Free WordPress security guides

Plain-English guides for stressed site owners

Everything here is written the way I’d explain it to you directly — no fear-mongering, no jargon. Start wherever your worry is.

It just happened

Emergency playbooks

What to do right now, in the right order, without making anything worse.

WP-Login Brute Force Attacks

Thousands of login attempts in your logs: how to tell noise from a break-in, and what stops it.

Read article →

Host Says Your Site Has Malware

The warning email before a suspension: what the scanner found, what to delete, and whether to buy their fix.

Read article →

Hacked Despite Cloudflare

What Cloudflare's WAF covers, the six ways attackers go around it, and the cached-malware trap.

Read article →

Hosting Suspensions

That 'Account Suspended' page isn't the end. What hosts want, and how fast you can be back.

Read article →

How Sites Get Hacked

The honest answer to the question every hacked-site owner asks me first.

Read article →

Hacked Site First Steps

The first hour after you discover a hack. What to do, and what not to touch.

Read article →

Locked Out After a Hack

Your password stopped working and the reset email never arrives. How to retake control of wp-admin safely.

Read article →

Reading Your Access Logs

Your server recorded every request they made. How to read the logs and find the way in.

Read article →

Preserving Evidence First

Ten minutes before you start deleting will tell you how they got in and what they reached.

Read article →

Timestamp Forensics

Every file records when it changed. Used properly, that tells you exactly when this began.

Read article →

Verifying Core Files

WordPress publishes a hash for every core file. One command lists everything that was altered.

Read article →

Hosting Account Takeover

Not one site but the whole account: panel, FTP, email, every site in it. How to take it back.

Read article →

Hacked DNS or Hacked Site?

Your files are untouched and visitors see someone else's content. The problem may be one level up.

Read article →

Domain Hijacking

Someone took the domain itself. Why this is worse than a hacked site, and how to get it back.

Read article →

Rogue Cloudflare Rules

The origin is clean and visitors still get redirected. Code running in the layer in front of your site.

Read article →

Warnings & blacklists

Google warnings, blacklists & the fallout

What each red screen, search label and disapproval means, and how it gets cleared.

Deceptive Site Warnings

The red Chrome screen, decoded: what each variant means and how to get it taken down.

Read article →

Google Ads Compromised Site

Ads disapproved for a compromised site? Why Ads is stricter than search, and the way out.

Read article →

Search Console Security Issues

Every detection type in the report, and how to write a review request that passes.

Read article →

Hacks and Your Rankings

What a hack really does to your rankings, and how fast they come back after a proper cleanup.

Read article →

This Site May Be Hacked

That little warning under your Google listing, what triggered it, and how to make it go away.

Read article →

Fake Hacked-Site Emails

Extortion, sales pitches and genuine alerts all look alike in your inbox. How to tell them apart before you panic.

Read article →

URL:Mal Detections

Avast and AVG are blocking your site with a generic label that explains nothing. Here is what it means and how to clear it.

Read article →

URL:Blacklist Detections

Avast and AVG matched your address against a blocklist, not your pages. Why it sticks around after a cleanup, and how to clear it.

Read article →

Reconsideration Requests

A manual action stays until a human lifts it. How to write a request that passes first time.

Read article →

Clearing Spam From the Index

The hack is gone and Google still lists thousands of pages you never made. How to clear them.

Read article →

Malicious Outbound Links

Hidden links to spam and malware, added to your pages. Where they hide and how to find every one.

Read article →

Recovering Your Rankings

The site is clean and traffic is still down. What actually recovers, and how long it honestly takes.

Read article →

AdSense After a Hack

Ad serving stopped and the notice mentions malicious software. How to clean up and get it back.

Read article →

Business Profile Suspended

Your listing vanished from Maps after the site was flagged. The order to fix things in.

Read article →

Bing & SmartScreen Warnings

Clearing Google does nothing for Microsoft. Two separate systems, two separate submissions.

Read article →

Know the hack

Field guides to specific hacks

What your site is infected with, how it behaves, and how I clean it.

Unknown Owner in Search Console

How an attacker verified themselves, how to remove them for good, and what it tells you.

Read article →

Slot Gacor Gambling Spam Hack

Indonesian gambling spam only Google can see: find the cloaking code and clear the index.

Read article →

Plugin Closed for Security

A plugin you use was closed on WordPress.org. What it means, whether you were hit, and what to do next.

Read article →

Redirects Only on Mobile

Spam redirects your phone visitors see and you don’t: how to trigger them, find them and kill them.

Read article →

Google Tag Manager Malware

Skimmers and redirects delivered through GTM: rogue containers, hijacked tags, and how to clean both.

Read article →

Malware Hidden in Elementor

Scripts buried in _elementor_data, widgets and popups that file scanners never see, and how to remove them.

Read article →

Defaced Websites

The 'Hacked by' page is the loud part. Recovery means finding the quiet parts too.

Read article →

Site Sending Spam Email

Bounce floods, an angry host, blacklisted mail. Finding the mailer script and shutting it down.

Read article →

Hidden Admin Users

That admin account you didn't create — and the ones that never show on the Users screen.

Read article →

Hacked .htaccess Files

Redirect rules that only fire for Google visitors — and the ten copies you didn't clean.

Read article →

Japanese Keyword Hack

Japanese spam pages ranking under your domain, on a site you never touched. Very fixable.

Read article →

Malware and Site Speed

When 'my site is slow' really means 'my site is infected', and how to tell the difference.

Read article →

Nulled Themes & Fake Plugins

Why the free copy of a $60 theme is never free — you're the payload.

Read article →

Phishing Pages

A fake bank login in a folder you never made, and scary emails about it. Here's what to do.

Read article →

Reinfection Loops

You cleaned it. It came back. Something survived, and here's how to find it.

Read article →

WordPress Backdoors

Why cleanups fail: the hidden doors hackers leave behind, and how I hunt them down.

Read article →

Pharma Hack

Google sees Viagra spam on your site. You see nothing. One of the oldest hacks still running.

Read article →

Injected Spam Links

Hidden links to casinos and counterfeit shops, added to your pages and shown only to Google. Where they hide and how to clear them out.

Read article →

WordPress Redirect Hack

Visitors land on casino or pharmacy pages, but the site looks fine to you. Here's why.

Read article →

wp-config.php After a Hack

The one file that holds your database keys — what to inspect and rotate once you've been hit.

Read article →

WooCommerce Card Skimmers

Fraud reports after checkout? How card-stealing code hides in a store — and what you owe your customers once you find it.

Read article →

Database Malware

Files clean but the spam keeps coming back? The four places malware hides inside the database itself — and how to clean them without breaking the site.

Read article →

WP-VCD Malware

It arrives inside a "free" premium theme, copies itself everywhere, and rebuilds anything you delete. The most common WordPress malware there is.

Read article →

Hacked functions.php Files

The theme file that runs on every single page load is the first place attackers hide code — and the first place to look.

Read article →

xmlrpc.php Attacks

Thousands of requests hitting xmlrpc.php in your logs. Why attackers love it, and how to shut it down.

Read article →

Cryptomining Malware

No defacement, no blacklist warning — just a maxed-out server. The quietest hack there is.

Read article →

Multisite Network Hacked

One infected subsite can compromise the whole network. How to clean every one of them, not just the one you noticed.

Read article →

Contact Form 7 Hacked

Old, unpatched installs let attackers upload PHP disguised as an image through the form itself.

Read article →

Malicious WP-Cron Tasks

The infection rebuilds itself with no new logins. WordPress’s own scheduler lives in the database, where file scanners never look.

Read article →

Obfuscated Code & base64

A few hundred characters of gibberish wrapped in eval(). How to read it safely, and how to tell malware from a legitimate encoded string.

Read article →

PHP Files in Uploads

Your media folder should never hold executable code. Finding a .php file there means something uploaded it — and it is rarely alone.

Read article →

Balada Injector

One of the longest-running WordPress campaigns there is, and a cleanup that never quite sticks.

Read article →

Fake Browser Updates

Your site is telling visitors to update Chrome. It is malware delivery, and they are the target.

Read article →

Sign1 Malware

Popup redirects on a site whose files are all clean. It lives in the database and rotates its own code.

Read article →

Web Shells

One uploaded PHP file gives an attacker a file manager, a database client and a command line.

Read article →

Injected JavaScript

Strange script tags on every page. The four places the injection comes from, and how to tell it from analytics.

Read article →

Hijacked siteurl Values

Two database rows control every URL WordPress builds. Change them and you cannot even log in.

Read article →

mu-plugins Backdoors

Code that loads automatically, cannot be deactivated, and never appears on your plugins screen.

Read article →

Push Notification Spam

Visitors get spam alerts days after leaving. Cleaning your server does not clear their browsers.

Read article →

Sitemap Spam

Your sitemap lists forty thousand pages and your site has sixty. Feeding spam straight to Google.

Read article →

Doorway Pages

Thousands of pages you never made, ranking for terms that have nothing to do with your business.

Read article →

Cloaking Hacks

Your site looks perfect to you and like a pharmacy to Google. How to prove what you really serve.

Read article →

Finding the Mailer Script

Your host says you are sending thousands of emails. How to find the actual file doing it.

Read article →

PHP Hidden in Images

A file that opens as a picture and executes as code. How polyglots slip past upload filters.

Read article →

.user.ini Backdoors

One config line loads attacker code before every page, without touching WordPress at all.

Read article →

Fake Core Files

Malware named after core files so it blends into a directory listing. How to tell real from imitation.

Read article →

Hacked robots.txt

Four lines of text nobody reads. Modified, it hides spam from you and keeps it visible to Google.

Read article →

ClickFix Fake CAPTCHAs

A verification box telling visitors to paste a command into their own computer. It is malware delivery.

Read article →

Cross-Site Contamination

You cleaned the site and it came back from the one next door. Why sequential cleanups go in circles.

Read article →

Other platforms

Not running WordPress?

Joomla, Drupal, Magento, Shopify, Laravel, Node, IIS and the rest — same attacks, different doors.

Hacked Joomla Sites

Same campaigns as WordPress, different doors. Where malware hides in a Joomla install.

Read article →

Hacked Drupal Sites

Usually unpatched core or a vulnerable contributed module. Where to look and why timing matters.

Read article →

Magento Card Skimmers

A skimmer on Magento checkout is a payment incident, not just a malware problem.

Read article →

PrestaShop & OpenCart

All the attention of an e-commerce target with a fraction of the documentation.

Read article →

Hacked Static HTML Sites

No database, no CMS, no plugins — and still compromised. The cleanup is simpler than you think.

Read article →

Exposed .env Files

One misconfigured server and your database password and API keys are a public URL away.

Read article →

Hacked Shopify Stores

You cannot get a backdoor onto Shopify's servers, but your store can still be compromised. The three real routes.

Read article →

Wix & Squarespace

Most hack symptoms on a hosted builder have a different cause. Telling a real compromise from the lookalikes.

Read article →

Magento Admin Compromised

An admin account you did not create. What they do with it, and why revoking API tokens matters most.

Read article →

Magento 1 in 2026

No security patches since 2020. The honest position, and the realistic options if you are still on it.

Read article →

Locked Out of Joomla

Your Super User password stopped working. Three ways back into the back end without the login form.

Read article →

Legacy Drupal & Drupalgeddon

Old Drupal carries years of unpatched flaws. Checking whether you were caught in a wave years ago.

Read article →

Hacked Laravel Apps

Rarely a framework flaw. Debug mode, exposed config, queued jobs and the app key are where the problems are.

Read article →

Node.js & Next.js

No PHP to scan and no uploads folder. Node compromises live in dependencies and the build pipeline.

Read article →

ASP.NET & IIS

Windows hosting has its own hiding places: web.config handlers, ASPX shells and application pool identities.

Read article →

Hacked WHMCS

A compromised billing system exposes client data and the credentials it holds for every server it manages.

Read article →

Hacked Moodle

Student records, grades and academic integrity. The data question usually outranks the malware.

Read article →

Hacked Forums

phpBB, vBulletin and MyBB: open registration, uploads by design, and years of core file modifications.

Read article →

Hacked TYPO3

Runs a lot of European business sites and gets a fraction of the cleanup documentation it deserves.

Read article →

Hacked Ghost CMS

A small attack surface, so the list is short: version, login, theme, and the code injection fields.

Read article →

Costs & choices

Costs, timelines & decisions

Straight answers about money, time, and whether to DIY or hand it off.

Recommended reading order

Detect, recover, then prevent

01

Confirm and preserve

Start with the owner checklist. Record symptoms and take a backup before making destructive changes.

Owner checklist →

02

Investigate the indicators

Use the technical IOC checklist to examine files, users, tasks, database content and logs.

Technical checklist →

03

Recover and harden

Remove the payload and persistence, close the entry point, rotate access and monitor for recurrence.

Prevention guide →