Margins matter too, not just headcount. Someone could do $2m/year but make less than someone doing $800k/year with better margins.
Doing perf/security reviews of a niche like that (woo, magento, etc) would probably still be a place to focus and make money, if you want to stay 'back end' (or at least technical). But even then, some of the measurable stuff will be needed - "we reduced the load times by 45% on the checkout page, and conversions went up 17%, adding $87k in profit last year".
99% don't care unless and until they get hacked, they will also forget about it all in 2 months.
If they don't get hacked for years they will just attribute that to luck and probability, not valuable security consulting.
And if they do... you can guess that one.
Lots of smaller businesses just don't care. They also don't have "chief somethings" to tell them it's important, or to do it to save their own asses just in case.
They just fly blind and in many cases they get lucky which further solidifies their beliefs.
And in the odd case when they get screwed they just bury it and move on.
Or post a "we are very sorry! security is our TOP PRIORITY!" message somewhere and move on.
I mean just look at the Equifax fiasco. Then scale that down to the smaller companies and see what you end up with...