Full-Stack Website Audit, CMS Development, Security Hardening & Production Deployment

via Freelancer ·

Budget / Salary$250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
Project Overview

I am seeking an experienced full-stack developer or small team to audit, improve, secure, and modernize an existing production website and infrastructure.

This is **not a greenfield project**. An existing frontend, backend/API, PostgreSQL database, content, media, forms, administrative functionality, Docker deployment, and VPS environment are already in place.

The objective is to preserve all existing content and required functionality while creating a secure, stable, maintainable system with comprehensive administrator content management.

Current Stack

* Next.js / React / TypeScript
* Node.js
* PostgreSQL
* Docker
* Nginx
* Linux VPS

The existing stack may be retained, refactored, or partially rebuilt where technically justified.

1. Audit, Backup & Implementation Plan

Before major changes:

* Create and verify backups of the application, database, media/data, and required configuration.
* Audit frontend, backend/API, database, admin/CMS, routes, forms, integrations, Docker, Nginx, VPS, deployment, and security.
* Identify technical/security issues and incomplete functionality.
* Recommend what should be preserved, repaired, refactored, or rebuilt.
* Provide a safe implementation/migration plan.

2. Data & Content Preservation

Preserve all required existing content and data, including pages, images/media, blog/content entries, reviews/testimonials, FAQs, form/business records, SEO metadata, and database records.

Database/schema changes must use controlled migrations. No required data may be lost, and migration integrity must be verified.

3. Backend & Admin/CMS

Review the existing administrative functionality and improve, refactor, or replace it as appropriate.

The final secure CMS/admin dashboard must allow a non-technical administrator to manage normal website content without editing code.

Admin must be able to manage:

* Pages and page content
* Images/media and alt text
* Blog/content entries
* Reviews/testimonials
* FAQs
* Navigation/menus
* SEO settings
* Form submissions

Admin must also be able to create new pages, edit pages, publish/unpublish pages, manage URLs/slugs, and upload/replace media.

**Normal new pages and content must be creatable through the CMS without source-code modification or application redeployment.**

4. Contact Forms & Email

All applicable forms must:

* Validate submissions.
* Save submissions to the database.
* Display submissions in admin.
* Send email notifications containing submitted information.
* Support configurable notification recipient(s).
* Include spam/abuse protection.
* Log email delivery failures.
* Provide appropriate user success/error confirmation.

5. SEO

Preserve existing SEO value and metadata.

Implement as applicable:

* Existing URL preservation
* 301 redirects when URLs change
* Editable titles/descriptions
* Canonical URLs
* Sitemap.xml
* Robots.txt
* Image alt text
* Social/Open Graph metadata
* Appropriate structured metadata
* Prevention of admin/staging/private indexing

The overhaul must avoid unnecessary loss of existing search-engine indexing/rankings.

6. Authentication & Security

Review and harden application and server security, including:

* Secure admin authentication and protected routes
* Appropriate roles/permissions
* Secure password and session/token handling
* Input validation/sanitization
* Protection against common vulnerabilities including SQL injection, XSS, CSRF, authentication abuse, brute-force attacks, and malicious uploads
* Secure media uploads
* Rate limiting/abuse protection where appropriate
* Secure HTTP configuration/headers
* Dependency/security review
* Proper secrets/environment management
* Least-privilege access
* No secrets stored in source code
* Database/internal services not unnecessarily exposed publicly
* Docker, Nginx, and VPS hardening

Provide a summary of vulnerabilities identified, remediation performed, and remaining recommendations.

7. Infrastructure & Production Deployment

Provide a clean, reproducible, documented deployment including:

* Dockerized services
* Docker Compose
* Nginx reverse proxy
* SSL/HTTPS
* Appropriate firewall/network configuration
* Health checks
* Automatic restart policies
* Secure environment/secrets configuration
* Production logging and log rotation
* Reliable recovery after container/service restart and VPS reboot

Testing/deployment should minimize production disruption. Use a safe cutover/rollback approach where appropriate.

8. Performance, Monitoring & Compatibility

Review and optimize page loading, images/media, frontend assets, and API/database performance.

Verify proper operation on desktop, tablet, mobile, and major modern browsers.

Implement appropriate monitoring for website uptime, application/container failures, critical errors, CPU, RAM, and disk usage, with reasonable alerts where appropriate.

9. Automated Backups & Disaster Recovery

Implement automated backups for required:

* PostgreSQL data
* Uploaded media/content
* Required application/configuration data

Define appropriate retention and document recovery procedures.

At least one actual backup restoration must be successfully tested before final acceptance.

10. Testing, Documentation & Handover

Perform complete production testing, including:

* Public pages/routes and existing functionality
* Admin authentication/CMS
* Creating and publishing a new page through admin
* Content/media management
* Blog, reviews, FAQs and navigation
* SEO management
* Forms, database storage and email notifications
* Mobile/desktop/browser compatibility
* SSL/HTTPS
* Container/service restart
* VPS reboot/recovery
* Backup and successful restoration

Provide documentation covering architecture, deployment, Docker Compose, Nginx, environment configuration, database migrations, CMS operation, backups/restoration, monitoring, security, and routine maintenance.

Another qualified developer should be able to deploy and maintain the system using the documentation.

Ownership

At completion, client must receive/control all required:

* Source code
* Database schema/migrations
* Docker/Docker Compose configuration
* Required server/Nginx configuration
* Documentation
* Production credentials/accounts

The completed system must not depend on undocumented developer-owned accounts, credentials, services, or proprietary components controlled exclusively by the developer.

Access & Confidentiality

The website URL, repository, server information, credentials, business information, and other identifying details will **not be disclosed publicly during bidding**.

Necessary access will be provided to the selected developer after engagement and any required confidentiality agreement.

Timeline

The target completion period is approximately **two weeks from project start**, assuming the initial audit confirms the existing system can reasonably be repaired/refactored within that timeframe.

If significant previously unknown problems require substantial additional work or rebuilding, they must be documented and discussed before materially changing scope or timeline.

Final Acceptance

The project is complete only when:

* Required existing functionality and data are preserved.
* CMS/admin requirements are operational.
* New pages can be created and managed through admin.
* Forms and email notifications work.
* SEO requirements are completed.
* Security hardening is completed.
* Production deployment is stable.
* Monitoring and automated backups are operational.
* Backup restoration is successfully tested.
* Documentation and ownership materials are delivered.
* Final production testing is successfully completed.
* Critical defects are resolved.

Proposal Requirements

Please include:

* Relevant full-stack experience and comparable projects
* CMS/admin development experience
* Security and Docker/Nginx/Linux experience
* Proposed approach
* Estimated completion time
* Fixed-price quote

Identify anything you consider outside your quoted scope **before accepting the project**.

Payment Terms

This is a **fixed-price project**. Final payment will be released after successful completion and verification of the agreed requirements, successful production deployment, delivery of documentation and ownership materials, and satisfaction of the final acceptance criteria. THE PRICE YOU BID IS THE BINDING PRICE FOR THE PROJECT (DO NOT BID RANDOM B.S. AND THEN TRY TO ESTIMATE THE PROJECT)

Please read all of the terms and conditions of this project and do not submit bids that are only for audit or other proposals.
This project is open only to United States- and Canada-based developers and companies!!!
linux nginx node.js postgresql docker web development full stack development backend development api development next.js
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.