Xscape4u — a hacked tourism website, rebuilt clean

Xscape4u was referred to us after a compromise: its site was being injected with links to offshore casino sites. We rebuilt the entire platform and delivered it clean.

Client since
2026

The situation

Xscape4u is a travel business. As at 28 September 2026, its website lists handpicked lodges, camps and hotels in destinations from Limpopo and the Western Cape to Botswana, Zanzibar and the Seychelles, and its property pages take general enquiries and booking enquiries.

When Xscape4u was referred to us, its site had been compromised: links to offshore casino sites were being injected into it. Google’s spam policies define hacked content as “any content placed on a site without permission, due to vulnerabilities in a site’s security” (as at 28 September 2026). We explain how hacks like this work, and how they are cleaned up, in our article on casino-link and SEO-spam hacks.

The developers who had been helping Xscape4u could not fix the compromise, and Xscape4u chose to move to us.

What we built

Xscape4u has been a client since 2026. We rebuilt the entire platform. We extracted the site’s data and left the hacked content out, so the new site started clean instead of inheriting the compromise. In our terms it was a website rescue, done as a rebuild.

How it works

As at 28 September 2026, this is how the rebuilt site works for Xscape4u’s customers. They browse the properties by destination or by collection, such as safaris, islands or last-minute stays, or search for one. A property page, such as the one for Ants Hill in the Waterberg, shows the room rates and any specials, with two buttons. “Enquire” opens a short form for a general enquiry. “Book Now” opens a booking enquiry, which asks for check-in and check-out dates, adults and children, the room type, and any dietary requirements, allergies or special occasions. The site takes both kinds of enquiry, not confirmed bookings.

What changed

Xscape4u’s site was delivered clean: the injected casino links gone, its data brought across without the hacked content, and the new platform protected with encryption and Wordfence.

What it runs on

The rebuilt site runs on WordPress, hosted by Fyre; as at 28 September 2026, its footer reads “WordPress by Fyre Interactive”. It was delivered protected with encryption and with Wordfence, which Wordfence’s product page describes as a firewall and malware scanner built to protect WordPress (as at 28 September 2026). What Wordfence does, and what it cannot do on its own, is in our guide to WordPress security plugins.

Related services

More work

See all our work

Start a project like this

A few lines about your project are enough to start. We’ll reply with questions, a sensible next step and, where the job allows, a fixed price.

Great service deliverables – Supportive, patient, reachable at all times and responsive

Samantha M. · Xscape4u · Google review