
Heart & Science International/Professional services
Contained the compromise, rebuilt with nothing left to attack, in under a month
Heart & Science International's site had been broken into. DevLime shut off the attacker's access within days, then rebuilt the site rather than patching it. What replaced it is a set of plain files with no content system, no database and no login page behind them. A first version was live in nine days and the finished site followed two weeks later. The new homepage ships 89% less HTML than the page it replaced and asks nothing of any other company's servers.
Visit the siteUnder a month
Rebuild time
Work started 17 August and the last pre-launch fix landed 9 September.
89% smaller
Homepage HTML
51 KB on the new homepage, against 462 KB on the page it replaced.
9 days
First version live
Live on hosting 26 August, with content still moving for two weeks after that.
0
Third-party scripts
The homepage loads one 6.5 KB file of ours and nothing from another company's servers.
Nothing
Left to break into
No content system, no database and no login page; what ships is plain HTML, CSS and images.
Challenge
The site ran on WordPress. That means a program on the server, a database behind it, a login page anyone can find, and third-party plugin code running on every visit. Those four things have to be watched, patched and defended, forever. The site was broken into. Cleaning up the installation would have left all four exactly where they were, and the next attacker would find the same four doors. Whatever replaced it also had to stand up to scrutiny: this is a firm whose buyers check before they sign.
Approach
Containment came first: shut off the attacker's access and clear out what had been injected. The rebuild then made the decision that shaped everything after it — take the machinery away rather than defend it. Every page is now built once, on a developer's machine, into a plain file the server only has to hand over. The contact form posts straight to a hosted service, so even that runs nothing of ours. The browser is instructed to ignore anything embedded in a page. An automated check runs before each deploy, so a stray script, a borrowed asset or a broken link fails the build.
Outcome
The site is live at hsiorg.com across 20 pages. Its federal contracting section links the firm's live SAM.gov record and SBA certifications profile. A government buyer can verify the credentials rather than take the page's word for them. The homepage loads one small file of ours and nothing from anywhere else: no analytics, no tracking pixels, no borrowed fonts. A pre-launch accessibility review closed the last findings, including label text that was too faint to read comfortably. Releases are made without any stored password or key, so the project holds no credential worth stealing.




