Recovering a Hacked Site

Recently we took over a site that had been hacked and was displaying nothing for the client, they had liaised with the hosting company and the company had been unable to fix the issue which resulted in the client being without any viable web presence. We took over the website and identified the root cause of the site outage within an hour or so. The htaccess file had been injected with some harmful rewrite rules which fortunately were breaking rather than redirecting customers to harmful content.

The next step was to download a copy of the website and run a malware scan on the site, we then installed the wordfence plugin which highlighted vulnerabilities and files that had been compromised. We were then able to remove the ‘backdoor’ access left behind by the hacker’s automated scripts that was allowing them to re-access the system each time the site was fixed. We checked for any issues in the database and updated the site passwords. We updated all of the plugins and the wordpress install to the latest versions and following this we cleared the site contents from the server and re-uploaded. The next step was regenerate the sitemap and to login to google search console to request that the site be re-indexed following the clean up which removed the ‘this site may have been hacked’ warning from google’s search results.

The site is now back up and running and has experienced no further hacks

Our Flubit Plugin for WordPress

Recently we were approached to develop a plugin for WordPress that would allow the wordpress content editor to click a button on the text editor, enter a URL of a Flubit product and embed the product onto the page with a link. This would then be hosted on the flubit blog and allow them to drive traffic towards particular products. The initial request was that this information would be scraped from the flubit site and parsed into the desired format.

We started out by building the plugin’s WordPress functionality, so setting the plugin up and setting up the popup window and button for the text editor. Then we began to scrape the provided website URL using CURL which is our standard method, this is where we hit a few issues.  The content of each flubit page is created dynamically using a javascript framework (such as angular) so when we made a CURL request, the returned page only contained the code that the server had responded with and not all of the additional layout and data provided by the javascript  framework. This was a problem because javascript runs only in the browser and was being used to request the page data, the result was that the page returned by CURL was just showing an error saying that the browser was out of date.

The next thought was to check if the twitter card information was provided in the response as we would be able to use that information for our plugin. Unfortunately this appeared to be generated by the javascript framework too.

After some snooping around the internet we stumbled upon a solution, to use phantomJS as a headless browser, this allowed us to make a request and retrieve a fully rendered page from the server which was exactly what we wanted. We implemented this and got the plugin up and running successfully. When it came to deploying the plugin we hit a few snags in that there is a security concern around installing third party code onto corporate servers and as such the phantom JS option was out of the window. Incidentally, we’re considering setting up a phantom JS service to allow developers to pull back any web page’s fully rendered html and javascript as this will likely become an increasingly more common issue in the future (for enquiries email us at:

The third solution was to make use of the API that existed (and only came to light at this point) which works with no issues. We enjoyed working on the project and took a lot from it in, the key factor, as always, is not to give up as there’s always more than one way to solve a problem.

The Front-end result

Embedded Product




Using JQuery Templates

Recently I was working on a project that required the user to add a date range then add the times for each day within that range. After looking into doing this the old fashioned, embed it in the javascript, way I decided to look at using jQuery templates where the content is defined in a templating language then loaded at run time and the data is injected into the template.

A case study
The project I was using this technology with required that the user select a start and end date then the interface would respond and create time picker fields for each day selected. The advantage of using the templates in this instance was that if anything needed to be changed in the template it would be far easier than if the html elements had been declared and added in jQuery.

A jQuery snippet adding dynamic html

var html ='
<div data-id="' + + '">' +
'<img src="' + src + '" alt="" />' +
'<input class="linkto" type="text" value="' + obj.url + '" placeholder="Linked url" />' +
'<input class="remove-button button-primary" type="button" value="Remove Icon" data-id="' + obj.imageid +'" />' +
' <input class="moveup-button button-secondary" type="button" value="Move Up" />' +
'<input class="movedown-button button-secondary" type="button" value="Move Down" />' +

A jQuery template:

<script id="dateTemplate" type="x-jquery-tmpl">
<div data-id="${id}">
	<img src="${src}" />
    <input type="text" class="linkto" placeholder="Linked url" value="${url}"/>
    <input type="button" class="remove-button button-primary" data-id="${imageid}" value="Remove Icon" />
    <input type="button" class="moveup-button button-secondary" value="Move Up">
    <input type="button" class="movedown-button button-secondary" value="Move Down">

The advantage here is that we can change this easily and we don’t have any nasty apostrophes all over the place. To get started with this technology head over to and include a copy of the js in your project. After creating a template we can load it like so:

$.get('js/create/step_two/_date.tmpl.htm', function(templates) {

We then append and render the template using something like the following:

var item = {
day: weekday[dateTime.getDay()],
pId: id,
dId: i,
date : dateTime.getTime()
//Add the template

Importantly jQuery templates have now been superseeded by JsRender:

The user is your friend…surely!?

Recently I’ve been encountering an increasing number of usability issues when visiting websites and accessing services and I feel it’s time to put a stop to these confusing and hard to use systems. When I visit a website I want to be able to get to the information quickly and easily but it never seems to be that easy, what I’m continually noticing is a trend of big companies with complex phone systems just trasferring that logic to their online offerings.

Don’t get me wrong, I’m a developer and often users are the enemy, they do things you don’t expect and end up with some mind boggling issues but I feel that is a good thing. What I’m talking about is the obscuring of information through complexity. I believe that simple is best and there has to be a better way!

Case Study One

Take the following example: I needed to cancel my home contents insurance policy due to a house move. This could have been a simple web form for me to send an enquiry and receive a confirmation call back however what I faced was this:

Claims Process

I continued to phone the correct number only to discover that they wanted me to key in only the numbers on my policy, when your policy number looks like the following ‘C12FQSK3D9D04B’ it becomes over complicated. What’s more, try doing that on a phone that goes dark every time you put it up to your ear and you have a serious usability problem. I think there would be a much more streamlined way of doing this if you could request a call back or resolve this online.

Case Study Two

This one really annoyed me as the user as I was doing something I didn’t really want to do anyway, paying council tax. (It should be noted at this point that I actually have previous experience in developing council websites).

Upon entering the home page there is no mention of council tax apart from a small quick link half way down on the right which isn’t ideal as most website users ignore that area of the screen, so I clicked services. This page is just a series of links, but I found and clicked ‘pay your council tax’, where did this go you ask? Well to a page that describes paying your council tax! The link for paying is half way down contained in a block of text.
Text Block

This is shown again further down :
Block Two

At this point I’ve already clicked twice and I just want a big shiny button that says pay online but I as a user am expected to read six lines of text to work out what the little link with an exclamation mark actually does. My favourite part of this is that the second link takes you to another page describing online payments!

Following the second link through brings you to a page of links with this :


clicking this FINALLY takes me to the payments page. I’ve now clicked four times, had to scroll down twice, read an essay and lose the will to live all to find a single payment form.

Going the other route takes you to a third party system where you have to tediously navigate through and sign up etc to pay.

The point of all this is that websites and online systems need to really focus their design around the user and the activities that will be carried out on the site. The precursor to any website design and development work should be consultation on who will use the site and what their journey will be. Ultimately, we want every process to be simple and painless with as little room for error as possible. I’ve been involved in a number of projects where the design and development were created from a perspective of ‘this is what we want to show’ as opposed to ‘this is what the user will be looking for’ and I think we are seeing a shift in this mentality in website design and development. I believe that websites should be a service and as a such should be subject to the same efficiency critique as other services. The irony of this is that the result of a successful information site is that the user session time will be short! I can see another post on vanity metrics waiting to happen…

How to enable shortcodes for widgets in wordpress

This recently became a requirement of some simple work that I did creating a plugin that allowed a single piece of content to be added in wordpress then output using a shortcode. I added the shortcode to the text widget but it was simply output as a the shortcode itself. After some googling and hunting through forums I discovered the solution:

 add_filter('widget_text', 'do_myplugin_content_shortcode');

Or when in an object context use:

 add_filter('widget_text', array($this,'do_myplugin_content_shortcode'));

where the ‘do_myplugin_content_shortcode’ is the function that outputs the shortcode content.

JavaScript for Responsive Sites

When you have a responsive website there are many things that need consideration in terms of changes to the layout for each breakpoint. Often this can be done with pure CSS but occassionally there are instances where using CSS doesn’t quite manage to do what you need it to. Examples of this would be moving content blocks to different locations in the DOM or adding extra content based on the current screen size. I usually have a single script that I use to handle this functionality although I do sometimes do something a bit unusual, let me explain:

In our CSS we will see something like the following to define a breakpoint:

   //do something 

The regular jQuery equivalent of this would be

  //do something 
   if((document).width() &gt;= 480){

what I dislike about this is that we’re hard coding values into our javascript and once we have three or more breakpoints it can become confusing and leave us with multiple changes that need to be made if we want to update a breakpoint or add a new one. Another drawback of this is that on occcasion the measured width in JavaScript can be different to the width in the CSS at a certain point leading to the JavaScript functionality not executing when the CSS layout has been triggered which is something we don’t want.

I get around this using a div, that’s right a div. I like to add an empty div as the first element in the body and give it an id eg. responsive div. Then in the CSS I will have something like the following:




Then I can use the z-index as a guide to which breakpoint the layout is currently in, this will be the same in the CSS and JavaScript and gets around that issue. This approach also means that the breakpoint value can be changed in the CSS without the JavaScript needing to be modified.

The following is a real life example of how I’ve used this in practice.

var previousIndex = 0;
var zIndex = parseInt($('#responsivediv').css('z-index'));

* On Resize, respond as appropriate
$(window).resize(function () {
  //Get the zindex and the previous
  var viewLevel = parseInt($('#responsivediv').css('z-index'));

  //If we passed a breakpoint
  if (previousIndex != viewLevel) {
    for (var i = 0; i &lt; mItems.length; i++) {
    previousIndex = viewLevel;

An example of one of the items in the MItems array would be a carousel that needs to be paused when the user is in mobile view as it has been restyled as a list. This would look like the following (using an object oriented approach to JavaScript)

var Carousel = {
  exists: false,
  Init: function (level) {
    this.exists = $('.carousel').length &gt; 0 ? true : false;
  Resize: function (viewLevel) {
    //It's broke so return
    if (!this.exists) {
      return false;

    //Disable the carousel in responsive.
    if (viewLevel === 0) {
      if (!$('.carousel').hasClass('paused')) {
        //Pause the carousel
    } else {
      if ($('.carousel').hasClass('paused')) {
        //Pause the carousel

Wrapping Tables

One other thing I commonly include in my Javascripts is a wrapper around all tables that just adds a horizontal scroll in the mobile view. I usually achieve this using the following code.

$('table').each(function () {
  $(this).css('min-width', '500px');
  $(this).wrap('&lt;div class="tablewrapper" style="width:100%; overflow:auto;"&gt;&lt;/div&gt;');

I feel that this approach to responsive JavaScript greatly simplifies the process and allows for an inter connectivity between the JavaScript and CSS that you don’t get when using regular methods for breakpoints.

Simple CSS image Zooming

Recently I’ve see a rise in the effect of an image zooming when the user hovers over it. This movement provides feedback to the user and the added movement should improve engagement.

I had a little look into this and it can be achieved with very few lines of code. An example of the effect is shown below.

How it’s done

The html is structured as follows:

<code>&lt;div id=&quot;bgzoom&quot; style=&quot;width:300px; height:225px;&quot;&gt; 
 &lt;a style=&quot;background-image:url('');&quot;&gt;&lt;/a&gt; 

Obviously you could have all of the styles in an external stylesheet but this is often a little impractical when using a CMS and allowing the admin to modify the background images.

The CSS is output as follows :

#bgzoom a{
     background-position:center center;
     -webkit-transition: all 0.5s ;
     transition:all 0.5s;
#bgzoom a:hover{
    transform: scale(1.15,1.15); 
     -webkit-transition: all 0.5s ;
     transition:all 0.5s;

The key element here is the transform function which scales the anchor tag by 115% in the x and y directions. The overflow on the parent tag takes care of any overflow caused by this and creates a nice zoom effect. I have applied a transition to make the whole thing appear smooth.

Scaling with background images IE8

Occasionally you may have the need to make some parts of a reponsive site work in IE8 as painful as that is. Often background images are used in newer browsers and scaled to fit their element. In IE this doesn’t work that well so the following jQuery snippet allows you to get rid of the background image that has been set and replace it with an IE specific filter that should resolve this issue. This is best used when the background image has been set using inline CSS (which often happens in content managed sites)

           var image = $(this).css('background-image');  
           image = image.replace('url("',"").replace('")',"");                                             
           $(this).css('filter',"progid:DXImageTransform.Microsoft.AlphaImageLoader(src=" + image + ", sizingMethod='scale'");     
           $(this).css('-ms-filter',"progid:DXImageTransform.Microsoft.AlphaImageLoader(src=" + image +  ", sizingMethod='scale')");             

Combine this with my solution for detecting if the user is using IE 8 and a you have a useful solution.

 if (!$.support.leadingWhitespace) {
            if ($.browser.msie && parseFloat($.browser.version) <= 8) {
                var image = $(this).css('background-image');  
                image = image.replace('url("',"").replace('")',"");                                             
                $(this).css('filter',"progid:DXImageTransform.Microsoft.AlphaImageLoader(src=" + image + ", sizingMethod='scale'");     
                $(this).css('-ms-filter',"progid:DXImageTransform.Microsoft.AlphaImageLoader(src=" + image +  ", sizingMethod='scale')");             

Adding an External Link Icon using Font Awesome and JQuery

Sometimes you need to add an icon to your external links to mark them out as different to your regular site links. This makes sense in terms of usability as it stops users becoming suprised that they are taken away from your site on clicking the link. I recently worked on a site where one of the links read ‘University’ and was an external link. On the surface of it that would be difficult for a human user to differentiate as being an external link.

It can be an absolute maintenance nightmare and lead to massive code bloating if you try to add an icon after every external link using your server side language or CSS. I’ve seen it a few times and it’s caused hours of wasted development time and effort. This is why I rely on a javascript based solution as then when a change happens it only occurs in a single place rather than a few. Don’t get me wrong, it can be done on the server side or in the CSS but it’s my preference to make the user’s browser do the work for this.

I achieve this using jQuery and Font awesome to add a little icon after all external links. In my main script file, inside the standard $(document).ready function I add the following:


* InitExternal
* Initialise external links
var comp =;

$('a').each(function () {
  //Get the link
  var link = undefined === $(this).attr('href') ? '' : $(this).attr('href');
  if (link != '' &amp;&amp; link.indexOf(comp) &lt;= -1 &amp;&amp; link.length &gt; 0) {
    if ($(this).text().trim().length == 0 || link.indexOf('javascript(') &gt; -1) {

    if (link.charAt(0) != '/' &amp;&amp; link.charAt(0) != '#') {
       $(this).append('&lt;i class="fa fa-external-link external-link"&gt;&lt;/i&gt;');
       $(this).attr('target', '_blank');


The code analyses each a tag and checks for an href, without this there’s no point in continuing for that item. It then looks for whether the link has any inner content or whether it’s meant to invoke a javaScript function, if these cases match then it ignores that link. It then checks for invalid starting characters such as ‘#’ or ‘/’ . Finally it can add the icon and set the target to blank to mark the link as external. There may be permutations on your site where this doesn’t quite work, one such case is when the a tag is empty but has been used as an image box with a background image. In that case you could add


The output :
Exteral Link Icon

Detecting Internet Explorer using JavaScript

Sometimes in JavaScript you need to detect whether the current user is using IE8 or below as generally support should be maintained for the previous three versions of IE (my opinion) and therefore the user may need to be prompted that perhaps they aren’t getting the best experience.
The script below checks the user’s browser capability for leading whitespace see: ( and then checks the browser version. This is because firefox doesn’t seem to support leading whitespace in all versions so the browser version then needs to be checked.

 if (!$.support.leadingWhitespace) {
            if ($.browser.msie && parseFloat($.browser.version) <= 8) {
                alert('This website is best viewed in Internet Explorer 9 and above, please upgrade your browser for the best experience.');

In this example an alert is shown but you could easily add a custom stylesheet or perform some other useful function.