14+ years building on WordPress / Replies in under 5 hours
Rescue

Hacked membership site cleaned, hardened and back online the same day

A UK membership site was compromised and suspended by its host, locking out paying members. Restoring the backup would have put the backdoor straight back.

6h
to service restored
first contact to site back online
3
backdoors removed
filesystem diff vs. clean core + plugin baselines
1,847
member records verified intact
row count and spot-check vs. pre-incident backup
14 days
monitored, no reinfection
daily malware scans post-restore

Representative engagement. The client's identity is withheld under NDA, and the figures shown illustrate typical outcomes for this type of incident response rather than one client's audited results. The methodology described below is exactly what I run on real projects.

Client
Membership site
Identity withheld under NDA
Industry
Membership / online community
Services
Bug fixes & rescue
Timeline
Same day, plus 14 days monitoring
In short

A compromised membership site was taken offline, forensically copied, then diffed against clean WordPress core and known-good plugin versions. Three backdoors were removed — two in an uploads directory a backup restore would have preserved — the entry-point vulnerability was patched, every credential rotated, and service restored in six hours.

The challenge

Malware had compromised the site badly enough that the host suspended it, which meant paying members couldn't log in and recurring revenue was actively at risk with every hour of downtime. The client's first instinct — understandably — was to restore last week's backup and get back online immediately. That would almost certainly have reinfected the site, because the vulnerability that let the attacker in was present in that backup too, and as it turned out so was one of the backdoors. The pressure to rush is the single most dangerous thing about incident response.

Starting point

State at first contact: site suspended by host, 1,847 active member accounts inaccessible, membership plugin running a version with a publicly disclosed unauthenticated file-upload vulnerability, no filesystem integrity monitoring in place, and admin credentials shared across three people.

Abstract graphic of a clean hexagon outline, representing a site restored and hardened

The approach

The instinct after a hack is to restore a backup and move on. That is precisely how sites get reinfected within a week — the backup usually contains the same vulnerability, and often the same backdoor. Cleanup has to be evidence-led or you're just resetting the clock for the attacker.

Took the site offline behind a maintenance page immediately, rather than leaving a compromised site serving malware to members
Pulled a full forensic copy before touching anything, so evidence of the entry point survived the cleanup and the attack could actually be understood
Diffed the entire filesystem against clean WordPress core and known-good plugin versions — this found three backdoors, two of them sitting in an uploads directory that no backup restore would have cleaned
Traced entry to an outdated membership plugin with a known unauthenticated file-upload vulnerability, then patched and hardened before bringing anything back online
Rotated every credential — database, all admin users, API keys and WordPress salts — on the basis that assuming the attacker had them was far safer than assuming they hadn't
Restored content from a verified pre-incident backup, confirmed member data against expected row counts, then ran daily scans for two weeks to catch any persistence mechanism that had been missed

The results

Service was restored within six hours and members were back in the same working day. Verification against the pre-incident backup confirmed all 1,847 member records intact. The part worth highlighting is what the filesystem diff caught: two of the three backdoors were in an uploads directory, exactly where a straight backup restore would have preserved them. That is the usual reason 'cleaned' sites get reinfected a fortnight later, and it's why the diff step isn't optional.

What this didn't cover

This was incident response, not a security retainer — monitoring was configured but ongoing management is billed separately. I gave no advice on GDPR breach-notification obligations; the client took that to their own legal counsel, which is where it belongs and where I'd always send it. Payment card data was never in scope because the site used a hosted gateway, so no cardholder data was exposed to the compromised environment. The membership plugin was patched rather than replaced, so the underlying vendor risk remains and is worth revisiting. I also can't prove no data was exfiltrated — nobody honestly can after the fact; what I can confirm is what was verified intact and what was removed.

Services used on this project

Want the same for your site? Start here:

WordPress bug fixes & site rescue, often the same day WordPress maintenance & care plans that keep you online

Common questions

Usually the same day for a site of this size. But speed is a secondary goal — the important thing is that it comes back clean. A site restored in an hour that gets reinfected next week has cost you more than one that took six hours and stayed clean.

Rarely, provided a pre-incident backup exists. Data gets verified against expected record counts before the site goes back up, so you get a specific confirmation rather than a reassurance. Where I'm always straight with clients: nobody can prove after the fact that nothing was copied. I can tell you what was verified intact and what was removed.

Because the entry point gets identified and closed, not just the symptoms cleaned. If a cleanup doesn't tell you how the attacker got in, it isn't finished. Beyond that: credentials rotated, filesystem monitoring in place, and updates actually applied on a schedule — most reinfections trace back to an unpatched plugin nobody owned.

Verified reviews

What clients say on Google

These are general reviews of working with me, not comments on this specific project.

★★★★★

“Fantastic Developer. Very knowledgeable. Very patient. Works extremely hard. Very good English Skills. Good communication skills. Takes the time to understand the project scope and the minor details in your project. I am very impressed.”

SB
Silvia B
Google Reviews
★★★★★

“Great developers! All the team are professionally, it's a pleasure work with them :). I, sincerely, recommend it.”

LB
Laura Ballart
Google Reviews
★★★★★

“Worked with them in several projects. They are always good and responsive. More projects will be coming.”

AD
Anatano dev
Google Reviews

Want results like these?

Send me your site and goals — I'll tell you exactly what's worth doing.

Start a conversation