This preserves the sequence of events during the security incident recovery, for project history. It is a written chronology, not the interactive “Timeline” feature listed on the Control Centre’s own Roadmap – that would be a future dashboard feature; this is content. See Security Incident – Website Compromise for what happened.
Sequence of events
- Discovery of the compromise – hacked pages and gambling/spam content found appearing in Google under the passlee.com domain.
- Hosting provider investigation – engaged the host to investigate the extent of the compromise at server level.
- Malware removal – malicious files and injected content removed from the site.
- WordPress core replacement – WordPress core files replaced with clean copies to remove any tampering.
- Plugin updates – all plugins brought up to date as part of closing off the likely entry point.
- Security hardening – permanent practices put in place to reduce the chance of recurrence (see Security Hardening Strategy).
- Google re-indexing efforts – working to have spam/hacked content removed from Google’s index and legitimate pages re-confirmed.
- Return to normal operation – site and search presence stabilised back to normal.
See the “Security Before SEO” Decision for how this sequence shaped the project’s priorities during recovery.