Four areas in seven business days: CRM security and product quality, the WordPress sites, the AI cost of building sites, and how the sites show up in Google and in AI assistants such as ChatGPT. The result is a ranked plan with an effort estimate for every step.
Your primary requirement is that the SVH Travel CRM and the site network are secure. Your further objectives are more automation in site creation, with about 2,000 more sites planned, a lower running cost, and faster, better sites. To scope the work you provided the CRM source, a description of the servers behind the 700-plus WordPress sites, your AI billing figures and a site-build log. This proposal is based on that material only, which is covered by the confidentiality terms in section 6.
| Provided | What it is |
|---|---|
| SVH Travel CRM | About 110,000 lines of Next.js, hosted on Vercel with a Neon Postgres database, Clerk sign-in, card processing through PCIVault and Authorize.Net, email through Resend, SMS through RingCentral, and twelve scheduled jobs. It holds client records, passport scans, saved cards and signed card authorizations, e-signed agreements, every email and SMS thread, and nightly backups. |
| Site network | 700-plus WordPress sites on 15 rented servers at Hetzner, ordered recently at Hetzner's current prices. The sites are built as white-label clones of one template, so one shared codebase and plugin stack serve all of them, and they are generated and deployed by an automated pipeline you want to automate further. |
| AI usage | About $20,000 spent across two vendors so far, most of it on building the 700 sites. Your build log puts one automated site build at about $23.86 across 525 API calls. |
We used this material to size and sequence the audit. This proposal describes the audit; findings come only in the report. It sets out what the audit covers, why each part matters to SVH, and what it delivers. The order of work is the CRM first.
You own the report and every recommendation, with no obligation to proceed. Any implementation scope and fee is proposed separately, after you have read the findings. The report is written so that your own team, or any vendor, can act on it.
The audit delivers two kinds of value.
The CRM and WordPress security reviews, with recommendations aimed at keeping the same classes of problem from returning.
Sized from your own figures at public 2026 prices, on the 2,000 sites you plan to build and the servers that will host them. The AI figures are approximate, based on the spend and build log you provided; the audit replaces them with measured numbers. The figures below are scenarios, not a promise, and they are gross: the audit delivers the report, and implementing its recommendations is separate work with its own cost, by your team or a vendor of your choice. The report turns the scenarios into a ranked plan with an effort estimate for each change.
| Lever | On today's footing | After the recommended changes are implemented |
|---|---|---|
| AI cost of building the next 2,000 sites, after the report's AI cost recommendations | about $48,000 to $57,000 about $24 to $29 per site | about $22,000 to $26,000 about $11 to $13 per site |
| The same 2,000 builds with the bulk of the AI work on private model hosting (open AI models on dedicated servers, paid by the month instead of per use) | about $22,000 to $26,000 | about $7,000 to $16,000 about $3.50 to $8 per site, plus a flat monthly hosting fee |
| Server hosting for the sites, today and as the network grows, on fewer servers with Cloudflare's free plan carrying the cached traffic | your current server bill | up to 50% lower |
Gross savings. On the 2,000-site program, about $22,000 to $35,000 from the AI recommendations alone, and about $32,000 to $50,000 with private hosting. On servers, up to 50% of the current bill, at today's size and as the network grows.
All figures in this table and the tiles below are approximate, based on what you shared: about $20,000 of AI spend for 700 sites, one logged build, your current servers, and the 2,000 further sites you plan. The AI rows assume the logged build is typical. The hosting row assumes consolidation behind Cloudflare's free plan can cut the server bill by up to 50%. The tiles count the hosting saving at the full 50% of the server bill you described. The audit measures today's costs and tests the assumptions behind the future ones. Every saving here is gross, before the private hosting fee and the cost of implementing each change; the net saving is what remains after them.
Why the audit comes before the changes. Every step has a way to go wrong that costs more than it saves. A cheaper model can quietly lower page quality, or cost more per page than it appears to; a new feature connected to the CRM inherits every weakness in it; a change to a site's search setup can carry a problem forward instead of leaving it behind; and one bad change rolled across 700 sites becomes 700 problems. The audit puts the steps in the right order with the checks that make each one safe.
Each area is reviewed by hand by a senior engineer, with automated tools in support. The report lists what was reviewed in full and what was sampled.
The primary purpose of the audit: a review of the CRM's source code and configuration, security first, then product quality.
Why it matters to SVH. The CRM runs the agency's daily work and holds its most sensitive data: client and passport details, saved cards, signed agreements and every message. Gaps in software like this do not show in normal use, which is why they are best found in a review.
The 700-plus sites, the 15 servers that run them, and the pipeline that generates and deploys them, reviewed as one system.
Why it matters to SVH. WordPress is the most used website platform and therefore the most attacked: 11,334 new vulnerabilities in its ecosystem were published in 2025 (Patchstack), most of them in plugins, and heavily targeted ones are exploited at scale within hours. With 700 sites cloned from one template, one vulnerable plugin can compromise hundreds of sites in an afternoon, and the fallout is injected spam, "this site may be hacked" labels in Google and browser warnings on your own brand.
The AI cost of the site-building pipeline, from your usage history with both AI vendors and the site-build logs.
Why it matters to SVH. You have spent about $20,000 on AI so far, mostly building the first 700 sites, and you plan about 2,000 more. Without a known cost per site, more automation means more spend at the same rate. The audit measures it, so that the next 2,000 sites are built at a known cost.
A review of the 700-plus sites as one network against Google's current policies, the 2026 enforcement record, and the shift of travel searches into AI answers, with recommendations for the existing WordPress platform. Content quality is checked on a sample of live sites. Some signals cannot change: 700 sites built from one template on shared code will always be recognizable as one operation, and the report says so rather than promising otherwise.
Why it matters to SVH. The network exists to bring leads. Google's spam policies on mass-produced content describe a pattern that large generated networks can match, and 2026 has brought three spam updates and two core updates (Search Engine Journal). Since April 2026, Google's guidance says it may act on the spam reports it receives (Search Engine Land). At the same time, AI answers roughly halve the clicks on the results beneath them (Pew Research Center data), and Google's AI Mode has booked hotels directly since August 2026 (Skift). Knowing which sites produce bookings is what makes every other search decision possible, which is why lead attribution is part of the audit.
What a finding looks like. Every finding carries a title, its severity, what it affects, the evidence, the recommended fix and an effort estimate. Severity has four levels:
The report closes with a recommended plan of work, in phases. CRM security always comes before the savings work; what goes into each phase, in what order and when, is set from the findings.
We can carry out any part of the plan, each scoped and priced from the report, separately and only if you want it. The first step, Protect & Save, covers any time-sensitive CRM fixes and the AI cost program; later work covers CRM hardening and product fixes, private AI hosting, the WordPress sites, search visibility, and ongoing care.
| Item | Amount (USD) |
|---|---|
| SVH Technology AuditCovers all four areas and every deliverable in section 4. | $15,000 |
| Total | $15,000 |
| Payment | Invoiced | Due | Amount (USD) |
|---|---|---|---|
| First installment | On signing | Before kickoff | $7,500 |
| Final installment | On delivery of the report | Within 15 days of delivery | $7,500 |
With the report, we price Protect & Save (section 5) from its findings. If you go ahead with it within 30 days of receiving that price, and the audit fee has been paid in full, $7,500 is deducted from its first invoice. The audit fee itself is not refunded.
The credit is a deduction on the Protect & Save invoice, never a payout, and is not available on any other service in section 5. The retest below is not credited.
| Retest | What it covers | Fee |
|---|---|---|
| Fixes made by us | After any engagement in which we did the remediation, we re-verify the fixes we made, once, if requested within 30 days of their completion, and give you a written confirmation of what we verified, for your records. | Included |
| Fixes made by your team or another vendor | The same single re-verification and written confirmation, on fixes we did not make, on the same terms. | $3,000 |
If you decide to act on the findings, we price Protect & Save from the report, and the $7,500 credit applies on the terms in section 8. If you act with your own team or another vendor, the report is built for that too, and the $3,000 retest in section 8 re-verifies their fixes and gives you written results.
This proposal becomes an agreement when both parties have signed below.