SerhiiNadolskyi
Hire me

Industrial components manufacturer · DE · 2025

A stranger's shop page hidden inside a product microsite

I traced a spam shop page on a manufacturer's microsite to a hidden auto-loaded file, and proved the fix on a local copy first.

With a certain parameter in the address, the manufacturer’s product microsite served a stranger’s shop page instead of its home page: a sneaker listing with prices, sizes and an Add to cart button. A classic spam injection, invisible at first glance.

I imported a production backup into a clean local site and left the live site alone. The spam page came up locally with the same parameter. I ruled out plugins and theme first: removing plugins and switching or updating the theme left the page in place, so the code loaded before the theme.

The malicious file sat in the folder WordPress runs automatically before any plugin or theme. I removed it through the file system, since deleting it from the admin would not be enough, and every address showed the real site again. For the agency I recorded each step on video and held the live change until it approved. When checked in September 2026, the live microsite showed its own home page for that address, both to a browser and to a request sent as Google’s crawler.

Contact

Have something similar?

Use the form or message me on LinkedIn.

Already working with me on Upwork? Write there.