1 Security Audit / glms.org / public inspection

Your website is publicly displaying online-gambling content.

During a public inspection of glms.org, corePHP found Indonesian online-gambling spam injected directly into your pages. It is rendering to ordinary visitors, not only to search engines.


This document lays out exactly what we observed, why it matters for a physicians' membership association, and the steps to remove it and keep it gone. Everything below comes from public inspection only. No active scanning and no authenticated access were used.

Findings at a glance
Ref Severity Finding
01
Critical
Visible SEO spam injection on the homepage
An injected gambling heading, promotional text, and outbound links render to every visitor, not only to search crawlers.
02
Critical
Injection spans many core pages
The same class of spam appears across membership, events, staff, and program pages indexed by Google.
03
Critical
Brand and reputation exposure
A physicians' association is publicly hosting sports-betting and casino promotions under its own domain.
04
High
Weak maintenance posture
The site runs the default twentyseventeen theme and an aging Elementor and Event Calendar plugin stack.
05
High
Risk of a Google "this site may be hacked" flag
Injected content of this kind commonly leads to ranking loss and browser warnings if left in place.
Exhibit A / captured evidence glms.org homepage · captured Aug 3, 2026 · public inspection

Injected heading, rendered on the live homepage:

"Berkat Tuntunan SBOBET Situs Judi Online SBOTOP Menyediakan Beragam Kemenangan"

Beneath it, the page carries promotional copy for SBOBET and SBOTOP sports betting, along with "Slot Gacor" and "Slot Kamboja" casino terms. Two live outbound links were present on the page. They are reproduced here as inert, non-clickable text so this document links to nothing.

Indonesian-language keywords observed:

SBOBETSBOTOPJudi OnlineSlot GacorSlot Kamboja

Same class of spam observed on these indexed pages:

Register Events Calendar GLMS Staff Benefits MedCentral Media Inquiries DocTalks Spear Essay Contest
Platform note

The site is built on WordPress with Elementor, which is a sound and maintainable foundation. The concern is posture, not platform. With the default theme in place, an aging plugin stack, and an entry point that is not yet identified, a one-time cleanup alone will not guarantee the spam stays gone. Removal has to be paired with hardening and monitoring.

Why this matters

Reputation

Member and public trust

A medical society is judged on credibility. Betting and casino promotions under the GLMS domain undercut the trust members and the public place in the organization.

Search

Hacked-site flag and ranking loss

Google routinely flags pages carrying this content. A warning label in results and lost rankings reduce reach for legitimate programs and events.

Escalation

From spam to redirects and malware

A foothold that starts as spam is commonly upgraded to visitor redirects or malware, which then trigger browser warnings for anyone visiting.

Governance

Member data on the same platform

Membership records and member login live on the same WordPress install, so the compromise is a governance matter, not only a marketing one.

Recommended next steps

ImmediateContain and clean
  1. Remove the injected content across every affected page, sitewide.
  2. Reset credentials and enable two-factor authentication for all admin accounts.
  3. Update the theme and all plugins to current, supported versions.
  4. Request a Google Search Console review to clear any hacked-site status.
  5. Monitor for reinfection until the entry point is confirmed closed.
StrategicKeep it gone
  1. Rebuild on a hardened platform using WordPress and Elementor with a current theme.
  2. Add a web application firewall in front of the site to block injection attempts.
  3. Enable malware scanning with alerts so any recurrence is caught early.
  4. Set a maintenance cadence so the theme and plugins never fall out of support again.
2 Proposed website / clean, monitored, professional

A trustworthy home for the Society, built to stay clean.

A professional association site that carries the work GLMS actually does, on a secure platform with monitoring built in from the first day. Every member-facing tool the current site needs, without the exposure.

Today, in public

The compromised site

  • Gambling spam visible to every visitor on the homepage and beyond.
  • Injected content indexed across membership, events, and program pages.
  • Default theme, aging plugins, no firewall or malware monitoring.
  • Exposed to a hacked-site flag and browser warnings.
Proposed

A clean, monitored platform

  • No injected content. Only the Society's own pages and programs.
  • HTTPS, a web application firewall, and active malware monitoring.
  • Staff-managed content in Elementor, with a supported theme and plugins.
  • Built so a compromise is far harder, and caught early if attempted.

What the new site carries

M

Membership

Join and renew, benefits, and a clear path to Member Login.

F

Physician Finder

A searchable roster and finder for members and the public.

E

Events calendar

A dependable calendar for DocTalks, events, and Society dates.

P

Program pages

Wear The White Coat, the Physician Wellness Program, and Advocacy.

L

Louisville Medicine

A proper home for the Society's publication and archives.

S

Secured and monitored

WordPress and Elementor with HTTPS, a firewall, and malware scanning.

The proposed homepage, in your own brand.

Not a generic template. This concept uses the Society's real fleur-de-lis logo, brand colors, and the current Louisville Medicine cover, on a clean and secure platform.

Open the full design

Design concept prepared by corePHP. Real GLMS logo, brand colors, and current publication cover shown. Sample content stands in for events and copy.

We build it, YOU own it.

You own the site outright, with no strings attached. The platform, the content, and the accounts stay with the Society. corePHP builds it and hands it over, cleanly.

3 Proposal and approval

Choose a scope. Approve when ready.

Two clear scopes, and a combined option that does both in one engagement. No payment is collected on this page. Approving records your selection and produces a signed PDF you can keep and circulate.

Scope A
$2,500
Security Fixes
  • Remove injected content across every affected page.
  • Reset credentials and enable two-factor authentication.
  • Update the theme and all plugins.
  • Request a Google Search Console review.
  • Monitor for reinfection during cleanup.
Scope B
$5,000
New Website
  • Clean rebuild on secure WordPress and Elementor.
  • Membership, Physician Finder and roster, events calendar.
  • Program pages and a home for Louisville Medicine.
  • HTTPS, web application firewall, malware monitoring.
  • Staff-managed content. You own it outright.
Recommended Scope A + B
$7,500
Both, at a combined rate
  • Everything in Security Fixes, done first to contain the issue.
  • Everything in New Website, on a hardened, monitored platform.
  • One engagement, one team, one clear handover.
  • The surest path to remove the spam and keep it gone.

Approval and signature

No payment collected
Select scope *
Prepared by corePHP · Ashley Blakemore
Approved and signed
Scope
Amount
Approved by
Title
Email
Date
Signature
OrganizationGreater Louisville Medical Society
Your contact at corePHP
Ashley Blakemore

ashley@corephp.com

(269) 979-5582

corePHP LLC
Creating Effective Digital Solutions.

245 Michigan Ave West
Battle Creek, MI 49017

corephp.com