Running Umbraco 13? Security support ends 14 December. Fixed-price upgrade to 17: £8,999 + VAT See how it works →
umbracofreelancer
Sound familiar?

Nobody understands our Umbraco site anymore.

The site works but nobody knows how, so nobody dares touch it. How websites become haunted houses, and how I make yours understood and safe to change.

The haunted house

Every organisation past a certain age has one: a system that works, that matters, and that nobody understands. Yours happens to be the website. It was built years ago by an agency two agencies back, extended by a contractor whose surname nobody remembers, patched by an IT team member who has since moved to Belgium, and inherited by whoever was unlucky enough to be standing nearby when the last person left.

The site runs. That is precisely the problem. Because it runs, fixing the situation has never been urgent, and because nobody understands it, touching it has never been safe. So an unspoken policy has formed, the same one that forms around every haunted house: do not go in. Content editors work around the broken bits with the practised weariness of people who stopped filing tickets years ago. There is a page nobody edits because it once took the site down. There is a button in the backoffice labelled do not press, and nobody can tell you what it does, only that pressing it is how the button got the label.

The costs are real but they never appear on one invoice, which is why nothing gets approved. A competitor ships a campaign page in a day; yours takes three weeks because every change is a nervous experiment. New marketing tools cannot be integrated because nobody can say what the integration would touch. Security updates get deferred, not out of laziness but out of honest fear: when you cannot predict what an update will break, not updating feels responsible, even though it is quietly the most dangerous choice available.

And underneath it all is a thought you may not have said out loud: if this thing ever seriously breaks, we do not have anyone who can fix it. That thought is heavier than any single line item, and it is carried by whoever owns the website, which is presumably why you are reading this.

What I do about it

Haunted houses stop being haunted the moment someone walks through every room with the lights on. That is the job, and it is more tractable than it feels from where you sit.

I start with an archaeology pass: the codebase, the database, the document types, the templates, the integrations, the hosting. Umbraco sites from every era have recognisable construction styles, and after fourteen years on the platform, from version 4 to version 17 across more than 200 sites, I have renovated most of them. The strange macro from 2014, the custom route handler, the mystery scheduled task: these are usually familiar artefacts with known purposes, not curses. What comes out of the pass is a map your organisation owns: how the site is built, what every moving part does, which parts are sound, which are fragile, and, at last, what the button does.

With the map drawn, fear stops making the decisions. The backlog of small changes editors gave up requesting becomes a list of ordinary jobs with ordinary estimates. The deferred updates become a sequenced plan instead of a cliff. If the site is old enough that modernisation is the honest recommendation, you will get that recommendation with numbers attached, including, for Umbraco 13 sites facing the December 2026 support deadline, the fixed price answer in what an Umbraco 13 to 17 upgrade costs. If the site has years of life left, which is more common than owners fear, we simply start maintaining it like something understood.

Keeping it understood is the part most rescues skip. Understanding decays: every undocumented change starts the haunting again. Ongoing support and maintenance keeps the map current while handling patching, monitoring and the steady flow of small improvements, and my answer to how quickly I apply security patches puts a number, 48 hours, on the update anxiety specifically. Where deeper remedial work is needed, it is planned openly as development you can see into, because the entire point of this exercise is that your website should never again depend on what one unavailable person happens to remember.

The first conversation costs nothing and commits you to nothing: tell me the site's age, its version if you know it, and the oldest story anyone tells about it, through the contact page. I have heard worse, I promise.