Skip to content
AI Website Security
Emergencies

Six situations, six answers

Each of these pages starts from a symptom and gives the full order of the steps, including those carried out without us. They have one thing in common: they all arrive at the same place, the one where you must establish the exact list of what has changed, and prove it to someone else.

The general case

The first 24 hours

The order of the seven steps when a site has been taken over by someone else: what to copy first, what to timestamp, and when to take back access.

Safe Browsing

Google's warning

"This site may be hacked", the red interstitial before the page, the notice in search results: where each one comes from, what you need to establish, and how to request a review.

Redirects

When your site opens another one

Visitors end up elsewhere, and you never do. Where a conditional redirect hides, how to see it from your own machine, and what removes it for good.

Foreign pages

Pages that have appeared in your results

Your domain shows up for words you never wrote. How to measure the real extent, remove the pages, and push down what remains indexed.

Host provider

When your host suspends the site

What your host provider saw, what it expects from you in order to reopen, and the piece of evidence that shortens the exchange the most: a dated report that someone else can verify.

Unjustified flag

A healthy site, flagged

An antivirus, a browser or a client flags you, and your site is fine. How to demonstrate it with evidence that stands up to scrutiny rather than with your word.

The point where all these roads meet

Whatever the symptom, the same question ends up being asked: what exactly has changed on this site? A live site holds tens of thousands of files, and the one that was added looks just like its neighbours. Searching for what is known to be bad misses everything that was written for you alone.

Our analysis takes the question the other way round: it asks each file to justify its presence, by comparing it with the authentic code published by its developer. Whatever checks out is counted; the rest is named, one by one, with its date and location. You leave with three signed documents that your host, your client or your insurer can verify with us, free of charge and forever.

The caveat is written on every document, and it applies here: a fully accounted-for site is a site in which every file has been vouched for — which is already a great deal, and still something other than a secure site. A weak password, or an up-to-date but vulnerable extension, remains beyond the reach of a file comparison.

How many files on your site can justify their presence?

You'll have the exact number, each file named, the likely date, and three signed documents that someone else can verify.

aiwebsitesecurity · aiwebsitesecurity · aiwebsitesecurity ·