Archive

Author: Farhan Memon

Threat research, walkthroughs, and security guides from the RedSecLabs team.

Blog/ 11 min read

WordPress Backdoor Detection: Plugin vs Server-Side Scanning

A backdoor is built to survive the obvious cleanup. This guide explains what local WordPress scanners, remote analysis, host-level tools…

Farhan Memon · August 2026
Blog/ 19 min read

WordPress Supply Chain Attack: Detecting Trojanised Plugins

How poisoned dependencies, compromised build pipelines and trusted plugin updates reach WordPress sites, what the 2026 incidents teach us, and…

Farhan Memon · August 2026
Blog/ 15 min read

WordPress SIEM Monitoring: Detect Rogue Admins and Backdoors with Guardian Gaze and Wazuh

Series Context Article 1 covers the incident-response case: multiple unauthorised administrators, wp2shell exposure analysis, backdoor checks and recovery. This article…

Farhan Memon · August 2026
Blog/ 10 min read

AI WordPress Security Plugin: How LLM Detection Catches What Rules Miss (2026)

Every WordPress security plugin before 2024 worked the same way: maintain a database of known malware signatures, compare your files…

Farhan Memon · July 2026
Blog/ 8 min read

Wordfence Review 2026: What It Gets Right, What It Misses, and When to Use It

Wordfence is the leading free WordPress security plugin, but its in-process scanner has limitations that modern malware can exploit. Here's…

Farhan Memon · July 2026
Blog/ 14 min read

WordPress Hacked? How to Fix, Clean and Recover Your Site (2026)

Think your WordPress site has been hacked? Learn how to confirm the infection, clean every compromised file and database entry,…

Farhan Memon · July 2026
Blog/ 14 min read

WordPress Casino Spam: Detection, Removal & Prevention (2026 Guide)

WordPress casino spam is a black-hat SEO infection that injects gambling, betting, and “free spins” content into your site but…

Farhan Memon · July 2026
Blog/ 16 min read

How to Do a WordPress Security Audit (Step-by-Step for Site Owners)

Learn how to perform a complete WordPress security audit with this step-by-step guide. Check for vulnerabilities and keep your WordPress…

Farhan Memon · June 2026
Blog/ 13 min read

Abandoned & Nulled WordPress Plugins: A Critical Security Risk

Two of the most common entry points for WordPress compromises aren’t exotic zero-days or sophisticated attacks. They’re plugins that stopped…

Farhan Memon · June 2026
Blog/ 19 min read

WordPress Brute Force Attack Prevention: The Complete 2026 Guide

A WordPress brute force attack is an automated attempt to log into your site by guessing username and password combinations…

Farhan Memon · May 2026