BM Mobil: Taking Over and Hardening a Corporate WordPress Site
We took over a corporate WordPress site after a security incident: regained control safely, audited it for backdoors, closed the common entry points and handed the business a ranked upgrade plan.
The challenge
A site that needed a safe pair of hands
BM Mobil sells and installs vehicle tracking, fleet management and in-vehicle camera systems across Turkey. After a security incident on its bilingual corporate WordPress site, and with the original agency no longer involved, it needed someone to take the site over and make it trustworthy again.
Inherited components, restricted access
The site ran on a commercial theme and page builder set up by the previous agency, had been migrated file by file from an older server, and sits inside the client's own network, reachable only over VPN.
Our approach
Regain control safely
We connected through the client's VPN and hosting panel and reset administrator credentials directly in the database, so control did not depend on any channel that might itself be compromised.
Audit before changing anything
We checked the uploads directory, must-use plugins and plugin code for injected files, and reviewed every plugin that contacted third-party servers before deciding what stayed active.
Close the common entry points
We applied the standard WordPress hardening set at both the web-server and application level, removed files that leaked server details, and added a security plugin for monitoring.
Rank what is left
Instead of a risky blind upgrade, we ranked the remaining work by risk and planned safe upgrade paths, leaving licensing and infrastructure decisions with the client.
How we delivered
-
1
Regain access
AuditConnected over the client's VPN and hosting panel and reset admin credentials directly in the database.
VPN access Credential reset Panel access -
2
Backdoor audit
AuditScanned uploads, must-use plugins and plugin code for injected files and reviewed plugins that contact third-party servers.
Uploads mu-plugins Plugin review -
3
Cleanup
CleanupRemoved files that leaked server details and deactivated plugins that were not needed.
Leaky files Unused plugins -
4
Hardening
HardeningApplied server- and application-level hardening and added security monitoring.
Server rules WordPress config Monitoring -
5
Risk roadmap
OperationsRanked the remaining risks and planned safe upgrade paths.
Risk ranking Upgrade plan
Results
A clean baseline
The post-takeover audit found no backdoors, and the site kept running normally throughout the cleanup.
Common attack paths closed
The usual WordPress entry points are closed, and a file uploaded through the media library cannot be executed.
A clear roadmap
The client has a ranked, costed list of the remaining upgrades instead of an open-ended worry.