Pasan Enterprises: recovering a fully compromised website and rebuilding it as a secure business platform

11 min left

Case study

Pasan Enterprises: recovering a fully compromised website and rebuilding it as a secure business platform

Most website projects begin with a blank page. This one began with a crime scene. How we recovered years of business content out of a hostile environment, rebuilt on a bespoke theme and three in-house plugins, and put every admin login behind a Cloudflare Zero Trust tunnel — inside the client’s original budget.

  • Cloudflare Zero Trust
  • Compromised web recovery
  • Wordpress
Regalia Sales Team 29 August 2026 11 min read

Engagement at a glance

ClientPasan Enterprises (pasanenterprises.lk), Sri Lanka
AgencyRegalia Solutions (Rukshimart Private Limited)
Project typeSecurity incident recovery and full website rebuild
PlatformWordPress — bespoke theme and three in-house plugins
Budget outcomeDelivered in full within the client’s original budget

Executive summary

Most website projects begin with a blank page. This one began with a crime scene.

When Pasan Enterprises approached Regalia Solutions, their website had been fully compromised. An attacker had taken control of the site, and the business content, product information and customer enquiry history the company had built up over years was sitting on the wrong side of a breach with no clear route back.

We were engaged to solve two problems at once. Recover whatever could be recovered from a hostile environment without carrying the compromise forward. And rebuild the entire web presence on a foundation that would not fail the same way twice.

What we delivered is a fast, professionally designed WordPress site running on a theme we wrote from scratch, supported by three custom plugins engineered specifically for this client’s workflow, and protected by a modern security stack in which every administrative login is brokered through a Cloudflare Zero Trust tunnel rather than exposed to the open internet.

About the client

Pasan Enterprises is an established Sri Lankan business whose website is a working commercial asset rather than a brochure. It carries their product and service information, it is where prospective customers form their first impression, and it is the channel through which enquiries and quotation requests arrive.

That context matters for understanding the severity of what happened. This was not a dormant site nobody would miss. It was a live front door to the business — and while it was compromised, that front door was both closed and dangerous.

The situation we inherited

Taking over a compromised environment is a fundamentally different discipline from building something new, and it is worth being clear about why.

When a site has been fully taken over, you cannot trust anything inside it. Not the files, not the database, not the user accounts, not the scheduled tasks, not the backups. An attacker who has held a site for any length of time will typically have left multiple ways back in, and many of those persistence mechanisms are designed specifically to survive a cleanup. A restore that looks successful can quietly reintroduce the original compromise — and the client discovers this weeks later when the site is defaced or blacklisted again.

This is why many agencies, handed a breached site, simply decline the recovery and quote for a rebuild from zero. It is the safe answer for the agency. It is also an expensive answer for the client, because it writes off everything they had built.

We were not willing to take that route without first exhausting the alternative. The client’s content had real commercial value, and recovering it was the difference between relaunching quickly and disappearing from the web for months.

The three constraints

  1. A hostile starting environment

    Nothing from the compromised system could be trusted or reconnected. Recovery had to happen in isolation, with everything treated as suspect until proven otherwise.

  2. Business content worth saving

    Years of product information, page structure and business copy. Losing it meant months of client-side rework, significant search visibility loss, and no functioning website in the meantime.

  3. A real and firm budget

    A growing business, not an enterprise with an open-ended security budget. Whatever we designed had to be affordable, maintainable without specialist staff, and still meaningfully secure.

Any one of those alone is routine. Solving all three at once is where the engineering judgement came in.

Our approach

Containment and assessment

The first phase was not building. It was understanding.

We treated the compromised environment as untrusted from the outset and worked from an isolated position rather than from inside the live system. Before touching recovery, we needed a clear picture of what had been affected, what remained intact enough to be worth extracting, and what would have to be rebuilt regardless.

That assessment shaped everything downstream. It told us what could realistically be salvaged, it set honest expectations with the client early rather than after weeks of silence, and it made clear that a clean rebuild of the platform itself was non-negotiable. Recovery would apply to the client’s content and data. It would not apply to the code that had failed them.

Strategic data recovery

Rather than accept the loss, our team worked methodically through every remaining avenue to reconstruct the client’s information. Content was extracted and validated in isolation, checked against what the business knew to be correct, and rebuilt into a clean environment. At no point was anything reconnected from the breached system into the new one.

The result was a genuine recovery. Pasan Enterprises did not start from zero.

A custom WordPress theme, written from scratch

We did not buy a theme and reskin it. The entire Pasan Enterprises theme was designed and coded by Regalia Solutions. Given how this project started, that was not a matter of preference.

  • Security

    Commercial themes carry inherited vulnerabilities and large volumes of third-party code nobody on the project has read. A theme we wrote has an attack surface we fully understand — and when a vulnerability is disclosed anywhere in the WordPress ecosystem, we can answer immediately whether it affects this client.

  • Performance

    No page-builder overhead, no unused component libraries, no scripts loading for features this client will never use. On Sri Lankan mobile connections that difference is felt by real visitors.

  • Brand fit

    Layout, typography and page structure designed around how Pasan Enterprises actually presents itself and sells — not around a template author’s assumptions. The site looks like their business, not a theme demo with the logo swapped out.

  • Ownership

    The client owns their theme outright. No licence to renew, no vendor who might abandon the product, no risk of a future update breaking a site they depend on.

Three custom plugins, engineered in-house

Third-party plugins are one of the most common weak points in any WordPress installation. Every additional plugin is another codebase the site owner does not control, another maintenance cycle they depend on, and another potential entry point. Plugin abandonment is routine — and an abandoned plugin with a disclosed vulnerability is exactly how sites like this one get taken over in the first place.

For the functionality this client needed most, we wrote our own.

  1. SMTP

    Reliable transactional email through the client’s own mail infrastructure, with credentials handled securely rather than sitting in plain configuration. For a business whose enquiries arrive by email, mail that silently fails to send is lost revenue — so this was treated as core infrastructure, not a utility.

  2. Quotation management

    Enquiries arrive structured and actionable rather than as loose form emails buried in an inbox. The client can see what has come in, what has been answered and what is still open. This is the single change with the clearest commercial return of anything we built.

  3. Testimonials

    Collecting, moderating and publishing customer testimonials on the client’s own property rather than through an external service or a plugin with an uncertain future. Moderation sits with the client; display is designed into the theme rather than bolted on.

Each plugin was written to fit this client’s actual workflow. No unused features, no licence fees stacking up year after year, no surprise deprecations, and no functionality the client is paying for but never uses.

Security architecture rebuilt from the ground up

Given how this project began, security was not a final checklist item. It shaped every decision from the first day. The centrepiece is a Cloudflare Zero Trust tunnel protecting all administrative access.

The WordPress admin login is the single most attacked endpoint on any WordPress site on the internet. Automated traffic hunting for it is constant, indiscriminate and relentless. Conventional defences try to survive that traffic through rate limiting, login attempt caps and firewall rules — all of which are a contest you have to keep winning forever.

Around that centrepiece, the site runs on a current, hardened configuration: traffic proxied and filtered through Cloudflare, a deliberately minimal and fully understood plugin footprint, disciplined update and backup practice, secure credential handling throughout, and correctly scoped administrative roles.

The practical effect for the client is that the failure mode which destroyed their previous site is no longer available to an attacker in the same form.

Performance, continuity and handover

A rebuild is also an opportunity, and we used it. The purpose-built theme gave the site a clean, fast front end with no inherited overhead. Content structure and URL continuity were handled carefully during reconstruction so the relaunch strengthened the client’s search position rather than starting it over.

We do not consider a project finished when a site goes live. The client was walked through their new admin environment, the quotation and testimonial workflows, and the access process for administrative logins under Zero Trust. Documentation and maintenance practice were left in place so the site stays secure through normal operation rather than depending on somebody remembering to do the right thing.

The client owns their theme, their plugins, their data and their infrastructure. Nothing about this build locks them to us.

Delivering within budget

Every decision above was made with the client’s budget in the room — and the budget genuinely improved the architecture.

  • Writing our own theme and plugins removed recurring licence costs entirely, which compounds meaningfully year after year for a small business.

  • Cloudflare Zero Trust delivered enterprise-grade access control at a cost a growing business can actually carry — which is precisely why we reached for it rather than proposing infrastructure the client would quietly stop paying for.

  • Keeping the plugin footprint minimal reduced both the attack surface and the long-term maintenance hours the client would need to fund.

Security is usually sold as an expensive add-on, a line item that scales with spend. On this project the security came from making better architectural decisions, not from spending more money. That is a distinction we think more agencies should be honest about with clients of this size.

Results

What Pasan Enterprises ended up with

  1. A fully recovered and relaunched website following a complete compromise, with no compromised code carried forward
  2. Client content and business data reconstructed rather than written off, avoiding months of rework
  3. A bespoke WordPress theme owned outright, with no third-party theme dependency and no licence renewals
  4. Three custom plugins covering transactional email, quotation management and testimonials, all engineered in-house
  5. Administrative access secured behind a Cloudflare Zero Trust tunnel, removing the exposed login surface attackers rely on
  6. A clean, fast front end built on purpose-written code rather than page-builder overhead
  7. A structured quotation pipeline that converts website enquiries into trackable business leads
  8. Full ownership of code, data and infrastructure handed to the client
  9. Delivered in full within the agreed budget

Why this project represents how Regalia Solutions works

A great many teams can build a website. Considerably fewer can take over a site that has already been broken into, recover the client’s data out of a hostile environment, and hand back something demonstrably stronger than what existed before — all inside a small-business budget.

  • Technical depth

    Custom theme development, custom plugin engineering and Zero Trust access architecture are not things you outsource to a template or a marketplace. Our team wrote every line, and designed the security model around this client’s specific risk profile.

  • Creative problem solving

    Neither the recovery path nor the budget had an obvious answer. Both were solved through better engineering decisions rather than bigger invoices.

  • Trust

    A live business emergency and a firm budget at the same time. We handled both, communicated openly throughout including when the news was uncertain, and left them owning their own code, data and infrastructure.

A client who can leave at any time and chooses to stay is the only kind of client relationship we are interested in building.

Frequently asked questions

Can a hacked WordPress website be recovered, or does it have to be rebuilt from scratch?

The content and data can very often be recovered. The code and configuration should not be. A compromised site typically contains multiple persistence mechanisms designed to survive a cleanup, so restoring it as-is risks reintroducing the breach. The correct approach is to extract and validate the content in isolation, then rebuild the platform itself clean — which is exactly what we did for Pasan Enterprises.

What is a Cloudflare Zero Trust tunnel and why use it for WordPress admin?

It brokers access to your admin login through Cloudflare, verifying identity before any request reaches your server. The login page is no longer exposed on the public internet, so brute-force and credential-stuffing traffic never arrives at all. It removes the attack surface rather than trying to survive attacks against it.

Why write a custom WordPress theme instead of buying one?

A purchased theme brings large volumes of third-party code nobody on the project has read, often bundling its own plugins and libraries. That is inherited attack surface and inherited performance cost. A custom theme is lighter, fully understood by the team maintaining it, owned outright by the client, and carries no licence renewals.

Is enterprise-grade security affordable for a small business?

Often yes, because the strongest controls come from architecture rather than spend. On this project, writing our own theme and plugins removed recurring licence costs, and Zero Trust access control was reached for precisely because it is affordable enough that a growing business will keep paying for it. Security the client cannot afford to run is security that fails the moment the agency leaves.