MD Pabel
WordPress malware removal expert. 4,500+ hacked WordPress sites cleaned manually. Malware cleanup, blacklist recovery, SEO spam removal & post-hack security.
18/05/2026
shipped a bluesky autoposter in 1 hour with claude code 🚀
it pulls my rss feed, generates captions with gpt-4o-mini, and posts daily via /api. upstash redis dedupes. vercel cron handles the scheduling.
open source — if you write a blog and want it on bluesky on autopilot:
https://github.com/mdpabel/Bluesky-Autoposter
https://bluesky.mdpabel.com
15/05/2026
New WordPress Malware Case Study Published
A hacked WordPress site lost nearly 60% of its AdSense revenue because of a hidden malware file called:
👉 mplugin.php
The scary part?
The malware only showed spam ads to Google visitors while hiding itself from:
❌ WordPress admins
❌ Logged-in users
❌ Most security scans
The site owner couldn’t even reproduce the issue on his own device.
Inside this cleanup I found:
• A fake “Monetization Code plugin” hiding in `/wp-content/plugins/`
• Admin IP tracking via `admin_ips.txt`
• 11 malicious `wp_options` database rows
• Search-engine cloaking targeting Google/Bing/Yahoo visitors
• Self-updating malware pulling payloads from external C2 servers
• Reinfection from a nulled WooCommerce extension
This is exactly why many hacked WordPress sites keep getting reinfected even after “cleanup”.
I broke down:
âś” How the malware works
âś” How it hides from admins
âś” The exact SQL queries used during cleanup
âś” IOC domains & indicators
âś” Step-by-step removal process
âś” Why most security plugins miss it
Full case study:
https://www.mdpabel.com/case-studies/mplugin-php-monetization-code-plugin-malware-case-study/
If your WordPress traffic dropped suddenly, ads look strange only on mobile, or visitors report popups you can’t reproduce — check your site carefully.
— MD Pabel
WordPress Malware Removal Specialist
4,500+ hacked WordPress sites cleaned
13/05/2026
Is your WordPress dashboard showing 1 user, but your security plugin says there are 2?
That can be a serious warning sign.
Some WordPress malware creates a hidden admin user, hides it from the Users page, and brings it back even after you delete it. This is one of the common reasons malware keeps returning after a cleanup.
I wrote a detailed guide showing:
How hidden WordPress admin users work
Where the malicious code usually hides
How to check the database directly
Why you must remove the malware code before deleting the user
How to stop the hidden admin from coming back
If you manage a WordPress site, this is worth checking.
Read the full post:
https://www.mdpabel.com/blog/how-to-find-and-remove-hidden-admin-users-in-wordpress-malware-analysis/
WordPress Hidden Admin User? How to Find & Remove (2026 Guide) Hidden admin user on your WordPress site? User count mismatch? Real malware code, detection methods, and removal steps from 4,500+ cleanups. Stop reinfection.
Click here to claim your Sponsored Listing.
Category
Contact the business
Telephone
Website
Address
Cumilla