
01Website Rebuild & Migration
Jim Bodine Magic
A cheap template WordPress site, sold by another local agency and left to rot, got hacked — and took a Lake Havasu magic show's entire online identity down with it.
Visit live site02 The Challenge
Jim Bodine performs close-up magic for an audience of 32 every Monday night at the London Bridge Resort — a decade of consecutive seasons, 67 reviews at a perfect 5.0 average, and the #1 spot on Google for his category. The reputation was never the problem.
The site he'd been sold was the kind a lot of local businesses get handed: a cheap template dropped onto WordPress by another local agency, invoiced, and left to sit. Cheap is the wrong word for it, though — that's a description of the build, not the bill. It cost him more than this rebuild did.
And what he got for the money was a login page, a database, and a stack of third-party add-ons — every one of them a door, every one needing to stay locked forever, and not one of them the owner's job to watch. One of those doors was left open, and the site was broken into through exactly the kind of back door that setup creates.
What that did to his business went well past having an ugly website. Google flagged the domain, and once that happens the address itself stops working everywhere at once. He couldn't email his own web address to anyone without it being marked a security risk. He couldn't post it. Every browser threw a full-page red warning at anyone who tried to open it. Even copying and pasting the link on a computer or a phone tripped the same check. Anyone who typed the address off a flyer or a business card got a warning screen instead of the show.
A working business had been cut off from its own name — and the #1 ranking made it worse, not better, because every one of those roads led people to a door they were being told not to walk through. He went back to the people who had built and handled the site for him — the agencies and designers who sold it to him in the first place. They didn't return his calls. They didn't answer his emails.
That is its own kind of damage. The website was one problem; being left alone with it was the bigger one, with a season coming and no way to point anybody at his own business. By the time he reached us he wasn't shopping for a website. He was looking for someone who would pick up the phone and get his business its own address back.
03 Our Solution
We built the new site static — pre-built pages served as files. No login page, no database, no plugins. The category of attack that took the old site down has no surface to land on. That was the specification, not a side effect: Jim's stated priority was that this never happen twice.
Every piece of proof on the page is his own. We recovered 82 real customer reviews from the old site — 61 Google, 21 Tripadvisor — and republished them with names and dates as two auto-panning marquees instead of three anonymous quotes in a box. An 18-second clip of actual guests reacting was compressed from 48MB to 3.4MB with the audio intact, so you hear the room. The photograph of the resort marquee at dusk was restored to full resolution from a small original with the sign wording and blue-hour composition preserved exactly. No stock photography, no AI-generated imagery of the show. One conversion goal throughout: Get Tickets.
The migration was engineered to carry the equity, not just to work. Every version of the old web address now sends people straight to the new site in one clean step, landing them on the matching page — every extra bounce along the way is somewhere search ranking leaks out. Mail records were left untouched on both domains, and we proved the client's old inbox still worked by sending a real message through the new contact form rather than assuming it. Printed flyers and business cards still route people to the right place.
The client had already bought his own hosting and wanted everything under one company he could call, so we deployed there — on a plan that strips out the automatic certificate tooling that normally makes HTTPS a non-event. Rather than launch it unsecured or stall the whole thing, we issued the certificate by hand so the site went live secure on day one, then worked with his host directly to switch on the one he had already paid for. Because static sites on shared hosting have nowhere to run form code, his contact form runs on our equipment and emails him directly. It is locked to his site alone, screened for spam, and keeps no copy of anything — no database, nothing stored. His enquiries go to him and nowhere else.
Then we got the warning lifted. Prove ownership of the old domain the manual way rather than the one-click way, because the shortcut would have handed Google write access to the account that also controls his business email. Audit who else already had verified ownership. Read the actual detection instead of guessing at it. File the review stating plainly what had changed. Approved the same day — because the compromised pages were already unreachable at the moment we filed. Filing while the bad pages are still live is what turns this into a multi-week loop.
04 Key Results
- 01Google’s warning removed — independently confirmed as "No unsafe content found"
- 02His address works everywhere again — emailable, postable, pasteable, no warnings
- 03Rebuilt static: no login page, no database, no plugins to exploit
- 04Old domain redirects in a single hop from all four address variants, path preserved
- 05Printed flyers and business cards still route to the live site
- 06Client's existing email address kept working — verified end to end, not assumed
- 0782 real customer reviews recovered from the old site and republished
- 08HTTPS live on day one on hosting that doesn't provision it automatically
- 09Contact form stores nothing — messages pass straight through to his inbox
- 10Domain, hosting, code and certificate all in the client's own name
05 More Projects
Ready to build something like this for your business?
Let's talk about your goals and see how we can help you grow online.


