I've been tracking webspammers for a while, and I've discovered some spammers hacking other people's websites in order to serve up their spammy websites.
They often stash a file named read.php in some directory off the root. But I've also seen other php files used. Usually the files are not supposed to be there rather than altered files.
The spammers will then spam guestbooks etc with the URL's to those spammy files.
I'm not saying that's happened here or even will happen here.
But with this development (and most of this seems to have started in August this year), we as site owners need to be a lot more vigilant. And webhosts also should be more vigilant.