Threat research, walkthroughs of real-world WordPress compromises (anonymised), plain-English explainers for site owners, and field notes from the RedSecLabs team. New posts roughly fortnightly.
WordPress casino spam is a black-hat SEO infection that injects gambling, betting, and “free spins” content into your site but only shows…
In this guide, we'll show you how to scan WordPress for malware using the free Guardian Gaze plugin and explain…
Learn how to perform a complete WordPress security audit with this step-by-step guide. Check for vulnerabilities and keep your WordPress…
Two of the most common entry points for WordPress compromises aren’t exotic zero-days or sophisticated attacks. They’re plugins that stopped…
A WordPress brute force attack is an automated attempt to log into your site by guessing username and password combinations…
If Google is showing “This site may be hacked” under your search result, Google has detected spam, malware, or unauthorized…
The Japanese SEO spam hack (also called the Japanese keyword hack) injects thousands of auto-generated Japanese-language pages into your WordPress…
A WordPress redirect hack sends your visitors to scam sites, fake pharmacies, sketchy ad networks, or malware downloads, usually only…
The WordPress pharma hack is a black-hat SEO infection that injects pharmaceutical spam (Viagra, Cialis, Tramadol, Phentermine) into your site,…
Discovering your WordPress hacked is one of the most stressful moments for any business owner, developer, or agency. Traffic drops…
One email per post. Threat walkthroughs, agency playbooks, and product updates. Unsubscribe anytime.