A website can serve a business reliably for years and still reach a point where every addition creates another dependency. That was the situation of a specialist provider of personal online language education. The roughly seven-year-old site was established, visible in search and supported by an unusually large archive of authentic testimonials. Its structure, technology and user journey, however, no longer matched the offer that had developed over time.
The original assignment was therefore not “build a new website”. It was a complete website audit, including a competitive benchmark and a clearly prioritised action plan.
The starting point: mature, but difficult to move
The existing site relied on WordPress, a commercial page builder and an extension landscape accumulated over several years. It included components for layout and forms, SEO, cookie consent, analytics, booking, messaging, sliders, email delivery, caching and security.
No single component was necessarily a problem. Together, however, they formed a tightly coupled system:
- updates required compatibility checks across several extensions;
- public code disclosed the CMS, builder and some extension versions;
- presentation, consent and booking depended on numerous scripts and external services;
- content and navigation increasingly followed system constraints rather than current customer questions;
- a major renovation would have affected templates, extensions, redirects, metadata and consent logic as well as content and design.
At the same time, the site had valuable strengths that had to survive: credible personal positioning, long experience, a clearly defined specialist offer, transparent information and an extensive body of genuine customer references.
The audit: strong substance, weak digital packaging
We examined approximately 20 public URL variants, core pages on desktop and mobile, server responses, metadata, redirects, forms, third-party dependencies and the primary booking journey. We also benchmarked the site against ten relevant market participants using one consistent criteria framework.
The outcome was deliberately balanced. The site sat in the competitive middle for public web execution but personal trust was one of its strongest dimensions. The problem was not the quality of the service. The problem was that this quality appeared too late, too broadly and with unnecessary technical friction.
The three audit pillars
Audiences, services, evidence, price and one clear next step.
First viewport, mobile, accessibility, consent and resilient booking.
HTTPS, language, metadata, security headers and dependencies.
1. Content and positioning
The most valuable arguments were present but did not form a coherent decision journey. Priority audiences and situations were not differentiated early enough. The lowest-risk first step competed with several similarly weighted calls to action. A deep testimonial archive was not curated by starting situation and outcome. Price, availability, process and rules did not answer objections at every relevant decision point.
The benchmark revealed a clear opportunity: do not imitate the breadth of large portals. Combine personal specialisation, convincing evidence and precise visitor qualification more effectively.
2. Design and user experience
The recognisable colour identity was worth retaining. Large generic group images, however, suggested a different service from personal adult tuition. The core proposition and next step appeared too low on common screens. On mobile, the consent dialogue covered almost the entire first viewport, while the external booking embed had no sufficiently visible fallback when scripts were blocked.
Long centred blocks and dense testimonial pages made scanning difficult. More than 100 missing alternative-text entries across the inspected views required a systematic accessibility review.
3. Technology, security and findability
Essential content was already available in server-rendered HTML, encryption worked and crawlers were not generally blocked. Even so, the audit found one critical issue and several high priorities:
- the HTTP version served content instead of redirecting immediately to HTTPS;
- Slovak pages were incorrectly labelled as German in the HTML;
- important security headers were absent;
- two public sitemap surfaces showed different freshness;
- archive pages reused titles and lacked a deliberate indexation strategy;
- structured data did not adequately describe the person, services and offers;
- the builder, consent system, analytics, widgets and extensions produced a large asset and third-party footprint.
The decision: renovate or rebuild?
An incremental renovation would have retained the page builder, most dependencies and much of the technical complexity. Many changes would have needed to be designed twice: once for the desired improvement and once for compatibility with the legacy system.
A rebuild allowed content, user journey and architecture to follow the audit findings directly. Existing URLs and valuable content remained a binding migration contract; the technical baggage did not. Because the offer, audience communication, imagery and central functions all required fundamental change, a clean rebuild was not only clearer but likely more economical.
The rebuild through the three pillars
Content: The information architecture now follows user intent. Substantial standalone pages cover the main situations. References can be found by theme without rewriting historical statements. Every indexable page received its own title, description, heading, canonical URL and appropriate structured data.
UX: The imagery was completely renewed. One consistent primary action leads through the site. The first viewport works on desktop and mobile, and contact fields are limited to what is necessary. If a visitor rejects optional content or the browser blocks an external script, a direct booking route and contact alternatives remain visible.
Technology: The new website is a lean server-rendered PHP application. A database is used only where structured data and protected editing genuinely require it. There is no CMS, page builder or production JavaScript framework. Fonts, images, CSS and essential scripts are served locally.
Security controls were introduced in stages: hardened forms, CSRF protection, rate limits, private configuration outside the web root, restrictive browser headers and policies tightened only after successful observation.
Two purpose-built functions instead of another plugin chain
A professionally designed language assessment
The new site includes its own B1–C2 orientation test with 40 independently written questions. It covers grammar, vocabulary, collocations, reading, register and pragmatics. The result considers both the total score and consistent achievement across the levels that build on each other.
Answer order is randomised for each attempt and remains stable during that attempt. The test creates no personal learning profile and states its limits clearly: it is guidance, not a certificate or a complete assessment of speaking, writing, pronunciation, listening and spontaneous interaction. The page deliberately remained outside search indexes until professional testing was complete.
A booking journey built on the client’s calendar
The external calendar managed by the client remains the operational source, but the website now provides its own fully integrated booking logic. Only appointments explicitly marked as free in the designated calendar are publicly bookable. Gaps between calendar entries are never treated as availability. A short internal reservation protects a selected slot during data entry or payment and prevents double booking.
The solution supports different durations, single and multiple bookings, optional online payment, confirmations, calendar files, reminders and protected cancellation. Every external step receives a unique processing key, and the actual calendar state is checked again after a write. Ambiguous errors are not repeated blindly. If a successful payment cannot be converted into a safe booking, an automatic refund is provided for.
Personal data is written neither to public calendar titles nor to technical logs. The payment service and the client-managed calendar are therefore the only substantial external systems, each connected through tightly limited interfaces.
A controlled transition, not a big bang
CMS and extensions
Content, UX and technology
Migration and acceptance
Clear, secure and independent
The rebuild was first developed in a protected environment kept consistently on noindex. Legacy URLs, redirects and content were recorded in a migration matrix. Before the switch, we created complete file and database backups, inventories, SHA-256 checksums and a documented rollback route.
Acceptance covered multiple page types on desktop and mobile, navigation, keyboard operation, forms, consent changes, booking fallback, structured data, sitemap, error pages and static assets. Only after successful technical and visual review did the new system replace the WordPress web root.
The audit did more than produce a list of defects. It prevented a substantial investment in a structure that would have made the next stage more difficult. The rebuild was therefore not an end in itself, but the demonstrably more sensible solution.
The central lesson: An older website does not need to be rebuilt simply because it is old. When content, user journey and technical dependencies all require fundamental change, a well-planned rebuild can be safer, simpler and less expensive than years of continued repair.