Guides from real jobs.

Short and specific. Each one comes from a site we actually worked on or a question we get asked: what we saw, what it meant, and the order we fixed it in.

Hacked WordPress: the cleanup order that holds

Most hacked sites get cleaned twice. The first time removes what you can see. Here is the full order we use so the second time is never needed: contain, find the door, clean, rotate, patch, watch.

Secure4 min readSeptember 2026

Is my website hacked? Twelve signs, and a five-minute check

Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.

Secure3 min readSeptember 2026

Deceptive site ahead: what it means and the fix order

Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.

Secure4 min readSeptember 2026

Security headers, explained by what our scanner sees

Five short lines in your server response stop most clickjacking, script injection and downgrade attacks. Most sites we scan send none of them. Here is what each one does, in plain terms, and how to add them on Apache, Nginx and Cloudflare.

Secure3 min readSeptember 2026

Website redirecting to another site: the malware and the fix

Your site sends visitors to a spam page, a fake update or a gambling site, but it looks fine when you open it. That is a redirect hack, and it hides on purpose. Here is where the code lives, how to see it, and the order to remove it in.

Secure3 min readSeptember 2026

WordPress security: the ten settings that stop most attacks

Most WordPress break-ins are not clever. They walk through the same few open doors. Here are the ten settings that close them, in the order they matter, with what each one takes and what it stops.

Secure3 min readSeptember 2026

Website malware removal: what a proper cleanup includes and costs

Malware removal is sold at every price from fifty to five thousand, and the cheap version is often a scan and a delete. Here is what a proper cleanup includes, step by step, how long it takes, what drives the cost, and what should come with it.

Secure3 min readSeptember 2026

Japanese keyword hack: why Google shows Japanese text under your site

Your search results show Japanese titles for pages selling watches or handbags you have never heard of. That is a specific, common hack with a specific fix. Here is what it does, the one step most cleanups miss, and how to get the results out of Google.

Secure3 min readSeptember 2026

'Not secure' warning or expired SSL certificate: the fix

A browser warning next to your name costs you visitors within minutes, and it is nearly always one of four things. Here is what each warning means, how to tell which one you have, and the fix, which is usually free and takes under an hour.

Secure3 min readSeptember 2026

Website firewall: what a WAF blocks, and Cloudflare versus plugins

A web application firewall is the single most useful thing you can put in front of a site, and most sites have none. Here is what a WAF actually does, the real difference between an edge firewall and a plugin, and the setup we use.

Secure3 min readSeptember 2026

Contact form spam, and a website that sends spam: stopping both

Two problems share the word spam. Your form fills your inbox with junk, or your server is sending junk to other people and your real email is bouncing. One is a nuisance, the other is a security incident. Here is how to tell them apart and fix each one.

Secure3 min readSeptember 2026

Securing a Node.js or Laravel app: the checks we run before launch

Custom applications get hacked through a different set of doors than WordPress: debug pages, leaked environment files, unpatched packages, missing rate limits. Here is the list we run through before any Node.js or Laravel app goes live.

Secure3 min readSeptember 2026

Outdated plugins: how attackers find your site, and the fix

A vulnerability in a popular plugin gets published, and within days scripts are testing every site on the internet for it. Yours included. Here is how that works, how to know which of your plugins are exposed, and a monthly routine that takes an hour.

Secure3 min readSeptember 2026

Not sure where your site stands?

Paste the address. Security, speed, SEO and how old the tech is, in about ten seconds.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.