Skip to content
Case study

simumed.ro: a compromised website, rebuilt from scratch without a page builder

SIMUMED is a medical simulation training centre in Bucharest: 13 hands-on courses and workshops for nurses, students and healthcare professionals. Their old website had ended up serving gambling pages instead of courses. We did not clean it, we rebuilt it: a custom theme, recovered content, and enrolment requests that land in the admin.

Client
SIMUMED, Medical Simulation Association
Sector
Medical education, simulation courses
Period
August 2026
What we did
Security audit, custom theme, enrolments, migration, email
simumed.ro home page on desktop
The home page: courses, the centre’s key numbers and the enrolment button, all above the fold.
117gambling spam posts, in 8 languages, found on the old site
2foreign administrator accounts, active for over a year
0executable files carried over from the old site
100Lighthouse desktop at handover, in all four categories
Starting point

A website that no longer belonged to the client

The site ran on shared cPanel hosting, on a page-builder theme with 17 plugins. The audit found a hidden file in the web root that proxied a gambling page hosted elsewhere, on its own route, with a dedicated rule in the server configuration. The blog was spam from top to bottom, and the user list held two administrator accounts nobody at the association had created.

  • 117 spam posts in 8 languages, indexed by Google under the association’s name, plus a separate SEO spam page.
  • Two foreign administrator accounts, one from June 2025, the other from August 2025.
  • Traces of a file manager plugin, the likely entry point, and of an earlier clean-up attempt that had failed.
  • The contact page had been emptied, so enrolment requests were going nowhere.
  • The association’s email lived with another provider and had to stay there, untouched.

On a site compromised for that long, nothing can be declared clean with certainty. The decision was to carry over no executable file at all: from the archive we extracted only the texts, the 48 original images and the logo.

What we did

Rebuilt from scratch, with what a training centre needs

WordPress with a theme written specifically for SIMUMED, without a page builder and without form plugins: everything specific to the site lives in the theme and is managed from the normal menus.

Audit and a clean rebuild

  • Audit of the complete archive of the old site: files, database, users, server rules. We documented what was found, so the association knows exactly what happened.
  • Content recovered from the database and cleaned text by text; images taken over as image files, checked one by one.
  • New site on our server, in containers, behind Cloudflare, with an application firewall, server-side cache and backups.
  • Custom theme: CSS and a single JavaScript file, subsetted fonts with Romanian diacritics, no external libraries.

Courses and enrolments

  • Courses are a custom content type with image, description and a chosen order; they are added and edited from the admin like any page.
  • Enrolment happens from a window opened on any course, with that course already ticked, or from the contact page.
  • Every request is saved in the admin under Requests, with CSV export; the email is just a notification, so nothing is lost if mail is delayed.
  • Protection without third-party CAPTCHA: a honeypot field, an arithmetic check and per-address rate limiting.

Design

  • Home page with the centre’s numbers, the courses, the gallery and the partners.
  • Course pages with the enrolment button in plain sight.
  • Legal and contact pages redone, all content in Romanian with proper diacritics.

Functionality

  • Enrolment notifications go to the people the client designated; the list changes in one place.
  • Dedicated SMTP for notifications, with a verified domain.
  • Gallery and partner list managed from options.

Migration and email

  • Certificate issued before the DNS change, so no downtime during the move.
  • The association’s email stayed with its provider; DNS records were corrected so mail does not pass through us.
  • From 17 plugins down to 8, each with a clear role: cache, images, security, SEO, mail.
On screen

What it looks like now

simumed.ro home page on mobile
Home page, mobile.
A course page on mobile
Course page on mobile, with the enrolment button.
The enrolment window with courses to tick
The enrolment window: courses to tick, contact details, preferred period and the arithmetic check.
A course page on desktop
Course page: description, photos from the workshops, enrolment.
The contact page
The contact page, with the same form saved in the admin.
Results

What changed

What we measuredBeforeNow
Foreign content on the site117 spam posts, an SEO spam page, a proxy to gambling pagesnone; only the association’s courses and pages
Administrator accountstwo unknown accounts, active for over a yearonly the association’s accounts, with two-factor authentication
Enrolment requestscontact page emptied, requests went nowheresaved in the admin, with email notification and CSV export
Plugins17, including a file manager8, no page builder and no form plugin
Lighthouse desktop (performance, accessibility, best practices, SEO)100, 100, 100, 100 at handover
PageSpeed on mobile, home page97 (5 September 2026)
Hosting and backupsshared, cPanel, no verified backupown server, containers, Cloudflare, backups

Suspect your website has been hacked?

We check it for free: files, users, indexed content. We tell you what we found and what we recommend, clean-up or rebuild, within one working day.

EN

Request a free audit

Tell us your website address. We review it across all six disciplines and send you the findings, whether or not we end up working together.

Your details come straight to us. We do not use them for anything else and we do not pass them on.