Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Resources

Guides to WordPress security incidents

Find practical guidance for compromised WordPress sites, from immediate actions and malware persistence to data-exfiltration assessment, recovery, and hardening. Every article states its sources and the limits of the described assessment.

Foundations & incident playbooks

Guides for active incidents and recovery

These guides explain immediate actions, assessment, cleanup, and hardening in context.

Guide

AI-enabled hacking and WordPress: real risks, limits and practical protection

How attackers use AI for phishing, vulnerability research and automation, what that changes for WordPress, and which security controls matter now.

Guide

WordPress WAF plugins compared: benefits, limits and suitable use cases

Compare Wordfence, NinjaFirewall, Sucuri, MalCare, Patchstack, AIOS, Shield Security and BBQ Firewall by architecture, strengths and limitations.

Guide

Can data exfiltration be established after a WordPress hack?

Which technical traces may support or challenge a data-exfiltration hypothesis, and why missing logs cannot provide absolute reassurance.

Guide

Hacked WordPress site: safe first steps in the first 60 minutes

What actually helps in the first 60 minutes after a WordPress hack — and what puts evidence and recovery at risk.

Guide

WordPress hardening checklist after a security incident

Prioritized hardening for WordPress, hosting, accounts, backups, and monitoring after controlled remediation.

Guide

Webshells, backdoors, and SEO spam: understanding WordPress persistence

How webshells, backdoors, SEO spam, and persistence differ, and why one detected file rarely explains the entire incident.

Focused answers

Technical findings and tools

These articles cover individual traces, diagnostic tools, and the appropriate next steps.

Technical answer

Why deleting an infected WordPress plugin is not enough

Why a compromised plugin may be only the entry point or one finding, and which persistence areas still require review.

Technical answer

Which logs to preserve after a WordPress incident

Prioritized log sources, safe preservation, and reconstruction limits after a WordPress security incident.

Technical answer

Malware scan versus forensic investigation

What malware scanning can provide, when incident analysis must go deeper, and where formal forensics begins.

Technical answer

Why an old WordPress backup may already be compromised

How to assess backup timelines and contents before using a backup as a recovery source.

Technical answer

Rotating WordPress secrets, salts, sessions, and API credentials

A controlled order for passwords, sessions, salts, application passwords, and external API secrets.

Technical answer

Investigating unknown WordPress administrators and application passwords

How to preserve, assess, and revoke unknown accounts, sessions, and application passwords.

Technical answer

WordPress checksums: what they prove and what they do not

How WordPress core checksums are used and why a successful comparison does not cover the database, uploads, or accounts.

Technical answer

Finding malware in WordPress uploads, cache, and backups

Why writable directories need special attention and how executable malware is distinguished from legitimate files.