Access Lebanon
A compromised WordPress site replaced with a hand-built static site: forensic audit, spam-URL removal, 410 rules, and a faster, harder-to-break codebase.

Overview
An ISP’s WordPress site was quietly publishing casino and software-download spam through injected posts. Black audited the live site, documented the compromise, and moved the site off WordPress entirely: a static Astro codebase with the same content, a contact endpoint, clean sitemap and robots, and 410 rules for every poisoned URL.
Challenge
Search results already showed the spam pages. Credentials had to be treated as exposed. The client needed the site back to a trustworthy state without losing legitimate pages or rankings.
Approach
Read-only audit first (sitemap crawl, REST and XML-RPC checks, headers, Lighthouse), a written report with evidence, then a static rebuild: home, about, three service pages, policies, a PHP contact handler, .htaccess with redirects and 410s, and a cutover checklist with full backups and a rollback path.




02 · technology
Deliverables
Site audit report · spam URL inventory with evidence · static Astro build with optimised assets · contact endpoint · .htaccess redirects and 410 Gone rules for compromised paths and WordPress attack surfaces · clean robots and sitemap · Lighthouse mobile and desktop reports before and after · cutover and rollback checklist.



