Budget: 7000 UAH Deadline: 10 days
I will host the copy of the site on my hosting, the production will remain unchanged. Before transferring changes to production - I will create a backup.
I have experience in protection/detection against injections and malicious code.
I have experience in optimizing PageSpeed metrics.
I have worked with both AIOS and the server side. In my opinion, the option with custom development, without vulnerabilities + CloudFlare + IpToBan (conditionally) - is a significantly better solution.
"..they cannot show at least 1-2 examples of sites with high PSI.." - I replied in the comments.