× Hive Studio

WordPress Maintenance & Development

Progress Report

April — July 2026

ClientKEMROC Spezialmaschinen
AgencyHive Studio
ScopeSecurity · Maintenance · Development

Contents

What this report covers

Period summary

Four months, at a glance

Everything delivered between 1 April and 31 July 2026.

17 Weekly security scans Wordfence, one full scan every week
3 Landing pages built Italian & English, April–May
1 New landing system Multilingual, dashboard-driven, June–July
1 New regional website kemroc.com/us with US-only units
0 Malware remaining Pre-existing infection fully removed

Kept running

  • Weekly Wordfence security scanning
  • Plugin & component updates
  • Monitoring after every release

Built new

  • Three landing pages, Italian & English
  • Landing System (JetEngine CPT)
  • LTR & RTL form templates
  • US version of the global website

Repaired

  • Testimonials page issue
  • Rank Math SEO blocked by Wordfence
  • Malware left by a previous user

Requested

  • Server audit submitted to the host
  • PHP 8, higher memory & upload limits
  • Server-side caching enabled

01 · Ongoing maintenance

Security & platform upkeep

The routine work that keeps the site online, patched and protected — carried out continuously across all four months, alongside every development track.

🛡

Weekly Wordfence scans

A full malware and integrity scan is executed every week across core files, themes and plugins. Findings are triaged the same day, and anything flagged is either cleared or resolved before the next cycle.

  • Core file integrity comparison
  • Theme & plugin file scanning
  • Known-vulnerability matching

Plugin updates

Plugins are updated on a controlled schedule rather than automatically, so every update is verified against the live design and functionality before it stays in place.

  • Security patches applied on priority
  • Post-update visual & functional check
  • Rollback path kept available
🔒

Firewall & access

Wordfence firewall rules are reviewed as part of the same cycle — including the false-positive rule that was blocking legitimate SEO edits from the dashboard.

  • Rule review & tuning
  • Blocked-request investigation
  • Admin activity monitoring
Why weekly matters. WordPress vulnerabilities are almost always exploited through known issues in outdated plugins. A weekly cycle keeps the exposure window to days instead of months.

01 · Ongoing maintenance

How the four months were spent

Maintenance ran continuously throughout. April and May produced the first landing pages by hand; June and July replaced that approach with a system.

April 2026 May 2026 June 2026 July 2026
Security scanning Continuous
Weekly Wordfence scans · continuous
Plugin updates Continuous
Controlled update cycle · continuous
Landing page UI design April
Design
Landing page build April – May
Front-end development
Domain migration May
Dev → main domain
Language versions May
3 pages · IT & EN
Server requirements June
Audit & upgrade request
Clean-up & bug fixes July
Malware · Testimonials · Rank Math
Landing System July
Design → build → content → handover
US version July
kemroc.com/us

Bars indicate relative activity across the period, not billed hours. Striped bars run continuously.

02 · Incident

Malware removal

An infection introduced through a previous user account was identified and removed, and that account's permissions were reduced.

  1. 1

    Detected

    Wordfence scanning surfaced files that did not match the official WordPress and plugin distributions.

  2. 2

    Traced

    The infection was traced back to activity from a previous user account rather than to a hosting-level breach.

  3. 3

    Removed

    Malicious files and injected code were cleared and the affected files were restored to clean versions.

  4. 4

    Access reduced

    The account itself was kept, but its role was lowered so it no longer holds the permissions that allowed the infection in.

03 · April — May

The first landing pages

Before any system existed, the landing page was designed, built and shipped by hand. This is the work that proved the concept — and revealed what it would cost to repeat.

April

UI design

The landing page interface was designed from scratch — layout, hierarchy, typography and the KEMROC brand treatment, shaped around a page built to convert.

April — May

Front-end build

The approved design was developed into a working page and checked across screen sizes and browsers before anything went near the live site.

May

Domain migration

The page was moved off the development domain onto the main KEMROC domain, so traffic and search value land on the live site rather than a staging URL.

Result

Live on kemroc.com

A designed, developed and published landing page running on the main domain — the reference every later version was built from.

Designed for KEMROC, not adapted from a template Built and tested before going live Migrated to the main domain, not left on a dev URL

03 · April — May

Three versions, built by hand

Using WordPress pages and a page builder, three versions of the landing page were produced across Italian and English.

Output

3 landing pages

Three separate versions of the page, each published and maintained as its own WordPress page.

Languages

Italian & English

Content prepared per version so each market reads the page in its own language.

Method

Pages + page builder

Each version was assembled visually in the page builder — the standard WordPress approach, and the quickest route to the first few pages.

What it showed

It would not scale

Three pages were manageable. Every further market would mean another hand-built page to lay out, translate and maintain separately.

This is where the Landing System came from. The manual approach worked and proved the page converts — but the cost of each new market grew with every one added. June and July were spent removing that cost.

04 · Flagship delivery

The Landing
System

A purpose-built system that lets KEMROC create a complete, on-brand landing page for any market or language — entirely from the WordPress dashboard, without a page builder and without a developer.

JetEngine CPTUnified designPer-section controlRTL readyForm shortcodes

04 · Landing System

The problem we set out to solve

Before · April–May

Every landing page was a project

  • A new market meant building another page from scratch
  • Three separate pages to keep aligned by hand
  • Editing required a page builder and technical confidence
  • Right-to-left languages had no path at all
  • Every change needed developer time
After · June–July

A landing page is now a form to fill in

  • New market = new entry, same proven layout
  • One fixed design shared across all languages
  • Everything edited from standard dashboard fields
  • RTL switched on with a single toggle
  • The team ships pages without us

04 · Landing System

How it is built

A custom post type powered by JetEngine, with every piece of page content stored as a structured field.

Step 1

Custom Post Type

“Landings” — a dedicated content type registered with JetEngine, listed in the dashboard like posts or pages.

Step 2

Structured meta fields

Eleven tabs of fields — hero, applications, products, catalogue, testimonials, job reports, contact, form, configuration, footer and section visibility.

Step 3

One fixed template

A single hand-coded template renders those fields. The design is locked, so no entry can break the layout — regardless of language.

Result

A live landing page

Published in any language, LTR or RTL, with its own contact form — created without touching code or a page builder.

No page builder on the front end — faster pages No duplicated design — one template to maintain No developer needed for a new market

04 · Landing System

What the system can do

🌍

Any language, one design

Each landing page is its own entry with its own language content, while the layout, spacing and brand treatment stay identical everywhere.

RTL mode

A single toggle — landing_configuration_language_direction — flips the entire page to right-to-left for Arabic and other RTL languages.

Edit from the dashboard

All copy, images, videos, links and contact details are plain dashboard fields. No Elementor, no shortcode hunting, no HTML.

Show or hide any section

Eight independent switches under “Sections Display” turn each section on or off per page, so no two markets need the same page structure.

Repeatable content blocks

Applications, products and job-site reports are repeaters — items are added, duplicated, reordered or deleted with a click.

Forms by shortcode

Each page points at a JetFormBuilder form ID. Ready-made LTR and RTL forms are supplied to duplicate and reuse.

04 · Landing System

Eleven control tabs, one page

Everything visible on a landing page maps to a tab in the dashboard.

1

Hero

Title, description, background video and thumbnail.

2

Applications

Title, description, CTA and a repeater of application areas.

3

Products

Title, description and a repeater of KEMROC solutions.

4

Catalogue

Cover image, description and a download call-to-action.

5

Testimonials

Rich-text success stories plus video and video thumbnail.

6

Job reports

Repeater of real job-site reports with CTA to the full archive.

7

Contact

Sales representatives — name, role, phone, mail, location, photo.

8

Form

Section heading, intro copy and the form ID rendered on the page.

9

Configuration

RTL toggle, header menu labels and the JetFormBuilder form ID.

10

Footer

Footer description and every quick-link label.

11

Sections Display

Eight on/off switches controlling section visibility.

04 · Landing System

Built for right-to-left markets

The Middle East pages need Arabic. Rather than maintaining a second design, the template mirrors itself.

Toggle OFF — LTR

landing_configuration
_language_direction

One field. Whole page.
Toggle ON — RTL
Layout, navigation, text alignment and form fields all mirror together — so an Arabic landing page reads as naturally as the English one, with no separate design to maintain.

04 · Landing System

Forms, ready to duplicate

Built with JetFormBuilder and connected to each landing page through a form ID.

  1. 1

    Two master forms are supplied

    One left-to-right and one right-to-left, both already styled to match the landing design.

  2. 2

    Duplicate the one you need

    The team copies the matching master form for a new market instead of building fields from zero.

  3. 3

    Translate the labels

    Only the field labels and messages change — structure, validation and notifications stay intact.

  4. 4

    Paste the ID into the landing

    The landing_form_id field connects the form to the page. Nothing else is required.

05 · Development

A US version of the global website

Built as a proving ground for regional websites — US measurement units only, with its own isolated data.

Location

kemroc.com/us

Installed as a directory on the existing domain, so the US site inherits the domain authority already earned by kemroc.com instead of starting from zero.

Data

Separate database

The US install runs on its own database. Content, users and settings are fully isolated — nothing done there can affect the global site.

Content

US units throughout

Specifications, dimensions and performance figures are presented in imperial units, so US customers read numbers in the form they actually work with.

Purpose

Functionality testing

This version validates the regional-site model — content structure, unit handling and maintenance overhead — before it is rolled out more widely.

Status: live and under evaluation. Findings from this build feed directly into the multisite plan on the next slide.

05 · Development

Next: WordPress Multisite

The directory-plus-separate-database approach proved the concept. The next generation moves to a proper network.

Today — independent installs

  • Complete isolation between regions
  • Fast to stand up for a single test market
  • Plugins and themes updated separately per site
  • Media and users not shared
  • Maintenance effort multiplies with each region

Planned — WordPress Multisite

  • One network, one update for every regional site
  • Themes and plugins installed once, activated per site
  • New market added as a new site in minutes
  • Consistent security posture across all regions
  • Maintenance effort stays flat as regions grow
Scales to as many regional sites as KEMROC needs One dashboard for the whole network Still to confirm: whether premium plugin licences cover a network or bill per site

06 · Corrections

Issues resolved

Fixed

Testimonials page

The issue

The testimonials page was not behaving correctly for visitors, affecting one of the strongest trust signals on the website.

The resolution

The cause was identified and corrected, and the page was verified across devices. Customer success stories now display as intended.

Fixed

Rank Math SEO edits blocked by Wordfence

The issue

SEO fields could not be saved. Wordfence was treating legitimate Rank Math requests as suspicious and blocking them, so titles, descriptions and keywords could not be updated from the editor.

The resolution

The blocked requests were traced in the Wordfence logs and the firewall rule was corrected — without weakening the site's overall protection. Rank Math now saves normally, restoring day-to-day SEO control.

Impact. Both fixes returned control to the KEMROC team: content that visitors see, and the SEO metadata that determines how the site is found.

07 · Infrastructure

Server requirements raised

We audited the hosting environment and submitted a formal upgrade request. Below is what the server reported at the time of the audit, against what we asked for.

SettingValue at auditValue we requested
Web serverApacheLiteSpeed / optimised stack
PHP version7.4.33 end of life8.2 or 8.3
PHP memory_limit256M512M
WP_MEMORY_LIMIT256M
WP_MAX_MEMORY_LIMIT256M512M
upload_max_filesize80M256M
post_max_size80M256M
max_execution_time300+
max_input_vars5000+
Server-side cachingDisabledEnabled

Summary

What KEMROC gained

Speed to market

The three April–May pages each needed design and development time. A page for a new region now needs neither — the marketing team publishes it directly, and the Middle East page is the first live proof.

🎯

Brand consistency

Every market gets the same locked design. Language changes, the presentation does not.

🛡

A secured platform

Malware removed, weekly scanning in place, plugins patched, and the firewall tuned so protection no longer blocks legitimate work.

🌐

A proven regional model

The US build validates the approach for future markets, and points the way to a multisite network that scales without multiplying maintenance.

Independence from developers

Content, visibility, contacts, forms and language direction are all controlled from the dashboard by the KEMROC team.

Looking ahead

Recommended next steps

In priority order, for the coming period.

April — July 2026

Thank you

We're glad to keep building on this platform with the KEMROC team.

Hive Studio

Report prepared by Hive Studio · WordPress maintenance & development partner

1 / 21
Use to navigate · O overview · F fullscreen