White-Label Drupal for Agencies

Steady, senior Drupal help for the weeks your pipeline is fuller than your team. I take discrete pieces of work at a fixed price against an agreed date, delivered under your name. A price and a deadline, not a day rate and a timesheet.

Fixed Price

You get a price and a date up front. Overrun risk sits with me, not your project margin.

White-Label

I work to your standards and hand back clean, documented code. Your client never hears my name.

Security Credentials

Drupal Security Team advisory credit and two published payment gateway modules on Drupal.org.

28 Years of PHP

Production Drupal Commerce experience and a long history of legacy PHP that still has to work.

What I take on

Narrow, deep pieces that are awkward to staff for and easy to hand out. Each one is scoped, priced, and delivered as a single deliverable.

Module security audits

Independent contrib and custom module review, with a severity-rated report and patches where remediation is in scope. Useful as evidence at ISO 27001 surveillance, and as an independent second pair of eyes your own team cannot be for its own code.

CyberSource and B2B payments for Drupal Commerce

Invoice payment, stored credentials, quote-to-order, and reducing a merchant's PCI scope to SAQ-A rather than SAQ-A-EP. I maintain two published CyberSource gateway modules, so this is my day-to-day rather than a first attempt.

Drupal 7 to 11 and PHP upgrades

Module and custom-code porting, and PHP 8.x upgrades priced per site. The kind of migration backlog that fills up fast as end-of-life deadlines and Cyber Essentials renewals close in.

Why an outside specialist, not another pair of hands

Some work is better done by someone outside the team. An independent security audit carries weight precisely because the author did not write the code. A payment integration is safer in the hands of someone who has shipped that gateway before. And migration overflow lets your own people stay on the roadmap work your clients are paying for.

Verifiable, not just claimed.

In June 2026 I reported the Commerce Core cross-site scripting issue published as SA-CONTRIB-2026-041. It is public on Drupal.org, in my name. My contrib work and the two CyberSource gateway modules are there too.

How it works

1

Send me a sentence or two

A plain description of the piece you want to hand out. No formal spec needed. I will ask the questions that matter and tell you honestly if it is not a good fit.

2

You get a fixed price and a date

A clear deliverable, a fixed price, and a delivery date you can plan a client commitment around. No hourly billing, no scope-creep surprises.

3

I deliver under your name

Clean, documented, reviewable code that matches your conventions, plus the report or patch set where the work calls for one.

4

Honest about the shape

I hold a full-time senior role, so this is discrete fixed-price work in evenings and weekends, not sustained embedded capacity. My employer has cleared the consultancy work. If you need a full-time contractor, I am not that, and I will say so.

More work than time this month?

Send me a sentence or two about the piece you want to hand out. I will come back within a working day.

Get in touch