management in purpose-designed tables, which makes the system as lean and scalable as a framework application while keeping the CMS your team already knows. I have built subscription systems on this approach that support tens of thousands of paying customers with ease.

Do you build subscriptions, paywalls and member accounts?

Yes. Recurring billing, renewals, upgrades and cancellations through Stripe, group and corporate subscriptions with bulk membership support, paywalled content and digital product delivery, customer portals and the back-office tools your team uses to manage it all. Systems are designed around MRR, churn and LTV, not just a checkout button.

How do you handle reporting and monitoring for transactions?

Custom database tables log raw data from Stripe webhooks, and custom dashboards act as a translation layer so the data is simple to interpret without the false positives of raw logs. Because the schema is minimal and purpose-built, precise SQL produces reports instantly instead of freezing the database the way plugin queries do. Server-side conversion tracking is tied to the same real payment events.

Why build on WordPress instead of Laravel or React?

Pure framework applications often require keeping developers on staff just to manage daily operations. With a hybrid approach, management tools are built into WordPress so your team controls the business, while lean, purpose-built code handles the transactional logic and keeps maintenance close to zero. You get the flexibility of the world's most popular CMS with the performance of a custom application. Where a client already runs Laravel, I work in that stack too.

How do you handle PCI compliance and payment security?

Card data never touches your server: payment collection runs through Stripe's hosted and tokenized flows, which keeps your PCI scope minimal. Around that I apply strict security standards for customer PII in portals and back-office tools, authenticated webhooks, PII-free logging, Content Security Policy and the same hardening used for regulated clients.

Can you add AI features to our eCommerce or lead generation flows?

Yes. I integrate APIs from OpenAI, Anthropic and Google Gemini to automate complex tasks: classifying and blocking spam form submissions, enriching leads, generating and reviewing content, powering onboarding assistants and handling workflows that used to need manual review. The integration is built into your own system so you own the data and the logic.

Digital Growth, Advertising & CRM

Lead generation, conversion optimization, ad platform integration and HubSpot or CRM implementation.

What does a digital growth consultant do?

I act as your technical growth partner, like a fractional CMO who can also design, code and analyze. That means managing the website, optimizing for search and AI visibility, building analytics and advertising infrastructure, integrating the CRM and creating lead generation and conversion systems, all as one coherent machine rather than a set of disconnected vendors. Strategy and execution come from the same person.

Can one person really cover development, SEO, ads, analytics and CRM?

Yes, because these areas are all connected. A website needs SEO to be found, SEO needs analytics to be measured and ads need a fast landing page to convert. My expertise is in understanding the whole system and implementing pieces that work together, which matters more than having a separate specialist for each channel who never talks to the others.

Which advertising platforms do you work with, and do you manage spend?

Google Ads, Meta, TikTok, LinkedIn, Reddit, Snapchat and others. I configure and integrate every platform with server-side conversion events, product feeds and offline conversions so campaigns optimize toward real revenue, and I have managed budgets from modest monthly tests to six-figure monthly programs with a focus on CAC, ROAS and actual revenue impact rather than vanity metrics.

How do you use AI in content and marketing workflows?

As a productivity multiplier paired with real expertise. I build AI-assisted workflows using APIs and fine-tuning to increase content output while improving quality, automate repetitive marketing operations and productionize AI-generated pages and prototypes so they meet the same standards as everything else on the site. Generic, unreviewed AI content is not something I ship.

Hosting, DevOps & Infrastructure

Managed WordPress hosts, deployment workflows, DNS and email infrastructure.

Which hosting providers do you work with?

I am a certified or recommended consultant at Kinsta, WP Engine, Flywheel, IONOS and Cloudflare, have development and administration experience on WordPress VIP and also work on Pantheon, Pressable, Cloudways, AWS Lightsail and Google Cloud. That includes account and server management, bandwidth and capacity planning, host coordination on server-level limits and firewall behavior and migrations between providers.

Do you work with WordPress VIP, and have you deployed and managed code there directly?

Yes. I have hands-on WordPress VIP development and administration experience: building against VIP's coding standards and code review requirements, working in VIP Go and VIP Platform Git repositories, deploying through their branch-based workflow, managing environments and configuration in the VIP dashboard and coordinating with VIP support on platform-level limits, caching and firewall behavior. Corporate sites running on VIP are a regular part of my custom WordPress work alongside WP Engine and Kinsta.

About Kevin

Background, certifications and how the work is done.

What is your background?

I have worked as a WordPress engineer, data engineer and designer for more than eighteen years, building and supporting web platforms for publishers, financial institutions, universities, healthcare organizations and B2B software companies. I have been an independent consultant for most of that time and have contributed to the WordPress community since 2008. My writing has been published by Smashing Magazine, CSS-Tricks and The New Stack.

Can I see examples of your work and client feedback?

Yes. The case studies section covers custom WordPress builds, headless platforms, subscription systems, analytics architectures, security programs and data warehouses across publishing, finance, insurance, higher education and software, and the testimonials page collects feedback from the marketing and engineering leaders I have worked with. References are available on request for serious engagements.

Do you use AI in your work?

Yes, like any modern practitioner, but in specific places. Its primary role is workflow automation: capturing and consolidating client requests and feedback from Slack, email and task tools the moment they arrive, running ongoing live testing of key site flows such as forms, checkout and signup, monitoring client sites for errors and downtime and triaging the alerts that come back. I do not use it for the communication I send to clients; that I write myself so everything is accurate and correct. The engineering judgment, architecture decisions and review of everything that ships are mine.