WordPress malware, taken apart.
Field notes from real cleanups: how infections hide, how to spot them on your own site, and how to get back online when the worst happens.
The Fake Plugin in Your wp-content: A Field Guide
Attackers love disguising backdoors as WordPress plugins: a plausible folder name buys them months of persistence. Here are the five structural tells we see in real cleanups, and a five-minute check you can run on your own site.
Read the guide →Obfuscated JavaScript on Your Site: Malware, or Marketing Code From 2009?
The most common "obfuscated malware" finding on older sites isn't malware at all. Why legitimate code from the 2000s looks guilty, how to decode it safely, and the four checks that separate relics from real threats.
Read the guide →My WordPress Site Redirects Visitors to Spam: The Complete Rescue Path
Visitors get bounced to casino or pharmacy pages, but the site looks fine to you. How cloaked redirect malware works, every place it hides, and the complete path to getting clean.
Read the guide →Your Host Suspended Your Site for Malware: How to Get Back Online
What the suspension notice actually tells you, the three questions to ask your host, how to remove the infection for real, and how to get reinstated fast, without a second suspension.
Read the guide →Where to Find Your FTP or SFTP Details on Any Host
What the four credential fields mean and exactly where they live on cPanel hosts, Hostinger, GoDaddy, SiteGround, Kinsta, WP Engine, and more, plus the two-minute fallback when nothing works.
Read the guide →