Skip to content
AI Website Security

Record · the record, à la carte

The diagnosis that leaves with signed documents

Every executable file on your site must justify its presence. Those that can't are named, dated, and recorded in three signed documents you can present to your host.

99 €

per site · €199 with Restore

A backdoor grafted into YOUR code is removed on its own, the rest of the file untouched — and the excision is refused as soon as its boundary isn't certain
Obfuscated code is unwrapped layer by layer — base64, compression, rotation, and literal-key encryption — to show you what it was really doing
Your sitemap is checked against your actual pages: SEO spam shows up there before it appears in search results
Your system core and your extensions checked against the official fingerprints from their publishers
Every file named carries its proof of belonging: your host recomputes THAT line and reaches its own conclusion, without ever receiving the list of your files
A number instead of a report: "0 unexplained executable files", or the exact count
The database examined where it can hold executable code, and nowhere else
Privileged accounts, scheduled tasks, your site's declared address and your active extensions — read from the database, where an intruder returns after a file cleanup
The intrusion date bracketed, and the likely entry point
The page executed in an isolated browser: the destinations actually contacted, the scripts inserted, the redirects and windows on the first click, the clipboard — what no reading of the HTML can see
Your checkout opened in an isolated browser: a dummy card and password are typed in, never submitted, and followed to their destination — a card skimmer is seen stealing, not guessed from a signature
Restore reinstates the official file from the publisher's archive, on eleven systems: WordPress, PrestaShop, Drupal, Joomla, TYPO3, OpenCart, Grav, Concrete, Moodle, Magento and the Laravel framework — fingerprinted and compared before being written, refused otherwise
A WordPress or Drupal extension file modified after installation is recognised against its publisher's official package and reinstated from that package — never quarantined, the extension keeps working
Read-only until you ask otherwise: you decide on every repair
Two levels

Know, or have it fixed

The first gives you the full diagnosis and the documents. The second adds the action: the repair, verified afterwards, and rolled back on its own if your site stops responding.

Record

« What's happening on my site? »

99 €

the fix — new verification analysis within 7 days

  • The six angles of analysis, plus the database
  • The dating of the intrusion, bracketed by two bounds
  • The likely entry point, dated and cross-checked
  • The three signed documents: the report, the document for your host, and verifiable proof

Record + Restore

includes the previous one

« Fix it. »

199 €

the fix — new verification analysis within 7 days

  • Everything included in Record
  • Restore: reinstate the official files, remove what doesn't belong
  • Proven or cancelled — if the site stops responding, the original state is restored automatically
  • The new verification analysis, which turns the finding into a certificate of recovery

One year, paid once. Nothing renews: at the end of the year, monitoring stops on its own and notifies you — resuming it is a new purchase, never a charge to your card.

What the analysis looks at

Six angles, and the first one to answer wins

A file doesn't need to be cleared six times. All it needs is a provenance: the vendor, an official repository, a seal you placed yourself, a known build. What has none is what we're talking about.

The core of your CMS

Every file checked against the fingerprint published by WordPress or PrestaShop. Four possible states — genuine, modified, foreign, missing — and no value judgement.

Your extensions, against the official repository

It's the number-one entry point. An extension fallen behind, pulled from the repository, or carrying a version that never existed: each of these three states is stated differently.

What runs on its own

mu-plugins, WordPress drop-ins, auto_prepend_file, Git hooks, package scripts. Code that runs without anyone calling it is an aggravating factor, never a detail.

The gap between what is served and what is written

When a public page contains code found nowhere in the files, the conclusion is that it comes from the database. We say so rather than searching where the light is.

Secrets left within reach

Open database backups, accessible configuration files, keys in an exposed Git repository. The leak often comes before the stolen password.

And our reservations, stated

Every limit reached is written into the report: the files a read cap left unopened, those whose content the server refused, and the case where the installed version is published by no one — we then soften our wording instead of accusing. A report that hides what it didn't see claims more than it measured.

The two questions of the first five minutes

"Since when?" and "which backup should I restore?"

These are the two questions a merchant asks before all the others, and answering "we don't know" amounts to advising them to restore at random — and so to reinstall the intrusion, or to lose three weeks of orders.

the intrusion is hereJuly 12last known clean stateJuly 15date of the dropped file

The lower bound

The last state of the site in which this file did not exist. It relies on what we inventoried ourselves, not on a declaration from the server.

The upper bound

The date of the file that was dropped, if it hasn't been altered. It's the more fragile of the two bounds, and that's stated in writing.

The reserve

A file date can be forged with a single command. This sentence appears in the signed document: we don't hide it, we raise it in advance.

Then we identify the backup to restore — the one preceding the lower bound, not the most recent one.

In two steps

You connect your site. You start the analysis.

Nothing to install, nothing to download, nothing to delete afterwards. The tool handles the rest.

01

You connect your site

Its address, and the access credentials your host sent you when you opened your account. One minute.

02

You launch the analysis

You have nothing left to do. The result is displayed, and your documents are issued.

You install nothing, none of your files are modified without the Restore option, and nothing is kept by us.

What the tool does for you

An agent that passes through, then erases itself

To analyse your files, the tool places a read-only agent on your server, then removes it at the end — and re-reads the server to verify it has indeed gone, rather than trusting a return code that says "success".

This agent exists for a technical reason, not a commercial one: fingerprinting two thousand files from the outside would require downloading them one by one. The agent fingerprints them where they are, and your files never leave your server.

A security module

  • stays installed indefinitely
  • runs on every visit to your site
  • must be kept up to date, or it becomes the vulnerability
  • widens the attack surface instead of reducing it

The AI Website Security agent

  • lives only as long as the analysis, a few minutes
  • never runs for your visitors
  • has nothing to maintain, since it is no longer there
  • is removed by us, and its removal is verified
Analysis pricing

Paid per job, once

The new verification analysis is free for seven days, and it is not a gift: after a cleanup, you have to prove it again. It is what turns an incident finding into a certificate of recovery.

Record

the diagnosis and the documents

99 €

per site

Record + Restore

with the cleanup and the new analysis

199 €

per site

There is no free analysis, and that is deliberate. A free preview would almost always answer "nothing found" — which is the good news everyone expects, given without proof, and offered to those who did not need it.

What it recognises

It finds without knowing. It names when it recognises.

A conventional antivirus names a file because it holds the signature: without it, it sees nothing. Here the order is reversed — a file is found because it cannot justify its presence, and its name comes afterwards, once its shape is recognisable. These 19 families are therefore a comment on what has already been found, never the reason it was found.

And when the shape says nothing, it writes it as such. A wrong name costs more than silence: it sends the merchant looking in the wrong place.

WSO Shell

A complete administration console, password-protected, dropped into the site: the intruder browses your files, reads the database and opens a terminal.

c99 Shell

One of the oldest PHP intrusion consoles, still massively copied.

r57 Shell

An intrusion console contemporary with c99, from the same distribution channel.

b374k Shell

A modern intrusion console, delivered as a single compressed file that unpacks itself on execution.

ALFA TEaM Shell

A very comprehensive intrusion console, specialised in shared hosting environments.

IndoXploit Shell

An intrusion console distributed with mass automated attack tools.

Gel4y Mini Shell

Minimalist console designed to slip past checks: just a few lines.

Marijuana Shell

Intrusion console geared toward bulk manipulation of a hosting account's files.

China Chopper

A one-line backdoor: the file has almost no content at all — all the logic lives in the software the intruder runs from home.

P.A.S. Shell

Encrypted intrusion console: its contents are only decrypted with the intruder's password, passed in a cookie.

Weevely

Backdoor generated by a penetration testing tool, deliberately written to look like ordinary code and contain no suspicious keywords.

WP-VCD

The most widespread WordPress infection in the world. It almost always arrives through a premium theme or plugin downloaded for free from a third-party site.

AnonymousFox

A campaign that doesn't target the site but the HOSTING ACCOUNT: it creates mail accounts and administrator access without your knowledge.

Japanese SEO spam

The site is being used to sell counterfeit goods in Japanese within Google results, with nothing appearing different to an ordinary visitor.

Pharma hack

Links to pharmaceutical sites are added to your pages, but shown only to Google — never to you.

Mass-mailing script

A form dropped on the site to send thousands of emails from your server.

Symlink attack

A script that creates shortcuts to the files of the OTHER sites hosted on the same machine, in order to read their database passwords.

Adminer (legitimate tool, dropped here by a third party)

A perfectly legitimate database administration tool — but not one anyone installs by accident in the middle of a production site.

Obfuscated code

The file was deliberately made unreadable by an automated tool — several nested layers of encoding before execution.

The scope of the baseline examination

Your customers remain out of reach, by design

Only a value containing executable code can be reported, and only the fragment around that code. A customer's address looks nothing like executable code: it is therefore never transmitted.

What is examined

  • options and settings, rendered across all your pages
  • the content of posts and pages
  • custom fields pulled in by the templates

What remains out of reach

  • orders and their details
  • customers and their contact details
  • addresses
  • carts
  • payment methods
  • passwords
  • messages

Is your site down, and your host is waiting for evidence?

The analysis runs, the documents are issued, and you can respond within the hour.

aiwebsitesecurity · aiwebsitesecurity · aiwebsitesecurity ·