Transport · ground operations · South Africa

42 pages in one day.

Their site had been hacked, filled with casino spam, and had collapsed into a broken shell. A 42-page replacement with a live booking engine and a server-authoritative pricing layer was built in one day.

The situation

Your website is the front door and it has been kicked in. Attackers injected online-casino spam into the WordPress build, and then the whole thing collapsed into a broken shell. For months, anyone searching for you found either spam or nothing. The bookings still had to happen, so they happened on the phone, by hand, one call at a time.

What was built

A 42-page replacement site, rebuilt from the operator's own recovered content and their own photography. A booking engine with two funnels — transfers and tours — with live price preview and a server-side price recompute, so the price the browser claims is ignored and the price the server calculates is the one stored. An admin console behind a gated session with a proper booking state machine, a payment-link flow, an event timeline per booking, and a daily manifest that arrives at 06:00. Off-matrix and oversize jobs route to a separate quote funnel instead of failing silently.

The result

Built in one day. Verified end to end against a live database — price tampering, over-capacity, past-date, honeypot, rate limiting, forged sessions, every admin state transition. Because it handles customer data, payment information and an admin login, it went through two independent adversarial security audits before launch: no critical and no high-severity findings. The medium and low items — session-secret strength, rate-limit hardening, constant-time comparison on the scheduled-job secret, request body caps — were fixed before it went anywhere.

42 pages

in one day

transport operator

Results are real; clients unnamed by request.

Built. Run. Owned.