Home Security stories When a hacked website puts an SEO freelancer’s reputation at risk

When a hacked website puts an SEO freelancer’s reputation at risk

Shield icon with checkmark

You can be 0% responsible for the security of a WordPress website and still get the blame when something goes wrong, even if just temporarily.

A freelance SEO consultant was working with a building company in the London area when the client suddenly emailed to ask whether they had done something to break the website.

Content had disappeared, the menu and footer were no longer displaying properly, and important sales pages had become unusable. Those pages were a major source of leads for the business.

The cause was not clear. What was clear was that the website had changed unexpectedly, and the client needed to determine what had happened and who might be responsible.

When the client thought the SEO consultant had caused it

The consultant had recently been given a user account on the client’s WordPress website as part of the SEO project. They had completed an audit and some off-page work and had started drafting content outside WordPress, but they had not yet logged in to the account.

Even after stating I had not yet logged into the account they created for me on the site, the client was convinced that the issue was caused by me, as I had recently been given access to the site.

There was no activity log available to provide a clear record of what actions had or hadn’t been taken on the consultant’s account.

That left them in an uncomfortable position in which they felt like they had to help investigate the problem while also proving they had not caused it.

The whole situation was very stressful, as your reputation is the cornerstone of any service business. As a freelancer, even more so, as that reputation is directly tied to you as an individual. Negative reviews can damage this reputation badly, which can obviously have many knock-on effects.

The client had already lost days of leads

While the consultant was dealing with the reputational side of the incident, the client was facing a more immediate business problem.

There was no detection in place to alert them when the website first became unusable. By the time they noticed, the affected sales pages had already been down for several days.

They lost days of leads and lost revenue and customers as a result of it.

The client and their developer or site administrator rushed to repair and rebuild the affected parts of the site. The consultant also spent considerable time helping them work out what had happened.

The exact technical cause was never confirmed to the consultant. Although unauthorized access was considered possible, the client didn’t say whether the changes were due to a compromised account, another security issue, or something else.

What the incident did show was its impact, which included lost inquiries for the client, additional recovery work, and significant stress for someone who had no responsibility for managing the website’s security.

What changed afterwards

The incident changed what the consultant recommended before beginning hands-on work inside a client’s WordPress website.

I’ve started recommending clients install an activity log before working on their website directly.

For this consultant, the value of that record became very practical after the incident.

It can not only show you what happened when something goes wrong, but it can also help prove that it wasn’t you when there is an issue.

An activity log cannot prevent every incident or automatically establish its cause. But it can provide a record of user actions that may otherwise be difficult to reconstruct afterward.

The lesson

As an SEO, I perhaps naively wasn’t expecting to encounter something like this.

Developers, marketers, SEO consultants, agencies, and other third parties may all, at some point, get access to a WordPress site. When something goes wrong, questions about who changed what can quickly become part of the incident.

The main lesson the consultant took from the experience was that even when WordPress security is not your responsibility, the effects of a security incident can still reach your work and your reputation.

Have you dealt with a WordPress security incident?

Your story can show what security incidents really look like beyond the statistics, including the impact and lessons that are easy to miss.

Tell us what happened, what the experience was like, and what you learned from it. Stories may be published anonymously.

Story at a Glance

  • Business Type Freelance SEO specialist
  • Website Type Building company website
  • Impact Lost leads and revenue, significant stress, and reputational risk
  • Incident Type Malware infection
  • Discovered By The client