What's Next — Optional Proposals
Community Newspapers — a menu of scoped-but-not-yet-purchased work. Nothing here is due; pick what's useful whenever you're ready. Have an open bill instead? See invoices & payments.
Speed RECOMMENDED
Scoped against your live mobile PageSpeed numbers (score 49 · Core Web Vitals failed · LCP 4.2s · TTFB ~1.0s). Step one is a full diagnostic so every change targets a measured cause — no guessing:
- Cloudflare CDN + full-page caching — attacks the ~1.0s server response (TTFB); highest-leverage move for a publisher
- Pinpoint & optimize the above-the-fold lead element — measure the exact item Google times for the 4.2s LCP on your live page, then load it lean and with priority
- Critical-CSS + defer the heavy theme stylesheet & non-essential JS — stops render-blocking; delivered as a one-file mu-plugin (survives theme updates, one-file rollback)
- Lazy-load ad slots + defer ad/tracker scripts — the third-party load that drags news sites most
- Reserve space for ads & media — eliminates the layout jump (the 0.1 CLS)
Breach Follow-Up
This section outlines the forward-looking actions required to fully contain the breach, address the legal implications of the data exposure, and permanently secure your infrastructure. Each tier includes the deliverables of the tier below it.
While T1 simply locks the doors and T2 addresses your immediate legal liability, T3 is the only tier that guarantees this scale of exposure cannot happen again.
- The FIPA Legal Trigger: Under Florida law, your 30-day breach notification clock started on July 15, 2026. T3 includes all the forensic data-mining your attorney requires to determine your legal liability before the August 13 deadline.
- Total Infrastructure Ownership: T3 goes beyond immediate forensics. It completely overhauls your security infrastructure by deploying dedicated, client-owned disaster recovery backups and 24/7 active monitoring.
- Our Recommendation: We highly advise selecting T3 so you not only satisfy your immediate legal obligations, but permanently secure your digital assets under your direct, exclusive control.
- 7 leftover log files from a 2022 migration were still publicly downloadable (~226 MB of internal site data). Fixed today — moved out of public reach.
- Your site was publicly publishing your full staff username list at a single web address — the exact list July’s password attack used. Fixed today — shut off.
- A forgotten, 2-years-unpatched newsletter sub-site shares your server and can read your main paper’s database password. Still open — this is the most serious finding.
- Remote-management keys on the site needed an owner check. Audited today (read-only): 2 real keys, not the 7 first thought; one new connection attempt on July 20 needs your confirmation.
- Not-To-Exceed (NTE) Ceiling. Secures the perimeter against secondary access.
- Force-rotate access keys for all critical third-party integrations (SMTP, mailing lists, APIs).
- Re-encrypt backup infrastructure and enforce new passphrase rotation.
- Deliver a formal Containment Completion Report for your security records.
- Not-To-Exceed (NTE) Ceiling. Includes everything in T1. Essential for legal compliance.
- FIPA Affected-Party Report: Forensic data-mining to determine exactly whose personal data was exposed, providing your attorney with the exact list of potentially notifiable parties.
- Access Attribution: Trace and tie the 24 database downloads to the specific exposed sources.
- Deep Persistence Audit: Deep-level server sweep to scientifically guarantee the attacker left no hidden backdoors, rogue admin accounts, or malicious timed tasks.
- Flat Rate. Includes everything in T1 and T2. Total infrastructure security overhaul.
- Deploy a dedicated, client-owned, off-site backup destination (ensuring you hold the keys, not a prior vendor).
- Execute a verified disaster recovery test to prove backups restore perfectly.
- Remediate and enforce strict, compliant backup retention policies.
- Implement 24/7 external uptime and active security monitoring.
- Reroute critical system notifications to an exclusive address under your direct control.
Site Search
Own search engine, licensed for your site — replaces the 5-6 second stock WordPress search.
- Modern indexed search engine replaces the stock WordPress search
- Takes searches from 5–6 seconds today down to a fraction of that
- Smarter ranking: titles, recency and your papers weighted properly
- Results page styled to match your site
- 30-day warranty on everything we build
- Everything in FAST, plus:
- Search-as-you-type suggestions (autocomplete)
- Filter search by publication — readers search their paper
- Monthly readers-search report — see exactly what your audience is looking for; your ad team can sell against it
- 30-day warranty on everything we build
- Everything in SMART, plus:
- AI-powered search suggestions and “related articles” recommendations that keep readers on the site longer
- Smart handling of typos and natural questions
- 30 days of hands-on tuning included after launch (up to 6 hours; overage $75/hr)
- 30-day warranty on everything we build
Staging Site PRIORITY
- Full mirror of communitynewspapers.com with password-protected access
- Automated prod-sync
- One-click deploy path
- Isolated environment, updated weekly from prod
CNEWS TV
- Reorganize 2,849 posts from host-first to show-first
- Deduplicate host categories
- Migrate existing tags
- Data-heavy: current 6 CNEWSTV categories + 11 host children — migration script + manual review
- Playlist scheduler
- Live-stream ingest
- Public-facing player
- Scheduled programming
- CDN + transcoding + storage — cost scales with viewer volume, $295/mo baseline
Backups
Your current on-server backup volume has been full and silently failing since Feb 2026 — this replaces it with off-site, encrypted, monitored backup.
- Weekly backup + restore test
- 30-day retention
- AES-256 encrypted
- Daily rotation
- 90-day retention
- Quarterly DR drill
- Right-sized for CN's ~200GB
- Included free for 90 days if T3 Fortify accepted
- Point-in-time snapshots
- 1-year retention
- Multi-region option
KPI Dashboard
One login-scoped view of your whole publishing business — powered by MC20.
- Audience (GA4)
- Search visibility (GSC)
- Site health monitor
- Your MC20 project view
- Everything in Essentials
- Ad performance + fill-rate
- On-site search intelligence
- Everything in Publisher
- Newsletter + CNEWS TV metrics
- Per-advertiser sub-logins — advertisers see their own campaigns
Security Hygiene
- Audit all installed plugins/themes
- Remove 12 inactive themes
- Retire abandoned plugins
- Document remaining stack
- Full remote-admin channel that bypasses wp-login
- Rotate all keys + verify
- newsletter.communitynewspapers.com is LIVE with open login
- 34 unmaintained plugins
- Shares filesystem with production paper
- DNS fix
- Relay of 2,965 frozen messages
Advertise Funnel
- Red-button CTA
- Rebuilt form
- GA4 + Meta Pixel conversion tracking
Discovery
- Does a block still exist? — CSF/cPHulk deny, .htaccess, Cloudflare/WAF, security plugin
- What exactly it blocks — country / ASN / user-agent / just /feed/
- Is it catching legit subscribers as collateral
- Who added it + when — WSAL has 410k events back to 2026-01-12
- Confirms EmailOctopus plan + list size (newsletters send from EmailOctopus, not your server)
- Send volume + bounce/list hygiene
- Deliverability check — SPF + DKIM present, no DMARC yet
- Whether server slowdowns are EmailOctopus-related or a separate load issue
Questions on anything above? Text or call Eddy directly — 786-426-4902.
