Hub

Website security, end to end

Start with the pillar closest to your stack, then follow the cluster into detection, removal and hardening.

Website security work splits into two very different jobs, and confusing them is the most common reason a cleanup fails. The first job is incident response: something already has write access to your site, and the priority is evidence, persistence removal, content cleanup and credential rotation, in that order. The second job is hardening: reducing what the next attempt can reach.

The pillars below are organised by stack and by business type, because the entry points differ. A WordPress site is usually compromised through an out-of-date extension or a reused administrator password; an e-commerce platform adds payment-page skimming and stricter reporting obligations; a small business site is most often hit opportunistically by automated scanning rather than targeted attack.

What this section covers

  • Confirming whether a site is actually compromised, using search-side, content-side and redirect evidence.
  • Removing injected spam, hidden links and conditional redirects without breaking templates.
  • Closing entry points: patching, least-privilege CMS roles, MFA on registrar and hosting accounts.
  • Recovering search visibility after a hacked-content manual action.
  • Hardening that limits blast radius, including security headers and backup verification.
  • Website Securityintermediate

    SEO Spam: The Complete Picture

    The pillar page for injected search spam: the attack family, how the variants relate, and the detection and remediation path shared by all of them.

    Updated 28 Aug 2026 · 2 min read

  • Website Securitybeginner

    WordPress Security

    WordPress compromises concentrate in plugins, credentials and writable directories. What to fix, in the order that removes the most risk.

    Updated 26 Aug 2026 · 2 min read

  • Website Securityintermediate

    E-commerce Website Security

    Online stores face a specific threat set: payment-page skimmers, third-party script risk, and account abuse. What to monitor and why.

    Updated 25 Aug 2026 · 2 min read

  • Website Securitybeginner

    Small Business Website Security

    No security team, no budget line, real risk. The five controls worth your limited time, and the two questions to ask your web supplier.

    Updated 25 Aug 2026 · 3 min read

Topic cluster

SEO spam and search-visible compromise

How injected spam gets onto a site, how to confirm it, how to remove it and how to recover search visibility.

Topic cluster

Hardening and prevention

The controls that stop a repeat compromise once a site is clean.

Topic cluster

Security careers and learning

Role-by-role expectations, the skills each one screens for, and free ways to build them.