Rescue · Security Forensics

Hacked-Site Cleanup & Hardening for a Marketing Services Firm

A business site compromised through a file-manager plugin: remote-code backdoors removed, 9,600+ spam posts purged, then hardened so it cannot happen the same way twice.

Results at a Glance

100%
Backdoors removed
9,600+
Spam posts purged
Closed
RCE entry point

A working business site, quietly working for someone else

The site looked normal to its owners. Underneath, attackers had come in through a vulnerable file-manager plugin, planted PHP backdoors for ongoing remote access, and flooded the database with more than nine thousand spam posts aimed at hijacking the site's search presence.

The brief: find everything, remove everything, prove it is clean, and make sure the same door cannot be opened again.

Industry Professional Services
Delivery Time Emergency response
Primary Result Clean site, closed entry point
Platforms
WordPressDiviWP-CLISecurity tooling
Services
Sole responder: forensicscleanuphardening plan

What the forensics found

Spam content is the visible symptom; the dangerous part is the access that planted it. Cleaning posts without finding every shell just invites the attacker back tomorrow.

Active remote-code backdoors

Injected PHP shells gave the attackers ongoing access independent of any password.

9,600+ spam posts

Keyword spam flooding the database, sitemaps and search results.

A vulnerable plugin as the door

A file-manager plugin with a known remote-code-execution history, still installed and active.

The challenge was real, and it was costing time, money, and client experience.

How the cleanup ran

Forensics first: file-integrity comparison against known-good WordPress and plugin sources, database inspection, and a timeline of what was modified when. Every injector, shell and modified core file was catalogued before anything was deleted, so nothing regrew.

Then the purge and the hardening: spam posts removed in bulk with the database verified afterwards, the vulnerable plugin removed entirely, credentials rotated, and a hardening checklist handed over covering the live server.

The solution was designed from the ground up to fit this exact business.

Forensic audit

File-integrity diff, database inspection, modification timeline.

Backdoor removal

Every injector and shell catalogued, then removed together.

Spam purge

9,600+ posts removed in bulk, database verified clean.

Hardening & handover

Entry point removed, credentials rotated, live-server checklist delivered.

Tools Used

Each tool chosen specifically for reliability, integration depth, and ease of use for the client.

WordPress + Divi

The compromised platform, preserved through cleanup.

WP-CLI & DB forensics

Integrity diffs, bulk operations, verification.

Hardening pass

Plugin removal, credential rotation, monitoring plan.

What shipped

A verifiably clean site and a straight answer about how it happened, in plain English the owners could act on.

100%
Backdoors removed

Catalogued first, removed together.

9,600+
Spam posts purged

Database verified after the bulk removal.

1
Entry point closed

Vulnerable plugin gone, credentials rotated.

Before
Attackers held remote access via PHP shells
Thousands of spam posts in the database
Vulnerable file-manager plugin active
Owners unaware how deep it went
After
Every backdoor found and removed
Database verifiably clean
Entry point removed, credentials rotated
Plain-English hardening plan delivered

Next Case Study

Invitation-Only Site for a Multifamily Investment Firm
Real Estate · Investor Relations
Invitation-Only Site for a Multifamily Investment Firm
An investment firm that admits investors by invitation, so every route on…

Need a build like this delivered for your agency?

Send me the brief, a Figma file, a reference site or a rough outline, and you'll have a fixed quote with a delivery date within 24 hours.