Web Design · Development · Security

Design, build,and secure your site.

Custom responsive web development, security testing for sites and systems, and managed hosting to keep it all running. From the build and protection to long-term upkeep — so your online service stays secure and dependable.

WordPressDjangoProgrammingRWDVulnerability ScanSocial EngineeringHealth Check
Web DesignWordPressSystem DevVulnerability ScanSocial EngineeringHealth CheckManaged HostingCloud Deploy
01Work & Reports

Work & Sample Reports

Real, shipped development work plus de-identified sample assessment reports. Report cards use fictional data to show format and quality only; real reports are delivered solely to the client under confidentiality.

Tendforge — Focused WordPress Plugins
WorkWebLive

Tendforge — Focused WordPress Plugins

Focused WordPress Plugins

Six self-built, live WordPress plugins — each solving one specific problem, with a full-featured free tier under GPLv2.

Products
0 plugins
Tests
0 automated tests
Quality
Passes Plugin Check
WordPressPHPWooCommerce
tendforge.com
02Services

What I can do for you

Web & System DevelopmentDevelopment

From brand sites to custom systems — I build the server environment myself, free of platform lock-in.

01

WordPress Sites

WordPress / RWD

  • Responsive design that adapts to desktop, tablet and phone
  • Built from scratch on Linux / VPS, free of platform lock-in
  • Visual layout design, front-end build and basic SEO setup
Project quote
02

Custom Systems

Backend / Web App

  • Membership, database and admin back office
  • LINE Bot and integrations with various programs and APIs
  • Self-hosted VPS environment for better performance
Project quote

Security AssessmentSecurity Assessment

Find the real weaknesses in your systems and how to fix them; items marked as subcontracting are open to security peers too.

03Available for subcontracting

Web Vulnerability Scan

Web Application VA

  • Scans web-app weaknesses by OWASP Top 10
  • Itemised with risk level and impact
  • Manual false-positive checks, fixes and a re-scan
$18,000from / URL
04Available for subcontracting

Host Vulnerability Scan

Host / Network VA

  • Scans known flaws in OS and service versions
  • Open ports and misconfigurations, graded by CVSS
  • $600 per IP beyond the first 10
$15,000/ 0–10 IPs
05Available for subcontracting

Social Engineering

Social Engineering Assessment

  • Phishing exercise measuring open, click and submit rates
  • Weakness analysis by department and role, with training advice
  • Per-recipient open and click records available
$30,000from / up to 300 people
06

Host / Server Health Check

Host / Server Health Check

  • For hosts and servers alike, priced per machine
  • My own tool audits running processes, patches, accounts and installed software
  • Processes checked against VirusTotal; flags suspicious accounts and risky software, with hardening advice
$2,000/ machine

Managed ServicesManaged Services

Looked after after delivery, so teams with no IT staff can run with confidence.

07

Managed Server

Managed Server / Hosting

  • Full-host care for small businesses with no IT staff
  • Updates, security patching, uptime monitoring and twice-monthly off-site backups
  • Fully managed (host included) or ops-only on your own host
$5,000from / mo
08

Managed WordPress

Managed WordPress

  • Core, theme and plugin updates, tested for compatibility first
  • Twice-monthly off-site backups, uptime monitoring and alerts
  • Performance tuning, SSL upkeep, and emergency containment and restore after a breach
$3,000from / mo
03Toolkit

Skills & Tools

DevelopmentDevelopment
WordPressDjangoPythonHTML / CSSRWDGit
SecuritySecurity
NessusNmapBurp SuiteAcunetixOWASP Top 10Kali Linux
Ops / InfrastructureOps / Infrastructure
VMwareDockerNginxVPS / LinuxCloudflare
04How We Work

How I work

  1. 01

    Consult & scope

    We talk through your goals, scope and expectations — a free initial consult to confirm I can help before going further.

  2. 02

    Quote & scope lock

    A clear quote and timeline for your needs; an NDA can be signed. Security testing also gets separate written authorization defining the lawful scope.

  3. 03

    Execution & reporting

    Development progress reported in stages; assessment findings recorded — transparent throughout.

  4. 04

    Delivery & follow-up

    Acceptance and go-live, or a full assessment report with fixes — plus the follow-up support you need.

05About

About me

Both web developer and security tester — from build to protection, handled end to end.

For builds, I can stand up WordPress and full server environments from scratch on Linux / VPS, free of platform lock-in; I also build custom systems with a back office and database, using whichever language fits the job — Python, JavaScript and so on.

On security, I offer vulnerability scanning, social-engineering exercises and host / server health checks — surfacing real risks and proposing fixes and hardening. These are also available as subcontracted delivery for security firms and system integrators.

After delivery, I keep things running. Managed server and WordPress hosting handles updates, security patching, monitoring and backups for small businesses with no in-house IT — keeping the site and host available and secure over time.

Available for work · 目前可接案
Certifications

Certificates are de-identified; the certificate number and verification code are hidden. Full details are available on request during discussion.

06FAQ

FAQ

How do you price? How long does a project take?
Web work is quoted per project — a brand site takes roughly 1–3 weeks, custom systems vary by feature. Security work has set starting prices: Web scan from $18,000 / URL, host scan $15,000 / 10 IPs, health check $2,000 / machine, social engineering from $30,000 / up to 300 people, with reports usually delivered within days to two weeks. A free consult gets you exact figures and a timeline.
What's needed for a security assessment? Will it affect operations?
Every assessment requires signed written authorization first and runs only within the authorised scope. Scans are non-destructive — no denial of service or data tampering — can be scheduled off-peak, and you should back up beforehand. What to prepare: Web scan — the URL and a test account; host scan — an IP list; social engineering — the recipient list and mail-gateway allow-listing (results can include per-recipient open/click records, owned by the commissioning organisation); health check — admin access to run the tool (remote or on-site).
What does managed hosting actually cover? What access do I provide?
Monthly work: system and plugin security updates, twice-monthly off-site backups and uptime monitoring. Fully managed needs only DNS access and your site content (or a backup); ops-only needs host admin access (ideally a dedicated account — you keep host ownership and billing). See the Service Level Agreement for details.
As a solo studio, can you issue an invoice?
I work under individual professional-practice income, so no uniform (VAT) invoice is issued; your company handles withholding (10% income tax and 2.11% NHI supplement where the threshold applies). I provide a signed service-fee receipt as your expense voucher, with details on the quote.
Where do you serve? Do you need to be on-site?
Anywhere in Taiwan. Web work and most assessments are fully remote; for host scans and health checks on an internal network, I can work over VPN or arrange an on-site visit (travel charged for other counties).
You don't have many public cases yet — why trust you?
I hold ISO 27001 Lead Auditor and CompTIA Security+ credentials, and can share de-identified sample reports for security work; for web projects we can start small or in stages so you can verify quality at low risk.
07Contact

Tell me what you need

Have a project or want to discuss working together? Drop a note and I'll reply soon.

admin@laisecure.comChat on LINEgithub.com/eeicc

Before you send: your name, email and message are used only to reply to your enquiry and for follow-up. See the Privacy Policy.