This is a historical record of a security incident affecting passlee.com. It documents what happened, not how to fix it – see Security Hardening Strategy for the resulting long-term practices.
Discovery
Hacked pages were discovered on the site, along with gambling/spam content appearing in Google search results for passlee.com – a clear sign the site had been compromised and was serving unauthorised content, at least to search engine crawlers if not always to normal visitors.
What was found
- Unauthorised files had been created on the server.
- Gambling/spam content was indexed by Google under the passlee.com domain.
- Search Console showed anomalies consistent with the compromise.
Effect on SEO and indexing
The compromise affected how the site appeared in search and how it was indexed – spam content competing for indexing attention alongside legitimate pages, and general uncertainty about the site’s standing with Google while the issue was unresolved.
Initial uncertainty
The attack vector was not immediately clear – a common characteristic of WordPress compromises, where the entry point (outdated plugin, weak credentials, server-level issue) often takes investigation to identify with confidence, and initial response has to proceed on incomplete information.
See the Website Recovery Timeline for the sequence of events that followed, and the Security Before SEO Decision for how this shaped subsequent priorities.