Free WordPress security guides
Plain-English guides for stressed site owners
Everything here is written the way I’d explain it to you directly — no fear-mongering, no jargon. Start wherever your worry is.
Start here
The foundations
01
Identifying Website Hacks
The calm first step: how to tell whether your site is actually hacked.
Read guide →02
Hack Detection & Indicators
The tell-tale signs of a compromised site, in plain English.
Read guide →03
Types of Hacks & Their Specifics
The common ways WordPress sites get hit — and what each one means.
Read guide →04
Security Best Practices
Practical habits that keep your site out of trouble in the first place.
Read guide →05
User Access and Permissions
Who can do what on your site — and why it matters more than you think.
Read guide →06
Backup and Recovery Strategies
How to make sure a hack is a bad day, not a disaster.
Read guide →07
Monitoring and Long‑Term Protection
Catching problems early so they never become emergencies.
Read guide →09
Website Security Packages
What ongoing protection looks like, and how to choose sensibly.
Read guide →10
Why WordFence
Why I lean on Wordfence for WordPress security, and how to use it well.
Read guide →Rather not do it yourself? That’s what I’m here for.
It just happened
Emergency playbooks
What to do right now, in the right order, without making anything worse.
WP-Login Brute Force Attacks
Thousands of login attempts in your logs: how to tell noise from a break-in, and what stops it.
Read article →Host Says Your Site Has Malware
The warning email before a suspension: what the scanner found, what to delete, and whether to buy their fix.
Read article →Hacked Despite Cloudflare
What Cloudflare's WAF covers, the six ways attackers go around it, and the cached-malware trap.
Read article →Hosting Suspensions
That 'Account Suspended' page isn't the end. What hosts want, and how fast you can be back.
Read article →How Sites Get Hacked
The honest answer to the question every hacked-site owner asks me first.
Read article →Hacked Site First Steps
The first hour after you discover a hack. What to do, and what not to touch.
Read article →Locked Out After a Hack
Your password stopped working and the reset email never arrives. How to retake control of wp-admin safely.
Read article →Reading Your Access Logs
Your server recorded every request they made. How to read the logs and find the way in.
Read article →Preserving Evidence First
Ten minutes before you start deleting will tell you how they got in and what they reached.
Read article →Timestamp Forensics
Every file records when it changed. Used properly, that tells you exactly when this began.
Read article →Verifying Core Files
WordPress publishes a hash for every core file. One command lists everything that was altered.
Read article →Hosting Account Takeover
Not one site but the whole account: panel, FTP, email, every site in it. How to take it back.
Read article →Hacked DNS or Hacked Site?
Your files are untouched and visitors see someone else's content. The problem may be one level up.
Read article →Domain Hijacking
Someone took the domain itself. Why this is worse than a hacked site, and how to get it back.
Read article →Rogue Cloudflare Rules
The origin is clean and visitors still get redirected. Code running in the layer in front of your site.
Read article →Warnings & blacklists
Google warnings, blacklists & the fallout
What each red screen, search label and disapproval means, and how it gets cleared.
Deceptive Site Warnings
The red Chrome screen, decoded: what each variant means and how to get it taken down.
Read article →Google Ads Compromised Site
Ads disapproved for a compromised site? Why Ads is stricter than search, and the way out.
Read article →Search Console Security Issues
Every detection type in the report, and how to write a review request that passes.
Read article →Hacks and Your Rankings
What a hack really does to your rankings, and how fast they come back after a proper cleanup.
Read article →This Site May Be Hacked
That little warning under your Google listing, what triggered it, and how to make it go away.
Read article →Fake Hacked-Site Emails
Extortion, sales pitches and genuine alerts all look alike in your inbox. How to tell them apart before you panic.
Read article →URL:Mal Detections
Avast and AVG are blocking your site with a generic label that explains nothing. Here is what it means and how to clear it.
Read article →URL:Blacklist Detections
Avast and AVG matched your address against a blocklist, not your pages. Why it sticks around after a cleanup, and how to clear it.
Read article →Reconsideration Requests
A manual action stays until a human lifts it. How to write a request that passes first time.
Read article →Clearing Spam From the Index
The hack is gone and Google still lists thousands of pages you never made. How to clear them.
Read article →Malicious Outbound Links
Hidden links to spam and malware, added to your pages. Where they hide and how to find every one.
Read article →Recovering Your Rankings
The site is clean and traffic is still down. What actually recovers, and how long it honestly takes.
Read article →AdSense After a Hack
Ad serving stopped and the notice mentions malicious software. How to clean up and get it back.
Read article →Business Profile Suspended
Your listing vanished from Maps after the site was flagged. The order to fix things in.
Read article →Bing & SmartScreen Warnings
Clearing Google does nothing for Microsoft. Two separate systems, two separate submissions.
Read article →Detection labels
Antivirus & VirusTotal detections, decoded
What the label on a VirusTotal report or a block screen actually means, how much weight to give it, and how to check who else is flagging you.
Website Blacklist Check
Every vendor's official lookup tool in one table, and the right order to get delisted.
Read article →Static AI – Suspicious PE
SentinelOne's machine-learning verdict on VirusTotal, decoded: suspicious vs malicious, PE vs archive.
Read article →VirusTotal Confidence Labels
High confidence, ML score, AIDetectMalware, Static ML: which VirusTotal verdicts deserve your worry.
Read article →Gridinsoft Verdicts Explained
Suspicious vs Phishing vs Malicious, the (no cloud) engine, and whether Gridinsoft itself is legit.
Read article →Tencent94332 & Tencent Detections
What real Tencent detection names look like, and how to trace an unexplained 'tencent' string on your site.
Read article →New Domain Flagged as Phishing
Why brand-new sites get blocked as phishing, how long it lasts, and how to get recategorised.
Read article →Strange Domain in Your Code
How to check an unknown script domain safely, find every copy, and stop it coming back.
Read article →Know the hack
Field guides to specific hacks
What your site is infected with, how it behaves, and how I clean it.
Unknown Owner in Search Console
How an attacker verified themselves, how to remove them for good, and what it tells you.
Read article →Slot Gacor Gambling Spam Hack
Indonesian gambling spam only Google can see: find the cloaking code and clear the index.
Read article →Plugin Closed for Security
A plugin you use was closed on WordPress.org. What it means, whether you were hit, and what to do next.
Read article →Redirects Only on Mobile
Spam redirects your phone visitors see and you don’t: how to trigger them, find them and kill them.
Read article →Google Tag Manager Malware
Skimmers and redirects delivered through GTM: rogue containers, hijacked tags, and how to clean both.
Read article →Malware Hidden in Elementor
Scripts buried in _elementor_data, widgets and popups that file scanners never see, and how to remove them.
Read article →Defaced Websites
The 'Hacked by' page is the loud part. Recovery means finding the quiet parts too.
Read article →Site Sending Spam Email
Bounce floods, an angry host, blacklisted mail. Finding the mailer script and shutting it down.
Read article →Hidden Admin Users
That admin account you didn't create — and the ones that never show on the Users screen.
Read article →Hacked .htaccess Files
Redirect rules that only fire for Google visitors — and the ten copies you didn't clean.
Read article →Japanese Keyword Hack
Japanese spam pages ranking under your domain, on a site you never touched. Very fixable.
Read article →Malware and Site Speed
When 'my site is slow' really means 'my site is infected', and how to tell the difference.
Read article →Nulled Themes & Fake Plugins
Why the free copy of a $60 theme is never free — you're the payload.
Read article →Phishing Pages
A fake bank login in a folder you never made, and scary emails about it. Here's what to do.
Read article →Reinfection Loops
You cleaned it. It came back. Something survived, and here's how to find it.
Read article →WordPress Backdoors
Why cleanups fail: the hidden doors hackers leave behind, and how I hunt them down.
Read article →Pharma Hack
Google sees Viagra spam on your site. You see nothing. One of the oldest hacks still running.
Read article →Injected Spam Links
Hidden links to casinos and counterfeit shops, added to your pages and shown only to Google. Where they hide and how to clear them out.
Read article →WordPress Redirect Hack
Visitors land on casino or pharmacy pages, but the site looks fine to you. Here's why.
Read article →wp-config.php After a Hack
The one file that holds your database keys — what to inspect and rotate once you've been hit.
Read article →WooCommerce Card Skimmers
Fraud reports after checkout? How card-stealing code hides in a store — and what you owe your customers once you find it.
Read article →Database Malware
Files clean but the spam keeps coming back? The four places malware hides inside the database itself — and how to clean them without breaking the site.
Read article →WP-VCD Malware
It arrives inside a "free" premium theme, copies itself everywhere, and rebuilds anything you delete. The most common WordPress malware there is.
Read article →Hacked functions.php Files
The theme file that runs on every single page load is the first place attackers hide code — and the first place to look.
Read article →xmlrpc.php Attacks
Thousands of requests hitting xmlrpc.php in your logs. Why attackers love it, and how to shut it down.
Read article →Cryptomining Malware
No defacement, no blacklist warning — just a maxed-out server. The quietest hack there is.
Read article →Multisite Network Hacked
One infected subsite can compromise the whole network. How to clean every one of them, not just the one you noticed.
Read article →Contact Form 7 Hacked
Old, unpatched installs let attackers upload PHP disguised as an image through the form itself.
Read article →Malicious WP-Cron Tasks
The infection rebuilds itself with no new logins. WordPress’s own scheduler lives in the database, where file scanners never look.
Read article →Obfuscated Code & base64
A few hundred characters of gibberish wrapped in eval(). How to read it safely, and how to tell malware from a legitimate encoded string.
Read article →PHP Files in Uploads
Your media folder should never hold executable code. Finding a .php file there means something uploaded it — and it is rarely alone.
Read article →Balada Injector
One of the longest-running WordPress campaigns there is, and a cleanup that never quite sticks.
Read article →Fake Browser Updates
Your site is telling visitors to update Chrome. It is malware delivery, and they are the target.
Read article →Sign1 Malware
Popup redirects on a site whose files are all clean. It lives in the database and rotates its own code.
Read article →Web Shells
One uploaded PHP file gives an attacker a file manager, a database client and a command line.
Read article →Injected JavaScript
Strange script tags on every page. The four places the injection comes from, and how to tell it from analytics.
Read article →Hijacked siteurl Values
Two database rows control every URL WordPress builds. Change them and you cannot even log in.
Read article →mu-plugins Backdoors
Code that loads automatically, cannot be deactivated, and never appears on your plugins screen.
Read article →Push Notification Spam
Visitors get spam alerts days after leaving. Cleaning your server does not clear their browsers.
Read article →Sitemap Spam
Your sitemap lists forty thousand pages and your site has sixty. Feeding spam straight to Google.
Read article →Doorway Pages
Thousands of pages you never made, ranking for terms that have nothing to do with your business.
Read article →Cloaking Hacks
Your site looks perfect to you and like a pharmacy to Google. How to prove what you really serve.
Read article →Finding the Mailer Script
Your host says you are sending thousands of emails. How to find the actual file doing it.
Read article →PHP Hidden in Images
A file that opens as a picture and executes as code. How polyglots slip past upload filters.
Read article →.user.ini Backdoors
One config line loads attacker code before every page, without touching WordPress at all.
Read article →Fake Core Files
Malware named after core files so it blends into a directory listing. How to tell real from imitation.
Read article →Hacked robots.txt
Four lines of text nobody reads. Modified, it hides spam from you and keeps it visible to Google.
Read article →ClickFix Fake CAPTCHAs
A verification box telling visitors to paste a command into their own computer. It is malware delivery.
Read article →Cross-Site Contamination
You cleaned the site and it came back from the one next door. Why sequential cleanups go in circles.
Read article →Other platforms
Not running WordPress?
Joomla, Drupal, Magento, Shopify, Laravel, Node, IIS and the rest — same attacks, different doors.
Hacked Joomla Sites
Same campaigns as WordPress, different doors. Where malware hides in a Joomla install.
Read article →Hacked Drupal Sites
Usually unpatched core or a vulnerable contributed module. Where to look and why timing matters.
Read article →Magento Card Skimmers
A skimmer on Magento checkout is a payment incident, not just a malware problem.
Read article →PrestaShop & OpenCart
All the attention of an e-commerce target with a fraction of the documentation.
Read article →Hacked Static HTML Sites
No database, no CMS, no plugins — and still compromised. The cleanup is simpler than you think.
Read article →Exposed .env Files
One misconfigured server and your database password and API keys are a public URL away.
Read article →Hacked Shopify Stores
You cannot get a backdoor onto Shopify's servers, but your store can still be compromised. The three real routes.
Read article →Wix & Squarespace
Most hack symptoms on a hosted builder have a different cause. Telling a real compromise from the lookalikes.
Read article →Magento Admin Compromised
An admin account you did not create. What they do with it, and why revoking API tokens matters most.
Read article →Magento 1 in 2026
No security patches since 2020. The honest position, and the realistic options if you are still on it.
Read article →Locked Out of Joomla
Your Super User password stopped working. Three ways back into the back end without the login form.
Read article →Legacy Drupal & Drupalgeddon
Old Drupal carries years of unpatched flaws. Checking whether you were caught in a wave years ago.
Read article →Hacked Laravel Apps
Rarely a framework flaw. Debug mode, exposed config, queued jobs and the app key are where the problems are.
Read article →Node.js & Next.js
No PHP to scan and no uploads folder. Node compromises live in dependencies and the build pipeline.
Read article →ASP.NET & IIS
Windows hosting has its own hiding places: web.config handlers, ASPX shells and application pool identities.
Read article →Hacked WHMCS
A compromised billing system exposes client data and the credentials it holds for every server it manages.
Read article →Hacked Moodle
Student records, grades and academic integrity. The data question usually outranks the malware.
Read article →Hacked Forums
phpBB, vBulletin and MyBB: open registration, uploads by design, and years of core file modifications.
Read article →Hacked TYPO3
Runs a lot of European business sites and gets a fraction of the cleanup documentation it deserves.
Read article →Hacked Ghost CMS
A small attack surface, so the list is short: version, login, theme, and the code injection fields.
Read article →Credentials & email
Credentials, email and the fallout
What to rotate, what was exposed, and how to get your email delivered again.
WordPress Admin Email Changed
Reset links going to an attacker? How the email gets changed, how to check it and the right fix order.
Read article →Email Delivery After a Hack
The spam stopped and now your invoices bounce. How sending reputation is repaired, in order.
Read article →SPF, DKIM and DMARC
The three records that prove your mail is really yours, and the mistakes that quietly break them.
Read article →Stolen SMTP Credentials
Spam sent through your real email account, from somewhere else. Cleaning the site will not stop it.
Read article →Rotating Every Credential
A full checklist of the passwords, keys and salts a compromise exposed — including the forgotten ones.
Read article →When It Was Your Computer
No exploit, no trace, because they logged in with your password. Stealer malware and hacked sites.
Read article →Costs & choices
Costs, timelines & decisions
Straight answers about money, time, and whether to DIY or hand it off.
Backups vs. Cleanups
Why rolling back to last week's backup usually brings the hack right back with it.
Read article →Hacked Website Repair Costs
Honest numbers for cleanup work, and what makes some hacked sites cost more than others.
Read article →Hack Recovery Timelines
The honest clock on a recovery: hours for the cleanup, days for Google, longer if you wait.
Read article →Choosing a Cleanup Path
Plugin, service, or a person? Where each one shines and where each one leaves you stuck.
Read article →Telling Customers After a Hack
Whether a hack stays a private repair or becomes a public disclosure hangs on one question: what did they actually reach?
Read article →Red Flags When Hiring
How to tell a real cleanup from an expensive scan, and the five questions worth asking first.
Read article →What a Cleanup Report Needs
You should get more than an assurance it is fixed. What a real report includes, and why.
Read article →Why Scanners Miss Backdoors
Your scan says clean and the site is still infected. What automated scanning structurally cannot see.
Read article →Rebuild or Clean?
Sometimes starting fresh is right and usually it is not. An honest framework for deciding.
Read article →Breach Notification Duties
When a hacked site becomes a reportable data breach, who you tell, and how quickly.
Read article →PCI After a Skimmer
A skimmer on your checkout brings defined obligations. What happens next and who to call.
Read article →Recommended reading order
Detect, recover, then prevent
01
Confirm and preserve
Start with the owner checklist. Record symptoms and take a backup before making destructive changes.
Owner checklist →02
Investigate the indicators
Use the technical IOC checklist to examine files, users, tasks, database content and logs.
Technical checklist →03
Recover and harden
Remove the payload and persistence, close the entry point, rotate access and monitor for recurrence.
Prevention guide →More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.