img
Muhammad Furqan

Speed, Core Web Vitals & Security

Almost every site I am asked to speed up has already been told it needs a rebuild. Most of them do not. What they need is images at the right size, caching configured properly, a plugin audit, a database clean and hosting that is not the bottleneck.

That work takes about a day and it costs a fraction of a rebuild. I do it first and tell you the result honestly, because finding out the platform was never the problem is a good outcome for you even though it is a smaller invoice for me.

Measuring the right thing

A performance report on your home page on desktop tells you very little. Your actual visitor is on a mid-range Android phone on a mediocre connection, landing on a long service page or a checkout, often at a busy time of day.

So that is what gets measured: real pages, mobile, throttled, before and after. Field data from Search Console rather than lab scores alone, because the score you can screenshot and the experience your customers have are not the same number.

The work, in the order I do it

  • Images. Almost always the largest single problem. Resize to the dimensions actually displayed, convert to WebP, lazy load below the fold and explicitly do not lazy load the hero, which is a common and self-defeating mistake.
  • Caching. WP Rocket or the host's own layer, configured with commerce in mind so cart and checkout stay uncached while everything else benefits.
  • Plugin audit. Every active plugin judged on whether it is used, whether something else already does it, and whether it loads assets on pages that do not need them. Removing overlap routinely beats any theme change.
  • Database. Post revisions, expired transients and orphaned metadata cleaned out. Improves admin responsiveness and helps checkout.
  • Hosting. Changed last by most people and often the highest impact. Cheap shared hosting sets a floor no optimisation gets under. Cloudflare, WP Engine and SiteGround all work well when configured properly.
  • Third party scripts. Chat widgets, tracking, embeds. Deferred, scoped to relevant pages, or removed where they cost more than they return.

What the three numbers actually mean

Core Web Vitals gets discussed as a score. It is really three separate questions about the experience, and knowing which one you are failing tells you what to fix.

  • Largest Contentful Paint. How long until the main thing on the page appears. Under 2.5 seconds is the target. This is almost always images or slow server response, and it is the one most closely tied to conversion: stores under 2.5s convert meaningfully better than those above four.
  • Interaction to Next Paint. How quickly the page responds when someone taps. This is JavaScript weight, and it is where builder sites and stacked plugins hurt most, particularly on mid-range Android phones.
  • Cumulative Layout Shift. Whether things jump around as the page loads. Usually images without dimensions, injected banners or late-loading fonts. It is the cheapest of the three to fix and the most irritating to experience, because it makes people tap the wrong thing.

The reason to separate them is that the fixes barely overlap. Compressing images does nothing for a page that is slow to respond, and trimming JavaScript does nothing for a hero image that is four times larger than the slot it renders in.

Security, which is the same job

WordPress runs roughly 42% of the web, which makes it a large target. The honest position is that it needs maintenance rather than luck: current core, themes and plugins, a security layer, real backups held somewhere other than the same server, and someone paying attention.

I work with MalCare and BlogVault for hardening, monitoring and backup, and I handle malware cleanup and recovery when a site has already been compromised. If you have been hacked once and nothing changed afterwards, you will be hacked again.

What you get

  • A before and after measured on your real pages, on mobile, with the method documented so you can repeat it.
  • Every fix above applied and verified rather than assumed.
  • Security hardening, monitoring and offsite backups configured.
  • Malware cleanup and recovery where needed, including the follow-up that stops it recurring.
  • A written summary of what was wrong, what changed, and what is left. If the remaining constraint is your theme or your hosting, you will be told plainly.

Common questions

Will you get me a 100 score?

I will not chase one, and you should be wary of anyone who promises it. A perfect lab score on a page nobody buys from is worth less than a good real-world experience on your checkout. I optimise the journey your customers actually take.

Do I need to leave my page builder?

Often no. Both major builders are fast enough for most sites once the images, caching, plugins and hosting are sorted. If after all that the builder is genuinely the remaining constraint, you will know, and it will be an evidence based decision rather than a suspicion.

How long does it take?

The audit and cheap fixes are usually a day or two. Deeper work depends on what is found. You get the measurement first, so you can decide how far to go.

Start free: test your longest page on mobile with a throttled connection, and count your active plugins. Send me both numbers and I will tell you roughly what you are dealing with.

Previous WooCommerce & E-commerce Development Next Search Visibility & Conversion

Not sure this is the one you need?

Tell me what is actually going wrong and I will tell you which of these fixes it, including when the answer is something cheaper than what you came here for.

Start a Conversation

I'm Muhammad Furqan, a Full Stack Developer and AI Engineer based in Lahore, Pakistan. 250+ high-performance websites delivered across the USA, UAE, UK and Pakistan.

address Lahore, Punjab, Pakistan
Let's Talk

I'm Muhammad Furqan, a Full Stack Developer and AI Engineer. 250+ high-performance websites delivered across the USA, UAE, UK and Pakistan.

address Lahore, Punjab, Pakistan
Let's Talk