06/08/2026
"We changed the password. It got hacked again anyway."
That's how a lot of our WordPress security calls start.
A client came to us convinced their online store was cursed — hacked over and over, no matter how many passwords they changed. Turns out it wasn't a curse. It was a hidden backdoor that had nothing to do with their password in the first place, plus something sitting quietly on the live site that they hadn't even noticed yet.
We wrote up exactly what we found, how we found it, and what every WordPress site owner should take away from it 👇
https://www.apaxon.co.uk/blog/how-a-forgotten-plugin-nearly-cost-a-client-their-store-and-what-we-found-when-we-went-looking
How a compromised WordPress plugin led to a hidden backdoor and search-spam injection on a client's e-commerce site — and how Apaxon investigates, cleans up, and prevents it happening again.