Security monitoring
Regular integrity checks on files and the database, detection of injections and conditional redirects. If something shows up, you're the one who's notified — not your customers.
WordPress hosting & maintenance — Quebec
Most WordPress infections stay invisible to the site owner. They switch off while you're logged in, then target your visitors. I detect them, I remove them, and I make sure they don't come back.
No access required · Report within 48 h · No commitment
A service by Roberto Mas — 27+ years of web experience
Real case — July 2026
Malicious code installs itself across a fleet of WordPress sites. It intercepts every page, disables the browser's protections and shows a fake "Prove you're human" check that tricks the visitor into running a command on their own computer.
Its trick: it erases itself for logged-in administrators and for their IP addresses. The owners saw a perfectly normal site. Neither the host nor the installed security plugin raised the alarm.
A cross-checked external scan: cached page against fresh page, and a search for the markers the code leaves behind precisely by hiding.
Malicious code quarantined, database traces purged, every stolen session invalidated. Nothing permanently deleted: everything stays recoverable.
Point of entry identified with evidence, and proven by elimination across the whole fleet. Skip this step and reinfection is inevitable.
Another case — summer 2026
A partner inherits a set of WordPress sites hosted for years on the same VPS account with a North American host. Everything runs slow, without anyone knowing why. A manual check reveals that 35 of the 57 sites have been compromised, with around 70 malicious PHP files per site, and 7,813 .htaccess files injected across the account.
This isn't a simple hack, it's an occupation. The attacker had installed several families of backdoors in parallel: ALFA webshell, polyglot PDF/PHP files, a fake "WP Super Cache" plugin, index.php bloated to 450 KB on some sites, and a ghost administrator account (boss@gmail.com) discreetly created on one of the sites. The commercial antivirus installed on the server had raised no alert.
The persistence technique was particularly nasty: instead of deleting, the attacker renamed. The real wp-content became wp-content__caaa583, replaced by a copy full of backdoors. Folders with randomly generated names (qqqqqqq, rrrrrrrr, eeeeeeeee) were dropped everywhere. And the .php entry files of legitimate plugins were deleted, so that any future cleanup would "break" the sites visually and discourage the operation.
Most likely point of entry: a pirated version of a paid WordPress plugin, downloaded from an unofficial site instead of the vendor. Inside the archive, PHP code hidden in files disguised as videos (.m4v, .fla) — a place classic security scans don't look.
The only clean way out was to leave the account entirely. Staying on the original VPS meant keeping the attacker in the house.
The 57 sites listed, scanned file by file, compared against official WordPress versions. Every backdoor quarantined, not deleted, so everything remained recoverable if a real file had been touched.
WordPress files replaced with fresh official versions, plugins reinstalled from wp.org (the originals having been deliberately mutilated), database audited, ghost administrator account deleted.
Each site redeployed on a clean host, with DNS coordinated to avoid any visible downtime. The old VPS was left behind: recovering it would have required a full OS reinstall.
Each site validated one by one, with a list of rebuilt files. One site lost 155 images with no pre-hack backup, uploaded manually. The rest, fully recovered. Operation spread over twelve weeks.
What I take care of
Three areas, designed so you never have to think about them again.
Regular integrity checks on files and the database, detection of injections and conditional redirects. If something shows up, you're the one who's notified — not your customers.
Core, plugins and theme kept up to date, with a backup taken first and verification afterward. An update that breaks the site is an incident, not a fact of life.
Regular copies kept off the server, and above all: tested restores. A backup you've never restored isn't a backup.
Pricing
Prices in Canadian dollars. Cancel anytime.
For a site that simply needs to stay online, fast and secure.
or $180 per year
For a business whose site works every day.
or $420 per year — 2 months free
So you never have to touch your site yourself again.
hosting included
Emergency intervention: diagnosis, full cleanup, access rotation and point-of-entry search. Free estimate over the phone.
Also available: .com/.net domains $25/yr, .ca $30/yr · Professional email from $12/yr · Migration from your current host
Prices in Canadian dollars, taxes extra.
FAQ
Free audit
Give me your site's address. Within 48 h you get a plain-language report: what's fine, what's not, and what's urgent. No access requested, no commitment.