riksi Start a project

WordPress and Shopify updates, Melbourne Your site, updated
and doing more.

We update old WordPress, WooCommerce and Shopify sites, fix what breaks and close the security holes. Then we add the features your customers ask for, like online booking, SMS reminders and phone login.

  • WordPress & WooCommerce updates
  • Shopify upgrades
  • Security fixes
  • PHP upgrades
  • New features
  • SMS reminders & login
A monitor with a list of website updates, a laptop comparing a store before and after, and a phone with a text reminder
  • WordPress
  • WooCommerce
  • Shopify
  • PHP
  • MySQL
  • Cloudflare

Why it matters

Attacks now start
within hours.

Most hacked sites were not chosen by a person. They were running old code, and a bot found it. Bots scan the web all day, and AI tools now help attackers move faster.

  • 11,334 new security flaws found in WordPress sites in 2025, up 42% on 2024
  • 91% of those flaws were in plugins
  • 5 hrs median time to mass attacks on the most attacked flaws

Source: Patchstack, State of WordPress Security in 2026 (data for 2025)

The check

What we look at
first.

Example screens from a site check and update. Every job starts with a check, so you know what we will change before we change it.

A site health check showing the WordPress and PHP versions, six plugins out of date and two known security issues
Updates on a staging copy with old and new version numbers, a saved backup and a Push to live button
The same store home page before and after an update, with checks for checkout, forms and emails, and a page speed result
A monthly care report with updates, backups, uptime and blocked attacks, and a list of next steps

What we do

Updates, fixes
and new features.

Choose a one-off update, or let us look after the site every month. One team handles all of it.

  • WordPress and plugins

    WordPress, plugins and themes updated and tested on a copy first. Plugins that nobody looks after any more get replaced.

  • PHP and hosting

    PHP 8.2 gets its last security fix on 31 December 2026. We move you to PHP 8.3 or newer and fix any code that breaks.

  • WooCommerce stores

    Payments, stock, shipping and order emails tested after every update, with test orders before anything goes live.

  • Shopify upgrades

    Old themes moved to Online Store 2.0. Old checkout code rebuilt with checkout extensions and Shopify Functions.

  • Security clean-up

    Unused plugins and old admin accounts removed. Two-factor login, a firewall and security headers added.

  • Backups and a way back

    Daily backups kept away from your server, and a tested plan to roll back if an update goes wrong.

  • Faster pages

    Heavy plugins and old code replaced during the update, so the site also loads faster on a phone.

  • New features

    Online booking, member areas, quote forms, product filters, and links to your CRM or accounting software.

  • SMS for your site

    Order updates, appointment reminders, marketing texts with consent, and SMS codes to check a phone number or log in.

How we work

Check, copy,
update, test.

A good update is a boring update. This is how we keep it that way.

  1. Check

    We look at versions, plugins, errors, speed and security. You get a list of what we found, with a price.

    • Versions
    • Security scan
  2. Copy

    We make a staging copy of your site and a full backup of the live one.

    • Staging
    • Backup
  3. Update and fix

    Updates go in one at a time on the copy. We fix any code, theme or plugin that breaks.

    • WordPress
    • Shopify
    • PHP
  4. Test

    Key pages, forms, checkout and emails. We compare every key page before and after.

    • Test orders
    • Speed
  5. Go live and watch

    We move the changes live at a quiet time and watch for errors. The backup stays ready.

    • Monitoring
    • Rollback

A laptop with a store checkout and a lime Pay now button, a phone with an order confirmation, and a paper checklist

Shopify in 2026

Shopify stores
changed this year.

Shopify Scripts stopped running on 30 June 2026. Shopify Plus stores had to move their discount and shipping rules to Shopify Functions. By 26 August 2026, Shopify had replaced the old Thank you and Order status pages on every plan. Stores that had not upgraded were upgraded for them, and code in the old Additional scripts box stopped running.

If your tracking, ad pixels or checkout rules lived there, they may have stopped without any warning. We check what broke and rebuild it the new way.

  • Tracking and pixels checked after the upgrade
  • Shopify Scripts rebuilt as Shopify Functions
  • Old themes moved to Online Store 2.0
  • Apps you no longer need removed

New features

Features we add
to existing sites.

Your site may not need a rebuild to do more. These are features we can add to the WordPress or Shopify site you already have.

  • An appointment reminder text on a phone, with reminder settings and a registered sender name
    SMS reminders Appointment and order reminders by text. Customers can reply to confirm.
  • A phone showing a six-digit login code and a Verify button, beside a passkey option
    Phone login A one-time code by text to log in or check a phone number, with passkeys as the safer option.
  • A booking form with a calendar, time slots and a Confirm booking button
    Online booking A booking form with times, reminders and email confirmations, added to your current site.

Why old sites get hacked

Most attacks are automatic. Bots scan millions of sites for old versions of WordPress, plugins and themes. Then they use the flaws that have gone public. In 2025, the security company Patchstack found that 46% of new flaws still had no fix when they were made public. So quick updates are only half the job. Good defences matter too.

WordPress itself gets attacked as well. On 22 September 2026, WordPress 7.1.2 fixed a critical flaw in WordPress core. Attackers were trying it within hours of the fix coming out. Sites that updated that day were protected.

AI makes attacks faster

Attackers now use AI to find weak spots and to write attacks. In November 2025, Anthropic reported the first known attack campaign run mostly by AI. The AI did 80 to 90% of the work. Google’s Mandiant team says attackers now often use a flaw before a fix even exists. Its M-Trends 2026 report puts the average time to exploit at minus seven days.

The same report says most successful break-ins still come from basic mistakes. So the basics matter most: current software, strong logins and backups you can use. That is where we start.

SMS for your site

A text is short, and it lands on the phone people carry all day. We connect your site to an SMS provider and set up the messages you need.

  • Reminders and updates. Appointment reminders, order and delivery updates, and back-in-stock alerts.
  • Marketing texts. Offers and news for people who have said yes to them.
  • Codes. A one-time code to check a phone number when someone signs up, or to log in.

In Australia, marketing texts must follow the Spam Act. You need consent, you must say who you are, and every message needs an unsubscribe that works within five working days. Since 1 July 2026, texts sent from a business name that is not on the SMS Sender ID Register show as “Unverified”. We set up consent, the unsubscribe and your sender name with the provider.

For logins, a text code is better than a password alone. But a code can be stolen if someone takes over the phone number. So for logins we also add passkeys, and keep SMS codes for checking phone numbers and as a backup.

Update, or rebuild?

Most sites can be updated. Sometimes the theme or plugins are so old that an update costs more than a new build. If that is the case, we say so. We show you both options with prices, and you choose.

Questions

What people ask
about updates.

Security fixes should go in as soon as they come out. For WordPress, that can mean the same day. Other updates can wait for a monthly round, tested on a copy first.

It can, if it is done straight on the live site. We update a copy first, test the key pages, forms and checkout, and keep a backup ready. If something goes wrong, we roll back.

Yes. We start with a check of the code, plugins and hosting. Then we tell you what we found and what we would change, before we change anything.

Shopify keeps its own platform up to date, but your theme, apps and custom code are yours. In 2026 Shopify turned off Shopify Scripts and replaced the old checkout pages, so some stores lost tracking or discount rules. We find those gaps and fix them.

Yes. We connect WordPress, WooCommerce or Shopify to an SMS provider for reminders, order updates, marketing texts and login codes. We set up consent and the unsubscribe to meet the Spam Act. We also register your sender name, so texts don’t show as Unverified.

Yes. A monthly plan covers updates, backups, security checks and a short report. We agree what it includes before we start, so there are no surprises.

Get in touch

Is your site
up to date?

Send us your website address. We will check the versions, plugins and security, and tell you what we find.

Start a project

Tell us what is
not working.

A few lines is enough. A real person reads every message and replies by email. Or choose the way that suits you.