WooCommerce support: e-commerce hosting, performance and security - init.d
IT

WooCommerce support: e-commerce hosting, performance and security

A WooCommerce store that stays fast, stable and ready for promo-day spikes.

WooCommerce turns WordPress into a full e-commerce platform, but a store isn’t a brochure site: the cart, checkout and account area can’t be served from cache, and every order is a transaction that can’t be lost. We handle the side that matters: infrastructure, stability and speed - not themes, graphics or catalogue management.

Need custom development instead - plugins, modules, integrations? See e-commerce development.

Overview

An online store lives on two things: how fast it is and how reliable it stays the moment traffic arrives. A checkout that drags on makes shoppers abandon their carts; a site that’s down during a promotion means sales that are lost for good. The technical challenge is that WooCommerce mixes pages that cache perfectly - home, categories, product pages - with pages that never can: apply a generic cache and you end up with carts shared between customers, or a store that’s just as slow as before.

We work on both fronts: cache rules written against the real purchase flow, and an infrastructure sized to hold the peaks, from seasonal sales to Black Friday. All delivered with a consultancy’s method: a single technical point of contact, documented work, configurations that stay yours. If you ever want to switch providers, you take everything with you - no need to ask permission.

Typical problems we solve

  • Checkout takes seconds to respond and carts get abandoned → we measure TTFB and queries, then tune PHP-FPM and the database.
  • The site crashes when the promotion launches → we check the infrastructure before the campaign and, where needed, put it through a load test.
  • The cache shows one customer another customer’s cart → we rewrite the full-page cache rules with correct exclusions for cart, checkout and account.
  • An update broke the order flow → updates only on staging, checkout testing and a rollback ready before we touch production.
  • Aggressive bots and crawlers saturate the server → WAF, rate limiting and mitigation with Cloudflare on the perimeter.
  • The database grows and dynamic pages slow down → cleanup of sessions and transients, missing indexes and optimisation of the heaviest queries.
  • No one has ever tried restoring a backup → encrypted copies and periodically tested restores, with priority given to orders and the database.

What’s included

  • E-commerce hosting: a stack tuned for WooCommerce, with resources sized on the store’s real traffic rather than default settings.
  • Performance under spikes: PHP-FPM and database tuning, a persistent object cache, fewer heavy queries and a lower TTFB on dynamic pages.
  • Cart-safe caching: full-page cache on static pages, exclusion of cart, checkout and account, correct handling of session cookies.
  • Payment security: properly configured HTTPS/TLS, server and WordPress hardening, checkout and wp-admin protection, a WAF in front of the site.
  • Uptime during promotions: an infrastructure check before campaigns and, where needed, a load test to see how far it holds.
  • Verified backups: encrypted copies tested on restore, with particular attention to orders, customers and the database.
  • Safe updates: core, WooCommerce and extensions updated on staging, tested against the order flow and promoted to production with a rollback ready.

Stack and technologies

Nginx in front of PHP-FPM with OPcache, MariaDB/MySQL tuned for WooCommerce queries, Redis as a persistent object cache and Varnish for full-page cache when traffic justifies it. On the perimeter, up-to-date TLS, a WAF and Cloudflare to absorb spikes and filter bots. Servers run on Debian or Ubuntu - on request also AlmaLinux, Rocky Linux and other distributions - hosted wherever you prefer: we work mainly on Google Cloud, with AWS and DigitalOcean as alternatives, or on existing VPS and dedicated servers. Payment gateways (Stripe, PayPal and similar) stay the PCI-certified ones - we secure everything around them. Every cache rule is written against your store’s real cart, not copied from a preset found online.

A real-world example

A sportswear store came to us after a Black Friday gone wrong: the site unreachable for most of the morning, orders stalled and customer support overwhelmed. A load test run in October reproduced the problem within minutes: PHP-FPM pools maxed out and category pages regenerated on every request, with no caching at all. We introduced Redis as an object cache, configured full-page cache with the correct exclusions for cart and checkout, resized the pools and put Cloudflare in front of the site to filter bots. On the following Black Friday the store absorbed higher traffic than the year before with no interruptions, and checkout stayed stable all day. The configurations are documented, and the client knows exactly what’s running on their server.

Who it’s for

  • WooCommerce stores that slow down at busy times or have already lost sales during a promotion.
  • Businesses and professionals who sell online and can’t afford slow checkouts or downtime.
  • Agencies building e-commerce sites for clients who want a stable technical partner on the infrastructure.
  • Anyone about to launch a campaign - sales, Black Friday, a new product - who wants to arrive with the site ready.

How we work

We start with a check of store and server: checkout performance, cache configuration, and the state of updates and backups. From there comes a plan with clear priorities and an indicative price, with no surprises on the invoice. Updates always go through staging, and we verify cache rules against the real order flow, not a test page. Coverage runs Mon-Fri 10:00-18:00 with priority triage: a store that isn’t taking orders is a P1, and we pick it up within one business hour; for night and weekend emergencies there are on-call retainers; pickup times are described on the response times page. For ongoing maintenance many clients choose hour packages, which never expire. Readable reports after every intervention: you always know what was done and why.

Frequently asked questions

Won’t caching slow down or break the WooCommerce cart?

Not when it’s set up properly. We apply full-page cache only to static pages and exclude the cart, checkout and account area, handling session cookies correctly: the store stays fast without ever showing one customer another customer’s cart.

Our store slows down during promotions and traffic spikes. Can you help?

Yes. We identify where the bottleneck is forming - PHP, database or cache - and work on tuning and a persistent object cache. Before a big campaign we can run a load test and size the infrastructure to the traffic you actually expect, rather than an optimistic guess.

Do you handle payment security as well?

On the infrastructure side, yes: correctly configured HTTPS/TLS, server and WordPress hardening, checkout and wp-admin protection, a WAF in front of the site and timely updates. The actual charge stays on the gateway (Stripe, PayPal and the like), which is already PCI-certified.

How do you update WooCommerce without stopping sales?

On a staging environment: we update core, WooCommerce and extensions, verify checkout and orders, then promote to production with a backup ready to roll back. No blind updates on the live store, especially during a campaign.

How much does WooCommerce support cost, and how does the quote work?

We bill at a flat €75/hour. For ongoing management many stores use hour packages that never expire: 5 hours at €350, 10 at €660, 20 at €1,200. Quotes are always free, with a reply within one business day.

Can you host the store yourselves, or migrate it to a new server?

We provision and manage servers under your own account, on Debian or Ubuntu, mainly on Google Cloud - with AWS and DigitalOcean as alternatives. Migration happens in an agreed window, with the order flow verified before the DNS switch: the infrastructure stays yours, with no lock-in.

Do you also work at night or on weekends?

Guaranteed only for clients with an active on-call plan, and only for real P1 emergencies: production down, data loss, active security incident. On-call is a monthly retainer with limited seats, available on systems we manage and, after a case-by-case assessment, on others too: prices and rules are on the On-call page. Without a plan, coverage is Mon-Fri 10:00-18:00 and out-of-hours work is best effort: it may happen, but it is neither guaranteed nor something you can demand. Night or holiday work planned at least 20 days ahead remains available to everyone, at the surcharged rate.

Need a hand with your infrastructure?

Tell us the problem: we reply with a clear plan and a quote.

Get in touch →