Website Migration & Audit · Prepared by Robot Kittens for Yellow Bloom

drreneecomizio.com

A complete recovery, forensic audit, and rebuild of Dr. Renee Comizio's practice website — migrated off inherited hosting after the original developer's passing, cleaned of orphaned licenses and dead weight, and staged for review.

Live staging preview

Original developer Firm Media (firm-media.com) Platform WordPress 7.0.2 Status Staged & verified

The previous developer had passed away, leaving no handoff, no license access, and no server access beyond a single cPanel login with SSH disabled. We recovered the site in full, audited every plugin against real evidence of use, and rebuilt it on managed infrastructure — lighter, safer, and under your control.

Active plugins
2820
8 removed, 0 features lost
Media library
434MB229MB
−47% lighter
Oversized photos
217MB12MB
−94%, visually identical
Paid-license liabilities
40
orphaned licenses cleared
Advanced Custom Fields
5.8.56.8.6
relicensed & current
Orphaned remote access
Closed
ManageWP + Jetpack removed
On performance & SEO scores

A PageSpeed test of the staging site shows SEO lower than the live site — this is expected and temporary. Staging is deliberately set to "no-index" so it can't compete with the live site in Google, and PageSpeed penalizes that. On the real domain the SEO score returns to its previous level. Everything else measured improved: performance, accessibility, and best-practices scores all went up.

01 · Access recovery

Getting back in

The only inherited access was one cPanel login per site, with SSH disabled at the host and no reseller/WHM access. Rather than wait on the host, we used cPanel's built-in terminal to package each site, pulled a complete backup down locally, and rebuilt on Robot Kittens' managed server — where you now hold full root/SSH control. Along the way we recovered something valuable: the developer's Git repository was still embedded in the site, giving us the complete source history of the custom theme and plugins back to 2016.

02 · Plugin audit

Every plugin, judged on evidence

Nothing was removed on assumption. Each plugin was tested three ways — against the database (is its shortcode on a published page? does it hold real data?), the theme code (does a template actually call it?), and the live rendered HTML (does it reach a visitor?). A plugin was removed only when all three came back empty.

PluginVerdictEvidence
Gravity Forms + Styles add-onRemovedBoth forms set inactive, zero embeds on any page, last entry Sept 2024. Superseded by Contact Form 7. Paid license, orphaned.
JetpackRemovedNot connected to WordPress.com (connection belonged to the late developer). 12 modules loaded, none functioning. No front-end footprint.
ManageWP WorkerRemovedLive remote-control channel into a dashboard nobody holds. Security priority.
UpdraftPlusRemovedOn-server backups (158 MB) made redundant by the new host's off-server snapshots.
WP Mail SMTP ProRemovedConfigured to plain PHP mail — the Pro features were never used. Replaced with the free edition. Paid license, wasted.
WP RocketRemovedPage-caching plugin (paid). The new host caches at the edge via Cloudflare, making it redundant. Paid license, retired.
Head & Footer Code, WP Sitemap PageRemovedEmpty / unused. Google Tag Manager and the sitemap are handled by other, active plugins.
Advanced Custom Fields ProRelicensed & upgradedLoad-bearing — 14 field groups, 2,253 values across the site. Moved to your own license and updated 5.8.5 → 6.8.6, verified rendering intact.
Contact Form 7 + CFDB7, Redirection, Popup Maker, Wordfence, AIOSEO, Font Awesome, custom fm-* pluginsKeptAll confirmed in active use — forms, 3,898 stored inquiries, 34 live redirects, security, SEO, and the practice's custom content types.
03 · Security & orphaned credentials

Closing the doors left open

When a developer passes, their accounts and keys don't. Several live channels were still wired to services no one on your side controls — each one a standing risk. We closed them.

ManageWP + Jetpack remote access — closed

Both maintained a live connection from the site to external dashboards owned by the late developer's accounts. Removed entirely.

reCAPTCHA keys — replaced

The old spam-protection keys belonged to the developer's Google account and were domain-locked to the old address. Replaced with a fresh client-owned reCAPTCHA v3 key pair, retrieved securely from 1Password and live on the site.

Orphaned paid licenses — cleared

ACF Pro, Gravity Forms, WP Rocket, and WP Mail SMTP Pro were all licensed to the developer's agency. ACF is now on your license; the rest were removed or replaced, ending the exposure.

WordPress core replaced with a clean copy

Rebuilt on a pristine WordPress 7.0.2 core rather than carrying the inherited files forward — your custom theme and plugins are the only non-standard code on the site.

04 · Media optimization

Half the weight, none of the loss

The 452 MB media library was audited against the database for orphans and oversized files. The real culprit wasn't clutter — it was 21 full-resolution stock photos stored at print size (up to 24 MB each) and served on a website. We removed 56 genuinely unused files, then resized the oversized originals to web resolution. Because the site already serves smaller thumbnails to visitors, the change is invisible on screen.

Unused files removed
56
19MB, all pre-2017
Oversized photos
217MB12MB
20 files, −94%
Largest single image
24MB0.9MB
same on screen
05 · Data preserved

Nothing important was thrown away

Before removing any plugin, every piece of real data it held was exported and archived for the practice:

⚑ Worth the practice's attention

Stored form submissions stop in September 2024, though the site was edited into 2026. Either the submission-logging quietly broke, or inquiries have gone unrecorded for ~2 years. We recommend confirming the practice's contact-form emails are actually arriving — this is a lead-capture question bigger than the migration itself.

⚑ Please confirm — homepage consultation form

During the audit we found the homepage's "Request a Consultation" form was embedded (through a theme field) with an old Gravity Forms shortcode pointing to a form that had been deactivated. With Gravity Forms retired — and that form already inactive — it was very likely showing as broken or empty on the current live site as well. We restored a working Contact Form 7 version (below). Because it appears to have been missing in production, it's worth confirming with the practice whether they actually want a consultation form here, or prefer to route inquiries another way.

Restored consultation form on the homepage
The homepage "Request a Consultation" form, now rendering via Contact Form 7 on staging.
06 · Visual verification

Pixel-for-pixel, it's the same site

The rebuild was checked against both the live production site and the developer's dev copy. The homepage renders identically across all three — the migration changed what's under the site, not what visitors see.

Live (before) · drreneecomizio.com
Live homepage
Rebuilt (after) · staging
Staging homepage
Dev reference · dev.drreneecomizio.com
Dev homepage
07 · Outstanding items

What's left before go-live

Amendment · July 18, 2026

Performance & accessibility improvements

After the migration we ran a technical optimization pass on the rebuilt site. Two areas improved measurably — how fast the site loads, and how usable it is for people with disabilities. The second one also reduces the practice's legal exposure (more below).

Server response
530ms~50ms
page caching
Images (WebP)
−88%
2,298 images, modern format
Render-blocking
1,880ms1,050ms
async fonts & icons
Accessibility score
7192
automated audit, out of 100

Speed

Text compression, next-gen WebP images (up to 88% smaller), page caching, preconnects, and non-blocking fonts — plus structured data and an llms.txt so search engines and AI assistants understand the practice. Most of these compound further on the production host's CDN.

Accessibility — and why it lowers legal risk

We fixed the issues an automated audit flags against WCAG (the accessibility standard the ADA is measured by): contact-form fields that had no labels for screen readers, icon-only phone/email/social links with no accessible name, an unlabeled menu control, and invalid keyboard tab order. The automated accessibility score rose from 71 to 92.

⚑ Why this matters legally

ADA website-accessibility demand letters and lawsuits have surged, and healthcare and medical practices are among the most frequently targeted. A site that fails basic WCAG checks — unlabeled forms, unnamed links — is exactly what these claims cite. Bringing the site into much closer conformance materially reduces that exposure and shows good-faith remediation. (This is risk reduction, not a compliance guarantee or legal advice — full conformance should be confirmed with an accessibility specialist.)

Three low-level items remain, and each is a decision rather than a quick fix: one eyebrow's contrast would require slightly darkening a brand background color, a heading order lives inside a third-party reviews plugin, and a mobile-menu focus detail is internal to the site's UI framework.