Malware Remediation and Website Security
Budget: $10 – $30 USD
Website flagged for malware. We need an immediate fix today and a permanent solution going forward.
A week ago, the following was done:
WHAT WAS FOUND LAST WEEK:
- 30 spam blog posts (casino/gambling content in multiple languages - Russian, German, Swedish, English) were published on the site between March 2025 and February 2026
- These were all published through the single admin account. The password was likely compromised or brute-forced, which is how the attacker got in
- The Blog page was showing spam because it listed these posts
- No Googlebot cloaking detected (some malware shows different content to Google vs real users - this site doesn't have that)
- No malicious JavaScript injections found
- No backdoor files or hidden admin accounts found
- The 4 pages Google flagged (car batteries, diagnostics, about us) were false positives - they contain the word "specialist" which Google's scanner partially matched against pharmacy spam keywords
WHAT WAS CLEANED:
1. Deleted all 30 spam blog posts (permanently, not just trashed)
2. Deleted an orphaned "Lorem Ipsum" draft post
3. Activated the Activity Log plugin (was installed but inactive) - this will track who does what going forward
4. Verified the blog page, all service pages, and homepage are completely clean
5. Verified no cloaking - Googlebot sees the same clean site as regular visitors
PLUGIN UPDATES (all 16 done):
- Advanced Custom Fields 6.7.1 -> 6.8.0
- All-in-One WP Migration 7.103 -> 7.105
- WebP Converter 6.5.4 -> 6.5.5
- Current Year Shortcode -> 2.5
- Duplicate Page -> 4.5.7
- Elementor 3.35.8 -> 4.0.2
- Elementor Pro (already latest)
- JetEngine -> 3.8.8
- Jetpack Protect -> 5.0.0
- Limit Login Attempts -> 3.1.0
- ManageWP Worker -> 4.9.33
- Really Simple SSL -> 9.5.9
- Insert Headers and Footers -> 2.3.5
- WPForms -> 1.10.0.4
- WP Headers and Footers -> 3.1.4
- Yoast SEO -> 27.4
SECURITY HARDENING:
- Added security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy) - all verified working
- Disabled file editing in wp-admin (prevents hackers from editing theme/plugin files if they get in)
- Hidden WordPress version number from page source
- Blocked user enumeration (author archive redirects)
- XMLRPC was already blocked by the hosting (good)
- Activated Activity Log plugin to track future admin activity
FULL SUMMARY OF ALL WORK DONE:
1. Deleted 30 spam blog posts (casino/gambling content)
2. Updated all 16 plugins to latest versions
3. Added security hardening snippet with headers and protections
4. Verified site is clean (no spam, no cloaking, no backdoors)
5. Admin password changed
A week ago, the following was done:
WHAT WAS FOUND LAST WEEK:
- 30 spam blog posts (casino/gambling content in multiple languages - Russian, German, Swedish, English) were published on the site between March 2025 and February 2026
- These were all published through the single admin account. The password was likely compromised or brute-forced, which is how the attacker got in
- The Blog page was showing spam because it listed these posts
- No Googlebot cloaking detected (some malware shows different content to Google vs real users - this site doesn't have that)
- No malicious JavaScript injections found
- No backdoor files or hidden admin accounts found
- The 4 pages Google flagged (car batteries, diagnostics, about us) were false positives - they contain the word "specialist" which Google's scanner partially matched against pharmacy spam keywords
WHAT WAS CLEANED:
1. Deleted all 30 spam blog posts (permanently, not just trashed)
2. Deleted an orphaned "Lorem Ipsum" draft post
3. Activated the Activity Log plugin (was installed but inactive) - this will track who does what going forward
4. Verified the blog page, all service pages, and homepage are completely clean
5. Verified no cloaking - Googlebot sees the same clean site as regular visitors
PLUGIN UPDATES (all 16 done):
- Advanced Custom Fields 6.7.1 -> 6.8.0
- All-in-One WP Migration 7.103 -> 7.105
- WebP Converter 6.5.4 -> 6.5.5
- Current Year Shortcode -> 2.5
- Duplicate Page -> 4.5.7
- Elementor 3.35.8 -> 4.0.2
- Elementor Pro (already latest)
- JetEngine -> 3.8.8
- Jetpack Protect -> 5.0.0
- Limit Login Attempts -> 3.1.0
- ManageWP Worker -> 4.9.33
- Really Simple SSL -> 9.5.9
- Insert Headers and Footers -> 2.3.5
- WPForms -> 1.10.0.4
- WP Headers and Footers -> 3.1.4
- Yoast SEO -> 27.4
SECURITY HARDENING:
- Added security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy) - all verified working
- Disabled file editing in wp-admin (prevents hackers from editing theme/plugin files if they get in)
- Hidden WordPress version number from page source
- Blocked user enumeration (author archive redirects)
- XMLRPC was already blocked by the hosting (good)
- Activated Activity Log plugin to track future admin activity
FULL SUMMARY OF ALL WORK DONE:
1. Deleted 30 spam blog posts (casino/gambling content)
2. Updated all 16 plugins to latest versions
3. Added security hardening snippet with headers and protections
4. Verified site is clean (no spam, no cloaking, no backdoors)
5. Admin password changed