12 signs your WordPress site is infected
Malicious code rarely announces itself. These twelve signs mean something is already happening on your site.
Short articles from practice: how to recognise an infected site, what to do after a breach, why a site is slow and what public sector websites must meet.
Malicious code rarely announces itself. These twelve signs mean something is already happening on your site.
Redirect malware works selectively: the administrator never sees it, while visitors from Google land somewhere else.
Search results show Japanese or Chinese text under your site name. Here is what is actually happening.
The red browser warning stops almost all traffic. Here is the order in which it gets resolved.
A rogue administrator is not the cause of a breach but its consequence. Here is what it tells you.
How to recognise obfuscated code in WordPress files, and why looking only in the theme is not enough.
Emails stop reaching customers and your IP lands on blacklists. The usual causes and what to do first.
The CPU is maxed out, the site is slow and traffic has not changed. How to spot a foreign process.
A single file that gives an attacker the same access as your developer. How to find it.
Reinfection almost always means the cleanup was done without an investigation.
Four instinctive actions that look sensible but destroy the data an investigation needs.
Who must report, within what deadlines and what information you will need. A practical checklist.
We check it externally and send a report with the concrete findings.