060 279 5587 info@sitect.co.za 139 Davies Street, Doornfontein, Johannesburg, 2001 Gauteng, SA
E-Commerce · WordPress + WooCommerce

WooCommerce stores, done properly.

WooCommerce powers ~25% of the entire web for a reason — total ownership, infinite flexibility, and a content engine baked in. But it has to be built carefully: server-tuned, plugin-disciplined, security-hardened. We do exactly that, for SA brands who want content + commerce in one place.

R11k starting · full custom 4–7 weeks typical timeline You own everything · code, server, data
proteacoffeeco.co.za + New
Howdy, Sipho
Dashboard
WooCommerce
Products
Posts
Media
Pages
Marketing
Settings

Edit product Add new

General Inventory Shipping SEO

Theme + plugins

GeneratePressActive
WooCommerce9.2
Yoast SEO22.4
WP Rocket3.16
CloudflareCDN
WordfenceFirewall

Publish

Status: Published
Visibility: Public
Updated: 2 min ago
Self-hostedYou own the server
A+
SSL
HardenedWordfence · 2FA · WAF
The honest truth

Why most WooCommerce stores stall, slow down or get hacked

WooCommerce gives you total freedom — and that freedom is exactly what kills most stores when nobody applies discipline. Here's what we see go wrong, week after week.

Anti-pattern 01

38 plugins, half of them abandoned by their authors.

It's so easy to install plugins that WordPress sites accumulate them like mould. Each one adds load time, security risk, and a compatibility gamble at every update. The store gets slower every month, and one day a plugin breaks PHP 8.2 and the checkout dies.

What it costs: 4-second LCP, monthly plugin-conflict outages, painful WP updates.
Anti-pattern 02

Hosted on R49/month shared hosting with 256MB PHP memory.

WooCommerce is a database-heavy application — it needs real memory, real CPU, and a real database. Cheap shared hosting buckles under any traffic spike, kills queries mid-checkout, and times out admin pages. "Why is the dashboard so slow?" — it's the host.

What it costs: 502 errors on Black Friday, admin that takes 8 seconds per click, ranking penalties.
Anti-pattern 03

No staging environment. Every change goes straight to live.

Most WooCommerce stores have one environment: the live one. So plugin updates get postponed for fear, new features are tested on customers, and any rollback means restoring from a backup that's a week old.

What it costs: change paralysis, accumulated tech debt, eventual full rebuild.
Anti-pattern 04

Default WP login at /wp-admin, no 2FA, weak passwords.

WordPress is the most-attacked CMS on earth precisely because so many sites leave the front door wide open. Brute-force login attempts hammer /wp-login every minute of every day. One weak admin password and the site is mining crypto by Monday.

What it costs: defaced sites, blacklisted by Google, customer data leaked → POPIA breach.
When WooCommerce wins

WooCommerce vs Shopify — the honest comparison

We build both. We tell every client honestly which fits them better. Here's the short version, with no marketing varnish.

You should choose WooCommerce if…

Content drives your commerce. You publish blog posts, recipes, guides, lookbooks, video — and the products live inside that content world. Shopify treats your blog as a side feature; WordPress treats your content as the engine.

You have an in-house developer or want full code ownership. Every line of Liquid in Shopify is rented; every line of PHP in WooCommerce is yours forever.

You need unusual commerce logic — custom pricing rules, B2B login-walls, marketplace-style multi-vendor, complex memberships — that Shopify Functions can't quite cover.

You want to host on your own infrastructure (compliance, cost control, vendor-lock concerns) or you're already heavily invested in WordPress for the main site.

 
WooCommerce
Shopify
Code ownership
Yours forever
Rented
Content + blog
Best in class
OK
Time to launch
4–7 weeks
4–6 weeks
Hosting / ops
You / us
Hosted
Customisation ceiling
Unlimited
High
Monthly cost
Lower
R600+ /mo
Our opinionated stack

The exact stack we build on, every time

Most agencies pick plugins by what they've used before. We pick the smallest possible set that delivers performance, security, and SEO out of the box — and refuse to add more.

Theme foundation

Lightweight, performance-first parent themes — never bloated marketplace themes.

GeneratePressKadenceAstra

Commerce engine

WooCommerce core, with a curated short-list of Woo extensions only when essential.

WooCommerceSubscriptionsBookings

SEO & structured data

Schema, sitemaps, breadcrumbs, social cards, and product structured data done right.

YoastRankMathSchema Pro

Performance

Object cache (Redis), full-page cache, CDN, image optimisation. Lighthouse 90+ on mobile.

WP RocketRedisCloudflare

Security

WAF, brute-force protection, malware scanning, mandatory 2FA on admin, hardened wp-config.

WordfenceiThemes2FA

Forms & flows

Light-weight contact, quote, and B2B inquiry forms with conditional logic and CRM hookups.

Fluent FormsWPFormsKlaviyo

Analytics

Server-side GA4, Meta CAPI, search-console, and a self-hosted Plausible board for privacy.

GA4Meta CAPIPlausible

Hosting

Managed WP hosting on Cloudways/Kinsta/RocketNet — or your own AWS / Hetzner box, tuned by us.

CloudwaysKinstaRocketNet
What we can build for you

The features SA stores ask us for most

Custom WooCommerce gives you room to do things Shopify can't. Here's the stuff we ship for SA brands every quarter.

SA payment rails

Yoco, Payfast, Peach, Ozow, PayGate — proper plugin integrations (not the rusty community ones), reconciled webhooks, 3DS 2.0 tested.

B2B / wholesale

Tiered pricing, login-gated catalogues, net-7/14/30 invoicing, quote-to-order flows, customer-group pricing rules.

Subscriptions

Recurring billing on Woo Subscriptions, retry logic on failed cards, customer-managed pause/skip/cancel flows.

Booking & appointments

Service-based stores — salons, clinics, courses, rentals — with calendar selection, deposit handling, and reminder flows.

Memberships

Members-only content, gated downloads, tiered access, free-trial → paid conversion flows.

Multi-vendor marketplaces

Dokan or WC-Vendors marketplaces — vendor onboarding, commissions, vendor-specific dashboards, payouts.

SA courier integrations

Aramex, Courier Guy/TCG, Pargo, Pudo lockers — live rate-at-checkout and auto-printed waybills.

SARS-compliant tax invoices

Automatic VAT invoice generation with all SARS-required fields, sequential invoice numbers, archived to PDF.

Custom plugins

When no plugin does what you need, we write a clean custom one — not a 200-line "snippets" hack in functions.php.

Security & performance

Hardened from day one, not as an afterthought

WordPress's reputation for being insecure is mostly a reputation for being badly configured. Every Sitect build ships with the hardening below baked in — not as an "upsell" 6 months later.

All hardening is reversible and documented; you keep root access to your own server.

Renamed login URLNo more /wp-admin guesses
Mandatory 2FAFor every admin user
Cloudflare WAFBot & brute-force blocks
Daily malware scanAuto-quarantine
Off-site backupsDaily · 30 days retention
Real-time monitoringUptime & SSL alerts
Hardened wp-configDisable file edits + xmlrpc
Staging environmentTest before live
What you actually get

Everything you walk away with at handover

One fixed scope, no "phase 2" line items, complete code ownership. Here's the full deliverables list — same for every Sitect WooCommerce build.

Custom child theme

Bespoke child theme on a performance-first parent (GeneratePress/Kadence), with all your brand styles, custom blocks, and product-page templates.

Configured store

Products, categories, taxes (15% VAT), shipping zones, courier integration, SA payment gateways, customer accounts — all configured and tested.

Hardened hosting

Production + staging environments set up, SSL, CDN, WAF, daily backups, monitoring, 2FA, hardened wp-config — all configured.

Performance tune

Object cache (Redis), full-page cache (WP Rocket), image optimisation, CDN, lazy-loading, critical CSS — Lighthouse 90+ at handover.

Analytics & marketing

GA4, Meta Pixel + CAPI, Klaviyo flows, Google Shopping feed, search-console, Plausible — all configured and reconciled.

Documentation + training

30-page admin handbook PDF, Loom videos for your team (add product, edit content, run promo, refund, troubleshoot), and a 14-day post-launch tune-in period.

From signature to launch

A predictable 5-phase build process

Typical turnaround is 4–7 weeks depending on scope. You see weekly progress in a shared staging environment — never wait a month between updates.

1

Discovery

Brand, products, audience, integrations, plugin shortlist.

Week 1
2

Design

Figma designs for home, product, cart, checkout, account pages.

Week 2
3

Build

Child theme, hosting setup, plugin install, content + product migration.

Week 3–4
4

Integrations + QA

Payments, couriers, analytics, hardening, performance tuning, full QA.

Week 5–6
5

Launch + tune

DNS cutover, soft-launch, 14-day daily monitoring, post-launch tweaks.

Week 7
Results we engineer for

What "shipped right" looks like

Numbers from recent SA WooCommerce rebuilds in the 90 days after relaunch. Your category and ad spend shape the upside — but these are directionally what proper WooCommerce engineering unlocks.

+126%
Organic traffic
Content engine + schema + speed
2.1×
Conversion rate
1.0% → 2.1% mobile
94
Lighthouse mobile
from a starting 47
0
Security incidents
across 24 hardened sites
Indicative pricing — ZAR, ex VAT

Three ways to launch with Sitect

Every build is scoped per brand — these tiers are guideposts, not menus. Final scope and price confirmed after a 30-min discovery call. 50% on signature, 50% on go-live.

Starter Store

Solo founders & first-time launches
R11 000 from
One-off · 4 weeks · ex VAT
  • Custom child theme on Sitect parent
  • Up to 50 products migrated & styled
  • 1× SA payment gateway + 1 courier
  • Hosted on Cloudways (or your host) + SSL + CDN
  • Full security hardening + 2FA
  • 14-day post-launch tune-in
Start a Starter quote

Enterprise & B2B

B2B portals, marketplaces, ERP-integrated
POA
From R48 000 · 8–14 weeks
  • B2B portal with net-terms invoicing
  • Multi-vendor marketplace (Dokan) or wholesale
  • Custom plugin development
  • Multi-site / multi-region setup
  • ERP / WMS integration (Sage, Xero, SAP B1)
  • Dedicated retainer post-launch
Talk to us about Enterprise
FAQ

The questions we get asked most

Honest answers about hosting, security, plugins, migrations and ongoing costs — the bits most agencies dodge in proposals.

WooCommerce or Shopify — which is actually better?
Neither is "better" universally. WooCommerce wins when content drives commerce, when you need unusual logic, when you want code ownership, or when monthly platform fees matter. Shopify wins when speed-to-launch and hands-off ops are paramount, or when you don't have technical capacity. We build both and recommend the right fit honestly — not the one with the higher project fee.
How much does ongoing maintenance cost?
Realistic monthly figures: hosting R600–R2 500/mo (depending on traffic), security/backup plugin licenses ~R250/mo, premium plugin renewals ~R400–R900/mo, optional Sitect care plan from R1 400/mo (updates, monitoring, backups verified, monthly health report). Most Starter and Growth stores run comfortably at R5 000–R8 000/mo all-in.
Where will my store be hosted?
We default to Cloudways on AWS Cape Town for SA-hosted speed + managed convenience. We've also built on Kinsta, RocketNet, and self-managed Hetzner/DigitalOcean boxes. You always own the hosting account — we just configure and tune it. POPIA-driven SA data residency is supported.
Can you migrate my existing site to WooCommerce?
Yes — about 35% of our Woo builds are migrations from Shopify, Wix, Magento, Squarespace, or older WordPress sites. We script product/customer/order migrations, preserve URL structure (or set 301 redirects to protect SEO), and run the new store on a staging URL until launch so the old site keeps trading.
Will WordPress slow my store down?
Only if it's built badly. We commit to Lighthouse 90+ on mobile at handover via object cache, full-page cache, CDN, image optimisation, and a strict plugin diet. Most "slow WordPress" stores have 30+ plugins, no caching, and shared R49 hosting — none of which we ship.
Is WordPress safe?
WordPress itself is reasonably secure — but most WP sites are misconfigured. Every Sitect build ships with renamed login, mandatory 2FA, Cloudflare WAF, hardened wp-config, daily malware scans and off-site backups. Across 24 hardened sites in the last 18 months we've had zero security incidents. Risks are real but manageable.
Does the store handle SA VAT correctly?
Yes — every build is configured for 15% inclusive pricing, separate-line VAT on tax invoices, SARS-compliant tax-invoice fields (your VAT number, sequential invoice numbers, "TAX INVOICE" label, customer details, line items, totals), and edge cases for zero-rated and exempt items.
What's not included?
Product photography, content writing, brand identity work (logo, palette), paid-media buying, and ongoing SEO content — unless you add them as a separate engagement. We do connect you with vetted SA photographers, copywriters and SEO specialists if you'd like an introduction.

Ready to launch a WooCommerce store your team can actually run?

Send us your current site URL (or describe what you're building from scratch) and we'll come back with a 30-minute video audit, a recommended tier, and an indicative price — no obligation, no pitch deck.