
Brackish Security
brackish.io ↗Marketing site for an offensive security firm. Static build, no CMS, technical layout system with a diagram-driven homepage.
- Static
- Marketing site
- Custom design
Website Design & Hosting · Central Illinois
Custom-built, fast, and hosted by a security firm. $2,500 to build, $249/month to run.
Based in Central Illinois. We work with businesses in Peoria, Bloomington–Normal, Champaign–Urbana, Springfield, Decatur, and the towns between them.
Need more than a website — user logins, multiple customers, AI features, cloud infrastructure? We build applications too.
Most small business sites run WordPress with a dozen plugins nobody has updated since launch. That is not a small problem. It is the single most attacked software ecosystem on the public internet.
Your host will not save you either. Hosting-level defenses stopped 12% of actively exploited WordPress vulnerabilities.
11,334
New vulnerabilities disclosed in the WordPress ecosystem in 2025, up 42% year over year.
91%
Were in plugins. Nine percent were in themes. Only six were in WordPress core itself.
~50%
Of high-impact vulnerabilities were exploited within 24 hours. In the most-targeted cases the median was five hours.
46%
Of vulnerabilities found in premium and freemium plugins had no patch available when they were disclosed.
12%
Of actively exploited WordPress vulnerabilities were stopped by host-level defenses.
1,966
Rated high-severity — 17% of everything disclosed that year.
WordPress core isn't the issue. The plugin ecosystem bolted to it is.
Source: Patchstack, State of WordPress Security 2026 — figures cover calendar year 2025.
We build static sites. Your pages are compiled to plain HTML ahead of time and served from a global edge network. There is no server executing code when a visitor arrives, no database to inject, no /wp-admin to brute force, and no plugin author in another country who stopped maintaining their code in 2023.
The entire class of attack that takes down small business websites does not apply to yours.
It is also, incidentally, much faster.
Nothing to exploit at runtime.
Bot protection and server-side validation on every submission, so your inbox gets leads instead of spam.
Not a marketing agency that also makes websites.
One thing we will not tell you: that any website is unhackable. Your domain registrar, your DNS, and your email are still live attack surface, and a security firm claiming otherwise is selling you something. What we remove is the plugin and database attack surface — which is where local businesses actually get hit.
Every site below was designed, built, and shipped by us — a marketing site, security tooling, two content-heavy publications, and a technical blog. All static or statically-rendered, all running in production. Applications with logins and infrastructure behind them are further down the page.

Marketing site for an offensive security firm. Static build, no CMS, technical layout system with a diagram-driven homepage.

Search interface over 13,663 ProjectDiscovery Nuclei templates, filtered by CVE, severity, name, and description. Built for speed.

Review publication with structured scoring, category browsing, and a large editorial library. Content-heavy and still fast.

Consumer electronics reviews and teardowns, organized by category and gear type, with scoring and search.

Technical blog covering security research, homelabs, and networking. Migrated off Jekyll and GitHub Pages onto a statically rendered Next.js build with tag routing and per-post metadata.
Some projects are not six pages of copy and a contact form. They have users who log in, customers whose data must never touch each other, background jobs, and integrations with systems you already pay for. We build those too.
Yes, this contradicts the “no database, no login” argument above. That is deliberate. A restaurant does not need a database. An attack surface management platform does.
The point was never that software should avoid having features. It is that you should not be running a database and an admin panel to publish your hours — and that when you genuinely do need them, they should be built by people who break into applications for a living.

Built for Brackish Security
External attack surface management platform. Continuously discovers an organization's internet-facing assets, tests them the way an attacker would, and reports findings with evidence attached. Runs on AWS with ECS for the scanning workloads and S3 for artifact storage.

Built for Brackish Security
Authenticated client portal for penetration testing engagements — live reporting, priority advisories, encrypted messaging, scoped file sharing, and Microsoft SSO sign-in.
Application work is scoped and quoted per project.
The $2,500 build price on this page is for static websites. It does not cover a platform with authentication, tenancy, and cloud infrastructure behind it, and we are not going to pretend it does. Tell us what you are trying to build and we will tell you what it costs.
Start a conversation$2,500one-time
$249/month
12-month minimum, month-to-month after that.
Year one runs $5,488 — $2,500 to build plus 12 months of care.
You own your domain and your content. Always. If you leave, you take them with you.
Twenty minutes. We find out what your business does, who you need to reach, and whether we are the right fit. If we are not, we say so on this call.
You send copy, photos, and your logo. We do not start the build until this lands, because unfinished content is what stalls every website project.
We design and build the site, then send you a live preview link. Two rounds of revisions are included.
We handle the domain and DNS, verify performance against real Lighthouse numbers, and put it live.
We host it, monitor it, back it up, and make your content changes. You never touch a plugin update again.
Contractors, clinics, law offices, restaurants, shops, and trades in Central Illinois. If you need a site that loads fast, ranks locally, gets you calls, and never becomes an incident — this is that.
If you need a 200-page storefront with live inventory and warehouse sync, we're not the right fit and we'll tell you that on the first call. If you need a platform with accounts, tenancy, and infrastructure behind it, that is a different conversation and we do build those.
Local enough to meet you in person. If you are outside Central Illinois and the fit is right, we still want to hear from you.
Tell us what your business does and what you need the site to do. We reply within one business day, and the first call is twenty minutes with no pitch deck.
Prefer email? info@injct.io
Looking for a penetration test instead? See our security services.