Free chapter 01 · 22 pages
Is the WordPress Site Actually Hacked?
Separate a suspicious symptom from an ordinary fault, preserve useful evidence, and decide when a full incident response is justified.
Read Chapter 1 freeStop deleting whatever a scanner flags and hoping the infection is over.
Learn how to follow a real WordPress compromise across files, database rows, hidden users, cron jobs, hosting accounts, DNS, checkout pages, and reputation systems—including a complete SC 4.0.3 self-healing malware case—then prove the behavior cannot return.
Pay what you want · Minimum price
$9.99
$19.99 suggested
Choose your price at secure checkout · Instant PDF download
Please read the two free chapters before purchasing. Digital-product refunds are limited to the eligible reasons in the 7-day refund policy.
See what changed on September 4, 2026
Accessible pricing, complete edition
I want this practical reference to remain accessible to developers and site owners in different markets. Choose what works for you—the minimum changes the price, not what you receive.
Pay what you want
Minimum price
$9.99$19.99 suggested
Every amount unlocks the same complete PDF and future edition updates. Enter your preferred amount securely at checkout.
Get the complete book · Pay $9.99+Secure Lemon Squeezy checkout · Instant PDF download
Review the two free chapters before checkout. Limited 7-day refund policy.
Read before purchasing
No email address or payment is required. Read the investigation method in Chapter 1, then see how that knowledge can become carefully scoped professional work in Chapter 18.
Free chapter 01 · 22 pages
Separate a suspicious symptom from an ordinary fault, preserve useful evidence, and decide when a full incident response is justified.
Read Chapter 1 freeFree chapter 02 · 17 pages
Explore marketplace opportunities, an evidence-led Upwork proposal, portfolio strategy, safe service boundaries, and the limits of earnings claims.
Read the freelancing chapter freeWhere ordinary cleanup advice stops
The difficult incidents are not solved by one suspicious filename. They are solved by understanding what visitors saw, what stored the payload, what executed it, who still had access, and what could restore it.
A file was deleted or WordPress was reinstalled, but a cron job, backdoor, neighboring site, or retained account restores the compromise.
The redirect or fake page appears only on mobile, after a Google visit, on the first request, or during checkout—while the owner sees a normal site.
A report can identify useful files without finding the database payload, hidden administrator, loader, entry path, or mechanism that recreates them.
A loading homepage is not enough. The original trigger, affected layers, account access, checkout, warnings, and recurrence window need to be tested again.
Look inside
These are finished pages from the book—not decorative mockups. Open any page to inspect the typography, screenshots, captions, and technical depth.
Chapter 1
Compare trusted files, visible behavior, error evidence, and independent views before deleting anything.
Chapter 12
Follow the XOR-decoded host, bot filtering, checkout condition, and dynamically executed response.
Chapter 15
Read the loader, identify its hidden source, and remove the restoration chain—not only its visible destination.
Appendix A
Find official lookup and review destinations for high-use browser, search, and antivirus warning systems.
Cases you can reason through
Each case begins with what the owner or visitor actually experienced, follows the evidence across the relevant layers, and ends with a testable recovery conclusion.
Case 01
A customer used their card on the site and later noticed unusual activity. The investigation follows the fake form, database storage, obfuscated loader, WebSocket connection, and persistence.
Case 02
Eleven incident screenshots connect PHP startup, MU plugins, drop-ins, a theme implant, ZIP archives, database payloads, and browser persistence. The chapter shows how the samples were decoded without executing them.
Explore the focused case-study bookCase 03
The host report was a starting map—not proof of full scope. Every site, shared account layer, backdoor, access path, and reinfection source still had to be checked.
Case 04
The missing evidence was stored in WordPress content rows. Reinstalling core could never remove the database payload that selected visitors still received.
Inside all 18 chapters
The sequence follows the work of a real investigation: diagnose before changing evidence, clean every affected layer, and follow each visible symptom to its source. It then shows why malware returns, applies the method to the complete SC 4.0.3 case, and turns the verified recovery into a monitored baseline.
Start with two free chaptersProve the symptom, preserve evidence, understand likely access, and determine the full scope.
Repair files and database state, then inspect the hosting account, server behavior, and DNS.
Trace redirects, SEO spam, fake components, hidden users, skimmers, suspensions, and blacklist warnings from the visible symptom to its source.
Find what can recreate the compromise, work through a complete self-healing malware case, close retained access, and monitor the recovered site.
Present malware-removal skills honestly, find suitable opportunities, protect client systems, and keep learning through authorized practice.
Author
MD Pabel
Field experience, turned into a method
I wrote this because the difficult part of malware removal is rarely pressing Delete. It is deciding what the evidence proves, what else must be connected, what must be preserved, and when a recovery can be trusted.
The investigations use real screenshots and retained artifacts from client work, with domains and sensitive details removed. Where a scanner helped, the book shows how. Where it missed the backdoor or database payload, the book shows that too.
More about my workReader reviews on Leanpub
“This book is an excellent and highly practical resource for anyone seeking to understand, detect, and effectively remove malware from WordPress websites. What I particularly appreciate is its hands-on approach. The book goes beyond simply explaining the nature of malware and provides practical guidance on identifying infections, investigating compromised files, understanding common attack methods, and following the appropriate steps to clean, restore, and secure a WordPress website. A professional, practical, and worthwhile reference for WordPress security. Highly recommended for WordPress developers and site owners!”
“A practical and easy-to-follow guide for WordPress security. It provides clear steps for detecting, removing, and preventing malware. Highly recommended for WordPress developers and site owners.”
“This book stands out because it treats malware removal as a methodical investigation rather than just relying on automated scanners. The breakdown of real-case scenarios—like hidden admin accounts and database-level injections—is clear and actionable. Perfect for freelancers, developers, and agency owners who want to resolve complex site infections permanently. Five stars!”
Choose your storefront
Direct purchase gives you the simplest checkout and later downloads through My Library. Leanpub and Gumroad remain available as marketplace alternatives.
New editions and field notes
Join for substantial chapter improvements, new preview material, and selected malware case notes—not a daily marketing sequence.
Thank you. Both complete free chapters are available above without signing up.
Questions, answered
Yes. Choose what you pay from a $9.99 minimum, with $19.99 suggested. Every purchase includes the complete 293-page expanded first edition, 18 chapters, 86 real screenshots and figures, an introduction, a conclusion, a website-reputation review appendix, and future edition updates.
It is written for WordPress developers, freelancers, agency teams, maintenance providers, technical site owners, and support professionals responsible for investigating or recovering hacked WordPress websites.
No. The code examples are explained from behavior and evidence. You should be comfortable with WordPress, hosting files, databases, and basic browser developer tools, but you do not need reverse-engineering experience.
No. Scanners are treated as evidence sources, not final conclusions. The book teaches how to connect symptoms to files, database rows, accounts, scheduled tasks, server state, DNS, and persistence.
Yes. You can download the complete opening chapter and Freelancing with WordPress Malware Removal without providing an email address or payment.
Yes. Open My Library and enter the email address used at checkout. Lemon Squeezy will email you a secure sign-in link, where you can download the current edition and view your receipt.
Because this is a digital book, purchases are generally non-refundable after access. Eligible duplicate-purchase, unresolved-access, or material-misrepresentation requests may be submitted within 7 calendar days. Please read the free chapters before purchasing.