NEXSUM_LABS
  1. Home
  2. Work
  3. A roofing contractor's lead machine was recovered from a hacked WordPress install — without losing its rankings
Book a call

[ Case study ]

Commercial roofingWordPressMalware cleanupFile-integrity monitoringWAF

A roofing contractor's lead machine was recovered from a hacked WordPress install — without losing its rankings

Google had flagged the contractor's site for serving spam pages injected by malware; leads dropped by half in six weeks, the host threatened suspension, and a previous 'fix' had removed the visible spam while leaving the injection mechanism in place.

CLIENT a commercial roofing contractor — FOCUS Find the mechanism, not just the symptom

WordPress MaintenanceMaintenance & SupportWordPress MaintenanceCommercial roofingRepresentative example
Client
a commercial roofing contractor
Industry
Commercial roofing
Engagement
5 weeks — systems pod — engineer
Service
Maintenance & Support / WordPress Maintenance
Headline outcome
Spam flag lifted after review, with the injection mechanism removed and monitored: Flagged → clean reconsideration, read from Search Console status

Representative examplesEvery case study in this library is an illustrative composite of the kind of engagement we deliver — written to show our method and standards, not to name clients.

Where they started

Commercial roofing — flat roofs, repairs, replacement contracts for property managers — is how this contractor earns its living, and it wins work almost entirely through search. The site ranks for the region's commercial roofing queries, built over a decade of steady content and project photos. The office is a project manager, an estimator, and an office administrator; the website was set up years ago by a relative and maintained irregularly since. When the website needs anything, the administrator emails the relative and waits.

What it was costing

Google had flagged the contractor's site for serving spam pages injected by malware; leads dropped by half in six weeks, the host threatened suspension, and a previous 'fix' had removed the visible spam while leaving the injection mechanism in place.

What they could see

  • Search results for the brand started surfacing spam pages for pharmaceuticals the contractor had never sold.
  • Leads fell steadily for six weeks, and the inquiry log's slope changed before anyone knew why.
  • Google Search Console showed the manual-action flag, and the host threatened suspension within the same week.
  • A previous fix had removed the visible spam, yet flagged pages reappeared within days of the all-clear.
  • The office stopped trusting the site — staff hesitated to send customers to pages they couldn't verify were clean.

The constraints we worked inside

  • Search visibility is the business's main channel; cleanup must preserve rankings, URLs, and content exactly — no 'start fresh' temptation.
  • The site is business-critical during cleanup; work happens on staging with short, rehearsed cutover windows.
  • The contractor must understand what happened; trust requires explanations in plain language, not a black box.

What had been tried before

A previous contractor deleted the visible spam pages and re-submitted the site to Google.
That treated the symptom; the backdoor and its re-injection cron survived, flagged pages returned within days, and the second flag stuck harder than the first.
The hosting provider was asked to clean the infection from their side of the account.
The host restored files from an older snapshot, which brought back the vulnerable plugin versions the attacker had used — a clean-looking site with the same door open.
The office hand-audited pages against a printed sitemap each week to catch reappearing spam.
Injected spam lived on generated URLs the sitemap never contained, so the audit passed every week while Search Console kept reporting pages nobody had seen.

What we proposed

We proposed finding the mechanism, not just the symptom: a file-integrity diff and log review to locate the backdoor and the cron re-injecting spam, then a full cleanup performed on staging, verified with malware scanners, Search Console, and content diffs, and cut over in a short rehearsed window with rollback ready. Rankings, URLs, and content survive exactly — no fresh start, because search equity is the business's main channel. The reconsideration request would document root cause, cleanup, and the monitoring now in place, in plain language the owner could stand behind.

Just as important is what we ruled out, and why:

  • Rebuilding the site fresh on a new domainSearch equity is the business's main channel; a fresh start torches a decade of rankings and reviews to escape a cleanup that was fixable in place.
  • Restoring the host's last clean snapshotThe snapshot predated months of content and contained the vulnerable plugin versions — that cycle is how the site got flagged in the first place.
  • Handing cleanup to an SEO reputation firmBlack-box fixes were the prior failure; the contractor needed plain-language explanations and evidence, which meant doing the work where the owner could inspect it.

How the work ran

01Find the mechanism, not just the symptom

A file-integrity diff and log review located the backdoor and the cron that re-injected spam, so cleanup removed the cause — the prior fix had removed only the symptom.

02Clean on staging, prove, then cut

The staged cleanup was verified with malware scanners, Search Console, and content diffs, then cut over in a rehearsed window with rollback ready.

03Request review with evidence

The reconsideration request documented the root cause, the cleanup, and the monitoring now in place, and rankings recovered over the following weeks.

Delivered by the systems pod — engineer over 5 weeks, with working increments reviewed with the client every week.

The stack, and the reasoning

WordPress
Rankings, URLs, and content had to survive exactly; rebuilding on anything else reset the equity the business runs on, so cleanup happened in place.
Malware cleanup
The backdoor and re-injection cron had to be found and removed, not the spam they generated — mechanism, not symptom, was the unit of work.
File-integrity monitoring
The search rankings are the recovery, so the integrity checks exist to catch a re-injection before Google does — a second flag would cost more than the first ever did.
WAF
Edge rules now refuse the request patterns the attacker used, buying time between a future vulnerability and anyone exploiting it.
Search Console recovery
The reconsideration request needed documented evidence — root cause, cleanup, monitoring — which the tooling produced as a byproduct of doing the work properly.

What went wrong

Obstacle

Two days after the first staged cleanup, flagged pages reappeared: the backdoor's re-injection cron had survived the file restore, exactly the mechanism the previous fix had missed.

Handled: We stopped trusting file snapshots, diffed the filesystem against a known-good core, and pulled the backdoor and cron from the logs before re-running the full cleanup.

Obstacle

A reused password on an old admin account — the likely original entry point — surfaced on the final day, after the cleanup had already been verified clean twice.

Handled: Every credential was rotated, including the database user and hosting account, and the rotation was documented in the evidence file the reconsideration request later cited.

How we worked together

Cadence
Twice-weekly 20-minute calls with the office administrator and project manager; the owner joined twice — once for findings, once to approve the reconsideration request.
Client side
The office administrator ran the inquiry-log baseline and validated content pages; the project manager owned the cutover window around a roof-install schedule.
Decisions
Cleanup trade-offs were presented as findings with evidence — file diffs, logs — so the owner could approve in plain language, which was the trust requirement stated up front.
They provided
Hosting and Search Console access, a list of every credential the business had ever used on the site, and the inquiry log going back six months.

What changed

The headline: spam flag lifted after review, with the injection mechanism removed and monitoredFlagged → clean reconsideration, read from Search Console status. A second check: lead-form submissions in the two months post-recovery vs during the flag at +38%.

The office trusts the inquiry log again — the slope that first alerted them is now the same chart they watch weekly. The owner can explain the incident to a customer in two sentences, which matters in a trade that sells trust. Search visibility recovered without the fresh-start conversation ever returning, and the site's upkeep stopped depending on a relative's goodwill. The scariest part of the whole episode — not knowing — is now a file diff away from an answer.

The result was read from Search Console status against the pre-engagement baseline over the stated window, with a guardrail check on lead-form submissions in the two months post-recovery vs during the flag. Where platform-reported numbers and business outcomes differ, this record says which layer it is quoting.

What they own now

  • The cleanup evidence file: diffs, logs, and the reconsideration request as submitted.
  • A credential rotation record covering every account, including the database user.
  • File-integrity monitoring and WAF rules documented with first-response steps.
  • A plain-language incident summary the owner can show partners or the host.
  • A monthly check schedule for Search Console and integrity alerts, owned in-house.

What we would do differently

We would change every credential including the database user before declaring clean — one reused password was the likely entry, and rotating it belonged in the first hour, not the last day.

Maintenance & SupportWordPress MaintenanceCommercial roofingWordPress

Next case study

A food hall's vendor-directory site got out of its volunteers' way with a maintained WordPress setup