Blog

Notes from inside hacked WordPress sites.

Threat research, walkthroughs of real-world WordPress compromises (anonymised), plain-English explainers for site owners, and field notes from the RedSecLabs team. New posts roughly fortnightly.

AI wordpress security plugin
Blog / 10 min read / July 2026

AI WordPress Security Plugin: How LLM Detection Catches What Rules Miss (2026)

Every WordPress security plugin before 2024 worked the same way: maintain a database of known malware signatures, compare your files against it,…

gazeblogadmin
Blog / 8 min read

Wordfence Review 2026: What It Gets Right, What It Misses, and When to Use It

Wordfence is the leading free WordPress security plugin, but its in-process scanner has limitations that modern malware can exploit. Here's…

gazeblogadmin · July 2026
Blog / 14 min read

WordPress Hacked? How to Fix, Clean and Recover Your Site (2026)

Think your WordPress site has been hacked? Learn how to confirm the infection, clean every compromised file and database entry,…

gazeblogadmin · July 2026
Blog / 14 min read

WordPress Casino Spam: Detection, Removal & Prevention (2026 Guide)

WordPress casino spam is a black-hat SEO infection that injects gambling, betting, and “free spins” content into your site but…

gazeblogadmin · July 2026
Blog / 6 min read

How to Scan Your WordPress Website for Malware Using Guardian Gaze

In this guide, we'll show you how to scan WordPress for malware using the free Guardian Gaze plugin and explain…

gazeblogadmin · July 2026
Blog / 16 min read

How to Do a WordPress Security Audit (Step-by-Step for Site Owners)

Learn how to perform a complete WordPress security audit with this step-by-step guide. Check for vulnerabilities and keep your WordPress…

gazeblogadmin · June 2026
Blog / 13 min read

Abandoned & Nulled WordPress Plugins: A Critical Security Risk

Two of the most common entry points for WordPress compromises aren’t exotic zero-days or sophisticated attacks. They’re plugins that stopped…

gazeblogadmin · June 2026
Blog / 19 min read

WordPress Brute Force Attack Prevention: The Complete 2026 Guide

A WordPress brute force attack is an automated attempt to log into your site by guessing username and password combinations…

gazeblogadmin · May 2026
Blog / 17 min read

How to Fix the “This Site May Be Hacked” Warning in Google Search Results (2026)

If Google is showing “This site may be hacked” under your search result, Google has detected spam, malware, or unauthorized…

gazeblogadmin · May 2026
Blog / 17 min read

WordPress Japanese SEO Spam Hack: Detection, Removal & Prevention (2026)

The Japanese SEO spam hack (also called the Japanese keyword hack) injects thousands of auto-generated Japanese-language pages into your WordPress…

gazeblogadmin · May 2026

Get new posts in your inbox.

One email per post. Threat walkthroughs, agency playbooks, and product updates. Unsubscribe anytime.

Subscribe →