The world leader in climbing and access equipment needed urgent security fixes to their Drupal website. Following a security and code audit by French Drupal security expert, Frederique Marrand, it was found that the original Drupal 5 development of the site had not been done in compliance with Drupal guidelines.
In particular the Drupal core files and contributed modules had been modifed directly, removing any possibility of upgrading inline with Drupal securtiy releases. The theme layer was also in a bad state, containing security weaknesses, business logic and code which would normally be provided by custom modules.
We removed direct code modifications from Drupal core and from most contributed modules and rebuilt functionality in small and lean custom modules, and brought the whole project to an easily updatable and upgradable state with a view on the upcoming Drupal 7 rebuild.