
Who
I still get the call after Bluehost malware: rebuild the marketing site, keep the builder’s phone ringing, and put the work in git without committing wp-content.
Highlands / Cashiers luxury custom-home buyers need a gallery and a form. Operators need a checklist that survives a .gitignore that deletes the entire WordPress tree from the repo.
What
I keep jenningscustomhomes. Public Hustle-Launch/jenningscustomhomes. HEAD ad1f91f. 5 commits. GitHub linguist empty. Tracked surface: 4 files.

README truth: Design a new website following a malware infection due to a lack of security on Bluehost. Next steps cover CSS cleanup, WP settings, CNAME, Analytics, Rank Math, socials, TrustIndex, form actions, SPF, login details.

HEAD “Launched” flips nine boxes to [x]. Two stay honest: TrustIndex [-] // client does not have any reviews, and Send login details [-].
Live product https://www.jenningscustomhomes.com. WordPress 7.1, Hello Elementor 3.5.1, child theme jch 2.0.0, Elementor 4.2.4, Elementor Pro 3.24.4, Elementor Contact form (name / email / message). Contact block: 83 Village Walk Wy, Cashiers, NC 28717 · 828-743-2307 · sam@jenningscustomhomes.com.

Pack-day DNS: 75.98.174.238, NS ns1/ns2.bluehost.com, LiteSpeed, PHP 8.3.33, Let’s Encrypt, HTTP/2 200. SPF still includes websitewelcome.com plus jch.hustlelaunch.com and an A2 host. Malware story. Host unchanged.

Honest gaps: G-85CPJ4D64C fires on about/contact/404, and does not fire on homepage HTML. Checklist claims Rank Math; home surface shows core wp-sitemap.xml only (no rank-math assets observed). About Partners block is still lorem ipsum. Repo gitignore means the live stack is HTTP-observable only.
Where
Code: github.com/Hustle-Launch/jenningscustomhomes. Public, no license declared.
Product: www.jenningscustomhomes.com. Cashiers / Highlands / Western NC custom luxury builder (marketing copy: in business since 2001).
git clone https://github.com/Hustle-Launch/jenningscustomhomes.git
# you get the checklist + gitignore, not wp-admin
When
2024-06-04 22:43 ET. 833a3eb init (.gitignore, empty README, workspace, SuperMaven recommend).
22:47 ET. 323c90a empty “ready to launch” (same tree).
2024-06-05 05:53 ET. 7f7964d checklist all open.
06:30 ET. e36678b preflight newline.
2024-06-06 14:33 ET. ad1f91f Launched to HEAD. Push 2024-06-06T18:34:29Z.
2026-09-08. Pack day. Site live. Still Bluehost. Draft and assets only. Do not publish.

Why
A malware rebuild that never leaves the host that got infected is a different story than a platform migration, and the README still tells it.
A public repo that gitignores WordPress is an ops checklist. Treat it like one, not like a content dump.
Checkboxes that leave TrustIndex and login handoff open are more honest than a fake green board.
Would you move NS off Bluehost next, or fix homepage GA injection and kill the About Partners lorem first?
