Skip to main content
Case Study

BM Mobil: Taking Over and Hardening a Corporate WordPress Site

We took over a corporate WordPress site after a security incident: regained control safely, audited it for backdoors, closed the common entry points and handed the business a ranked upgrade plan.

BM Mobil bmmobil.com
BM Mobil: Taking Over and Hardening a Corporate WordPress Site

The challenge

A site that needed a safe pair of hands

BM Mobil sells and installs vehicle tracking, fleet management and in-vehicle camera systems across Turkey. After a security incident on its bilingual corporate WordPress site, and with the original agency no longer involved, it needed someone to take the site over and make it trustworthy again.

Inherited components, restricted access

The site ran on a commercial theme and page builder set up by the previous agency, had been migrated file by file from an older server, and sits inside the client's own network, reachable only over VPN.

Our approach

Regain control safely

We connected through the client's VPN and hosting panel and reset administrator credentials directly in the database, so control did not depend on any channel that might itself be compromised.

Audit before changing anything

We checked the uploads directory, must-use plugins and plugin code for injected files, and reviewed every plugin that contacted third-party servers before deciding what stayed active.

Close the common entry points

We applied the standard WordPress hardening set at both the web-server and application level, removed files that leaked server details, and added a security plugin for monitoring.

Rank what is left

Instead of a risky blind upgrade, we ranked the remaining work by risk and planned safe upgrade paths, leaving licensing and infrastructure decisions with the client.

BM Mobil screen 1
BM Mobil screen 2

How we delivered

  1. 1

    Regain access

    Audit

    Connected over the client's VPN and hosting panel and reset admin credentials directly in the database.

    VPN access Credential reset Panel access
  2. 2

    Backdoor audit

    Audit

    Scanned uploads, must-use plugins and plugin code for injected files and reviewed plugins that contact third-party servers.

    Uploads mu-plugins Plugin review
  3. 3

    Cleanup

    Cleanup

    Removed files that leaked server details and deactivated plugins that were not needed.

    Leaky files Unused plugins
  4. 4

    Hardening

    Hardening

    Applied server- and application-level hardening and added security monitoring.

    Server rules WordPress config Monitoring
  5. 5

    Risk roadmap

    Operations

    Ranked the remaining risks and planned safe upgrade paths.

    Risk ranking Upgrade plan

Results

0
Backdoor files found in the post-takeover audit
4
Hardening steps applied (server & application)

A clean baseline

The post-takeover audit found no backdoors, and the site kept running normally throughout the cleanup.

Common attack paths closed

The usual WordPress entry points are closed, and a file uploaded through the media library cannot be executed.

A clear roadmap

The client has a ranked, costed list of the remaining upgrades instead of an open-ended worry.

Have something to build — or something that is stuck?

Tell us what you are working on. You will talk to an engineer, not a salesperson.

Before you go — have a system that's stuck, or needs AI?

We build what's missing, put AI where it earns its place, and keep it running.