Record · the record, à la carte
The diagnosis that leaves with signed documents
Every executable file on your site must justify its presence. Those that can't are named, dated, and recorded in three signed documents you can present to your host.
per site · €199 with Restore
Know, or have it fixed
The first gives you the full diagnosis and the documents. The second adds the action: the repair, verified afterwards, and rolled back on its own if your site stops responding.
Record
« What's happening on my site? »
99 €
the fix — new verification analysis within 7 days
- The six angles of analysis, plus the database
- The dating of the intrusion, bracketed by two bounds
- The likely entry point, dated and cross-checked
- The three signed documents: the report, the document for your host, and verifiable proof
Record + Restore
includes the previous one« Fix it. »
199 €
the fix — new verification analysis within 7 days
- Everything included in Record
- Restore: reinstate the official files, remove what doesn't belong
- Proven or cancelled — if the site stops responding, the original state is restored automatically
- The new verification analysis, which turns the finding into a certificate of recovery
One year, paid once. Nothing renews: at the end of the year, monitoring stops on its own and notifies you — resuming it is a new purchase, never a charge to your card.
Six angles, and the first one to answer wins
A file doesn't need to be cleared six times. All it needs is a provenance: the vendor, an official repository, a seal you placed yourself, a known build. What has none is what we're talking about.
The core of your CMS
Every file checked against the fingerprint published by WordPress or PrestaShop. Four possible states — genuine, modified, foreign, missing — and no value judgement.
Your extensions, against the official repository
It's the number-one entry point. An extension fallen behind, pulled from the repository, or carrying a version that never existed: each of these three states is stated differently.
What runs on its own
mu-plugins, WordPress drop-ins, auto_prepend_file, Git hooks, package scripts. Code that runs without anyone calling it is an aggravating factor, never a detail.
The gap between what is served and what is written
When a public page contains code found nowhere in the files, the conclusion is that it comes from the database. We say so rather than searching where the light is.
Secrets left within reach
Open database backups, accessible configuration files, keys in an exposed Git repository. The leak often comes before the stolen password.
And our reservations, stated
Every limit reached is written into the report: the files a read cap left unopened, those whose content the server refused, and the case where the installed version is published by no one — we then soften our wording instead of accusing. A report that hides what it didn't see claims more than it measured.
"Since when?" and "which backup should I restore?"
These are the two questions a merchant asks before all the others, and answering "we don't know" amounts to advising them to restore at random — and so to reinstall the intrusion, or to lose three weeks of orders.
The lower bound
The last state of the site in which this file did not exist. It relies on what we inventoried ourselves, not on a declaration from the server.
The upper bound
The date of the file that was dropped, if it hasn't been altered. It's the more fragile of the two bounds, and that's stated in writing.
The reserve
A file date can be forged with a single command. This sentence appears in the signed document: we don't hide it, we raise it in advance.
Then we identify the backup to restore — the one preceding the lower bound, not the most recent one.
You connect your site. You start the analysis.
Nothing to install, nothing to download, nothing to delete afterwards. The tool handles the rest.
You connect your site
Its address, and the access credentials your host sent you when you opened your account. One minute.
You launch the analysis
You have nothing left to do. The result is displayed, and your documents are issued.
You install nothing, none of your files are modified without the Restore option, and nothing is kept by us.
An agent that passes through, then erases itself
To analyse your files, the tool places a read-only agent on your server, then removes it at the end — and re-reads the server to verify it has indeed gone, rather than trusting a return code that says "success".
This agent exists for a technical reason, not a commercial one: fingerprinting two thousand files from the outside would require downloading them one by one. The agent fingerprints them where they are, and your files never leave your server.
A security module
- stays installed indefinitely
- runs on every visit to your site
- must be kept up to date, or it becomes the vulnerability
- widens the attack surface instead of reducing it
The AI Website Security agent
- lives only as long as the analysis, a few minutes
- never runs for your visitors
- has nothing to maintain, since it is no longer there
- is removed by us, and its removal is verified
Paid per job, once
The new verification analysis is free for seven days, and it is not a gift: after a cleanup, you have to prove it again. It is what turns an incident finding into a certificate of recovery.
Record
the diagnosis and the documents
99 €
per site
Record + Restore
with the cleanup and the new analysis
199 €
per site
There is no free analysis, and that is deliberate. A free preview would almost always answer "nothing found" — which is the good news everyone expects, given without proof, and offered to those who did not need it.
It finds without knowing. It names when it recognises.
A conventional antivirus names a file because it holds the signature: without it, it sees nothing. Here the order is reversed — a file is found because it cannot justify its presence, and its name comes afterwards, once its shape is recognisable. These 19 families are therefore a comment on what has already been found, never the reason it was found.
And when the shape says nothing, it writes it as such. A wrong name costs more than silence: it sends the merchant looking in the wrong place.
WSO Shell
A complete administration console, password-protected, dropped into the site: the intruder browses your files, reads the database and opens a terminal.
c99 Shell
One of the oldest PHP intrusion consoles, still massively copied.
r57 Shell
An intrusion console contemporary with c99, from the same distribution channel.
b374k Shell
A modern intrusion console, delivered as a single compressed file that unpacks itself on execution.
ALFA TEaM Shell
A very comprehensive intrusion console, specialised in shared hosting environments.
IndoXploit Shell
An intrusion console distributed with mass automated attack tools.
Gel4y Mini Shell
Minimalist console designed to slip past checks: just a few lines.
Marijuana Shell
Intrusion console geared toward bulk manipulation of a hosting account's files.
China Chopper
A one-line backdoor: the file has almost no content at all — all the logic lives in the software the intruder runs from home.
P.A.S. Shell
Encrypted intrusion console: its contents are only decrypted with the intruder's password, passed in a cookie.
Weevely
Backdoor generated by a penetration testing tool, deliberately written to look like ordinary code and contain no suspicious keywords.
WP-VCD
The most widespread WordPress infection in the world. It almost always arrives through a premium theme or plugin downloaded for free from a third-party site.
AnonymousFox
A campaign that doesn't target the site but the HOSTING ACCOUNT: it creates mail accounts and administrator access without your knowledge.
Japanese SEO spam
The site is being used to sell counterfeit goods in Japanese within Google results, with nothing appearing different to an ordinary visitor.
Pharma hack
Links to pharmaceutical sites are added to your pages, but shown only to Google — never to you.
Mass-mailing script
A form dropped on the site to send thousands of emails from your server.
Symlink attack
A script that creates shortcuts to the files of the OTHER sites hosted on the same machine, in order to read their database passwords.
Adminer (legitimate tool, dropped here by a third party)
A perfectly legitimate database administration tool — but not one anyone installs by accident in the middle of a production site.
Obfuscated code
The file was deliberately made unreadable by an automated tool — several nested layers of encoding before execution.
Your customers remain out of reach, by design
Only a value containing executable code can be reported, and only the fragment around that code. A customer's address looks nothing like executable code: it is therefore never transmitted.
What is examined
- options and settings, rendered across all your pages
- the content of posts and pages
- custom fields pulled in by the templates
What remains out of reach
- orders and their details
- customers and their contact details
- addresses
- carts
- payment methods
- passwords
- messages
Is your site down, and your host is waiting for evidence?
The analysis runs, the documents are issued, and you can respond within the hour.