A theme move in 2024, then a full security clean-up when the agency came back in 2026.
Online shop · DE · 2024–2026
A German WooCommerce shop: theme migration and hack clean-up
I moved a small shop off an abandoned theme to Flatsome. Two years later I found a hack hidden since 2019 and cleaned it out with the catalogue intact.
Hidden in the shop since about 2019, while the real product categories stayed intact.
A small German online shop on WooCommerce. I worked on it through a German web agency in 2024 and again in 2026.
The first job moved the shop off a theme its author had abandoned, to Flatsome. Two years later a question about failing card payments led me to an audit, and I found the shop had been hacked since about 2019: more than 24,000 spam categories, hundreds of spam posts and a backdoor admin account in the database. I cleaned all of it out, and the real product categories stayed intact. Every account deletion was confirmed first, and the owner got a plain report of how the attack happened.
Projects
- 2024
WooCommerce theme migration to Flatsome
I moved a WooCommerce shop from a bought theme, unsupported since 2020 and known to break, to Flatsome without a rebuild.
The agency first asked about repairing the old theme. I looked at it and advised against a repair, since every WordPress or PHP update would break it again, and recommended a supported theme. Before agreeing to the agency’s scope I checked the job against Flatsome’s documentation, and told the agency in advance that the shop would look different.
For the switch I commented out old-theme code that blocked the Themes screen and plugin uploads. I installed and licensed Flatsome on the live domain, moved the live shop to it and then made a local copy. Then I set the newest products to show first by default and put the existing logo in the header.
The shop moved to a theme that gets updates. In September 2026 it was on Flatsome, and its categories showed the newest products first.
Stack: WordPress, WooCommerce, Flatsome, PHP
- 2026Came back after two years
Hacked WooCommerce shop: black-hat SEO clean-up
I audited and cleaned a shop hacked for black-hat SEO. It had casino and essay-writing spam, hidden casino text in real product descriptions, a backdoor admin account and a home-page redirect to a look-alike domain.
Before any change I took a backup and made a local copy. I checked the files for backdoors (uploads, obfuscated code, theme and plugin files, .htaccess) and they were clean, so the attack lived in the database only.
I cleaned the database one kind of junk at a time and checked each step with a row count and a control query: spam pages, hundreds of spam posts, more than 24,000 spam categories and orphaned meta rows. Before the big delete I verified that the real product categories were untouched. Then I cut the hidden casino blocks out of the product descriptions and the Shop page, and removed the redirect.
I ranked the user accounts by risk and deleted them only after confirmation. Among them were a recently created backdoor admin and an old account that had been injecting content for years.
I traced the payment failures from both ends, with a local test through the payment SDK and the logs of a real failed order. The cause was a merchant account the bank had not activated yet. I set up Apple Pay and Google Pay and kept them switched off, so customers see no buttons that fail.
For the owner I wrote a plain report: how and when the attackers got in, what it means for the business, and a short list of hardening steps.
In September 2026 the live shop showed only its real product categories, no spam categories, no spam posts and no casino text in pages or posts.
Stack: WordPress, WooCommerce, MySQL, PHP
A cosmetics shop rebuilt from scratch after the old one went dark
The brand's hosted store went offline. I rebuilt the shop on WooCommerce with a German-law checkout and brought back its old links and reviews.
WordPress support for a German timber merchant's site
Two support cases on a timber merchant's WordPress site. I traced an admin hang on a copy, reopened a locked admin and measured why updates kept failing.
EU VAT rules, PDF invoices and free shipping for a WooCommerce shop
Business buyers from other EU countries now see the right tax note at checkout and on the invoice, and my custom work survives theme updates.
Contact
Have something similar?
Use the form or message me on LinkedIn.
Already working with me on Upwork? Write there.