Joshua David Plumbing — Repeat Reinfection Stopped at the Source
WordPress Security & Error Fixing

Joshua David Plumbing — Repeat Reinfection Stopped at the Source

A WooCommerce plumbing site was trapped in a hack-clean-hack loop. We found the hidden database trigger quietly rebuilding the attacker’s admin, removed the whole multi-layer infection, and shut the door for good.

Reinfection loop broken · verified clean & hardened

928
Hidden spam pages removed
1
Reinfection trigger killed
0
Rogue admins remaining
Clean
Verified & hardened

Plumbing · WooCommerce · Australia · Full forensic scan & hardening · 2026

Joshua David Plumbing — Repeat Reinfection Stopped at the Source Page 1 / 3
Report page 1
Full case study report
PDF · Free download
1

The problem

Joshua David Plumbing was infected with a casino/gambling SEO-spam and cloaking campaign — it hijacked the site's Google rankings, showing spam pages to search engines while hiding them from the owner. Worse, it kept coming back within days of every cleanup. The attacker had buried multiple independent backdoors across both the website files and the database, including a hidden administrator account that silently reappeared each time it was deleted. Earlier fixes had only treated the surface, so the business was stuck in a costly loop of getting hacked, cleaned, and hacked again.

2

What we did

  • Ran a complete forensic scan of the entire website file system and database — not just a surface plugin scan.
  • Identified and mapped every backdoor: a webshell hidden in the theme, staged PHP-execution consoles, fake "plugin" folders, and a database-resident spam engine.
  • Uncovered the true cause of reinfection — a hidden MySQL trigger that automatically recreated the attacker's admin account whenever a specific blog comment was posted.
  • Traced the timeline back to patient zero (31 March 2026) and pinpointed the likely entry point: an outdated, vulnerable import plugin.
  • Removed all malware from both files and database, then dropped the hidden reinfection trigger and its detonator comments.
  • Independently re-scanned the cleaned database exports to confirm zero remaining threats — SHOW TRIGGERS returned an empty set.
  • Rotated all credentials, locked the database user down to least privilege, and installed a custom must-use security layer built to detect and block the exact techniques used against the site.
3

The result

The reinfection cycle is broken. The site is fully clean and verified — no malware, no rogue admins, and the hidden database backdoor permanently removed. Instead of another temporary patch, Get Shielded left the site with active tripwires that instantly block any unauthorized admin, watch for new backdoors and database triggers, and email the owner the moment anything suspicious appears — turning a site that was repeatedly compromised into a monitored, hardened, and protected one.

Want results like this?

Tell us what your website needs. We’ll handle the rest — no jargon, no hidden fees.

UK Registered Company · No contracts · Cancel anytime · Response within 4 hours

Chat on WhatsApp