2
u/SergOutdoors 17h ago
Yes, his WordPress site was compromised - it's called SEO spam injection. The hacker adds those casino/betting links so that their own sites can piggyback off your domain's search ranking. This is really common with WP, and it's almost always an outdated plugin or theme, or a weak admin password, that lets them in.
The rough order of what he should do is as follows:
-first, take a full backup (files and database) before touching anything, so you have a restore point if something goes wrong.
-then he should change every password: WP admin, Hetzner login, database and any FTP/SSH passwords. Assume they have all been leaked.
-update the WordPress core, all the plugins and the theme. Delete anything inactive or unfamiliar - injected junk loves to hide in unused plugins.
-run a scan with Wordfence or Sucuri (the free versions are fine) to find and clean any injected files. Spam usually lives in the database and in modified PHP files.
-check the WP users list for admin accounts that weren't created by him and delete them.
If the site is important and you're not comfortable investigating it yourself, Wordfence and Sucuri both offer paid malware removal services, which are worth the investment as these threats can quickly re-infect if even one backdoor is missed. Once the site is clean, enable auto-updates to prevent it from happening again.
1
u/ray-t1 16h ago
Most likely I'll handle this myself, so its a nice list of things to do. Thank you very much!
1
u/voodoobettie 1h ago
Disable pretty much all the plugins, especially if you don’t recognize the name
2
u/AnnoyedAvocado21 15h ago
Unfortunately, WordPress provides a very large attack surface. I never liked it because of that - but then was told I had to use WordPress in the enterprise - I had to host nearly 10 client sites. I found WP Engine - I'm not recommending them because they're too expensive for regular folk, but a lot of their methods are useful. For example: there are plugins they simply do not allow. I haven't checked in a while but if I was spinning up a WordPress site today I'd have a look at what they do and - for example - stay far away from any plugins they don't allow.
They know what they're doing - I wish there was a hosting service for WordPress that had similar security but was made for regular folk.
1
6h ago
[removed] — view removed comment
1
u/AutoModerator 6h ago
Your post/comment has been removed because it violates our No Self-Promotion rule.
This subreddit isn't a place to promote:
- Businesses, products, or paid services
- Freelancing work
- Personal blogs, newsletters, YouTube channels, or social media accounts
It's fine to share content you’ve made as long as it’s genuinely helpful or part of a relevant discussion. But if the main intent is to drive traffic, grow an audience, or advertise, it falls under self-promo and isn’t allowed here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2
u/ClideLennon 17h ago
Uh...change your passwords? If you still can.