A business site compromised through a file-manager plugin: remote-code backdoors removed, 9,600+ spam posts purged, then hardened so it cannot happen the same way twice.
Results at a Glance
The site looked normal to its owners. Underneath, attackers had come in through a vulnerable file-manager plugin, planted PHP backdoors for ongoing remote access, and flooded the database with more than nine thousand spam posts aimed at hijacking the site's search presence.
The brief: find everything, remove everything, prove it is clean, and make sure the same door cannot be opened again.
Spam content is the visible symptom; the dangerous part is the access that planted it. Cleaning posts without finding every shell just invites the attacker back tomorrow.
Active remote-code backdoors
Injected PHP shells gave the attackers ongoing access independent of any password.
9,600+ spam posts
Keyword spam flooding the database, sitemaps and search results.
A vulnerable plugin as the door
A file-manager plugin with a known remote-code-execution history, still installed and active.
The challenge was real, and it was costing time, money, and client experience.
Forensics first: file-integrity comparison against known-good WordPress and plugin sources, database inspection, and a timeline of what was modified when. Every injector, shell and modified core file was catalogued before anything was deleted, so nothing regrew.
Then the purge and the hardening: spam posts removed in bulk with the database verified afterwards, the vulnerable plugin removed entirely, credentials rotated, and a hardening checklist handed over covering the live server.
The solution was designed from the ground up to fit this exact business.
File-integrity diff, database inspection, modification timeline.
Every injector and shell catalogued, then removed together.
9,600+ posts removed in bulk, database verified clean.
Entry point removed, credentials rotated, live-server checklist delivered.
Each tool chosen specifically for reliability, integration depth, and ease of use for the client.
The compromised platform, preserved through cleanup.
Integrity diffs, bulk operations, verification.
Plugin removal, credential rotation, monitoring plan.
A verifiably clean site and a straight answer about how it happened, in plain English the owners could act on.
Catalogued first, removed together.
Database verified after the bulk removal.
Vulnerable plugin gone, credentials rotated.
Send me the brief, a Figma file, a reference site or a rough outline, and you'll have a fixed quote with a delivery date within 24 hours.