The publisher's site had been flagged by Google for serving malware, but every security audit returned clean. The team was frustrated - their WordPress dashboard looked fine, no suspicious activity, no strange files.
The malware was injected through a legitimate but compromised commercial plugin that passed all automated checks. It loaded only for certain user-agent strings and geographical locations, making it invisible to most scanners. The fix required deep file-level forensics.
A media publisher's high-traffic WordPress site had a clean bill of health from multiple security scans - yet was still serving malicious redirects to visitors. The dashboard showed no signs of compromise. No unauthorized admin users. No suspicious files detected by standard scanners. Yet the site was actively harming readers.