Skip to content

Hacked WordPress site? We’ll clean it and lock it down.

Redirects to spam, strange pages in Google, a “This site may be hacked” warning or a suspension notice from your host. We find the malware, remove it from your files and database, close the way in, and tell you in writing what we found.

  • Backups before anything changes
  • Fixed price, written scope
  • NDA on request
An example cleanup log. Each problem found on a hacked WordPress site is listed with its fix: a redirect rule, a backdoor in uploads, modified core files, hidden spam links, an unknown admin and an outdated plugin.
Site statusClean
  1. .htaccessMobile redirect ruleRemoved
  2. wp-content/uploads/cache.phpBackdoor in uploadsRemoved
  3. wp-includes/Core files modifiedReinstalled
  4. wp_postsHidden spam linksCleaned
  5. wp_usersAdmin nobody addedRemoved
  6. plugins/form-builderOutdated, known holeUpdated

Signs of a hackAny one is worth a look

Signs your WordPress site
has been hacked.

Most hacks are built to stay out of the owner’s sight, so the first clue often comes from a visitor, Google or your host. Any one of these is worth a proper look.

  • Visitors get sent elsewhere

    Your site redirects to spam, pharmacy or scam pages, often only on phones or from Google.

  • Google shows a warning

    “This site may be hacked” under your listing, or a red “Dangerous site” screen in Chrome.

  • Spam pages in search

    A site: search for your domain shows pages in other languages or for things you don’t sell.

  • Your host suspended the site

    Or emailed about malware, spam being sent from your account, or unusual server load.

  • Admins you didn’t add

    New administrator accounts, or passwords that suddenly stop working.

  • Files you don’t recognise

    PHP files in the uploads folder, or plugins and themes that changed on their own.

  • Your emails bounce

    Messages land in spam, or your domain turns up on an email blocklist.

  • The site is suddenly slow

    Pages crawl or time out, because the server is busy doing someone else’s work.

Seen one of these? Tell us what you’ve noticed and we’ll tell you what we’d check first.

Request a cleanup

What we doScan · Clean · Harden · Monitor

How we clean
a hacked site.

Malware rarely travels alone: there is usually a backdoor to get back in. We work through the whole site in order, so the cleanup holds.

  1. Scan. Back up, then look everywhere

    • A full backup of files and database before we change anything
    • Every file compared with clean copies of WordPress, your plugins and theme
    • The database searched for injected scripts, spam links and hidden users
    • Server logs reviewed, where your host keeps them, to find the way in
  2. Clean. Remove it at the source

    • Malware and backdoors removed from files and the database
    • Core, plugins and theme reinstalled from clean, official sources
    • Rogue admin users and unknown accounts removed
    • Spam pages and injected links taken out
  3. Harden. Close the way back in

    • Every password reset, with new WordPress keys and salts
    • Abandoned or vulnerable plugins updated or replaced
    • File editing turned off and file permissions tightened
    • Unused plugins, themes and old copies of the site removed
  4. Monitor. Clear the warnings, then watch

    • A review requested in Google Search Console once the site is clean
    • Spam URLs submitted for removal from Google’s index
    • A follow-up scan after the cleanup to check nothing came back
    • Ongoing checks, if you add a monthly support plan

What you getIn writing, at the end

A written report
of what we found.

At the end you get a short report in plain English, so you know what happened and what changed. It’s useful for your host, your team and your own records.

How they got in
The likely entry point, such as an outdated plugin or a reused password, and how sure we are.
What we found
Each infected file, database entry and account, and what it was doing.
What we fixed
What we removed, reinstalled, reset or replaced, and what we left alone and why.
What to do next
A short list of the changes that keep the site clean, in order of importance.

Agreed before we startEvery cleanup

  • Fixed price, written scope

    You see the scope and the price before we start. If we find more than expected, we tell you first.

  • NDA on request

    We sign it before you share any access, and keep what we see between us.

  • Yours at handover

    The site, the backups, the logins and the report are yours. We hand back every key.

AfterwardsHardening

Keep it from
happening again.

Most reinfections come from the same few gaps. We close these during the cleanup where your host allows, and a support plan keeps them closed.

  • Updates, tested first

    WordPress, plugins and theme kept current, and anything abandoned replaced.

  • Only the access people need

    Each person gets the role their work calls for, with as few administrators as possible.

  • Two-factor sign-in

    A second step for every admin login, so a leaked password isn’t enough.

  • A firewall in front

    We’ll suggest a web application firewall that suits your host, and help set it up if you want one.

  • Backups kept offsite

    Automatic backups stored away from your server, so a hacked host can’t take them too.

  • Monthly support

    A support plan keeps all of this up to date, from the people who cleaned the site.

    See support plans

How it runsTell us · Agree · Clean · Hand over

What happens
after you get in touch.

A hacked site is stressful. Here is what to expect, so you know what comes next at each point.

  1. Tell us.

    You

    Send the site address and what you’ve noticed. Warnings, emails from your host and screenshots all help. We aim to reply the same working day.

  2. Agree.

    Scope and access

    We send a written scope and a fixed price, then ask for hosting, WordPress and Search Console access. An NDA first, if you’d like one.

  3. Clean.

    Us

    We back up, scan, clean and harden, and keep you posted as we go. We aim to start the same working day you approve.

  4. Hand over.

    Report and next steps

    You get the report, new passwords in your hands and the Google review under way. Then you decide whether you want ongoing support.

Cleanup FAQ

Cleanup
questions.

Something else you’d like to check first? Email us and the person who’d do the cleanup will reply.

Will I lose any content?

We take a full backup of your files and database before we change anything. The cleanup removes malicious code, not your posts, pages or media. If an infected plugin or theme has to be replaced, we reinstall a clean copy and keep your settings where we can.

How do you stop it coming back?

We look for how the attacker got in, not only what they left behind, and close it: clean reinstalls, updates, new passwords and keys, removed accounts and tighter settings. A monthly support plan keeps the site updated and checked after that.

Do you need access to my hosting?

Yes. Malware lives in files and the database, so we need hosting or SFTP and database access as well as a WordPress admin login. We’ll tell you exactly what we need and why, and you can remove our access when we’re done.

What about the damage to my Google rankings?

Once the site is clean we request a review in Search Console, submit spam URLs for removal and check that your real pages can be crawled again. Rankings often recover once the warning is lifted, but how fast is up to Google, so we won’t promise a date.

Can you work under an NDA?

Yes. An NDA is available on request, and we sign it before you share any access.

How is the cleanup priced?

It’s a fixed price, agreed in writing before we start, based on the size of the site and how deep the infection goes. Starting prices for WordPress work and support plans are on our pricing page.

Tell us what you’re building.

A few lines about the project are enough. You’ll hear back from the people who’d do the work, with a fixed quote to follow. Rather talk first? Pick a time that suits you.

Book a free 30-min call

Opens the contact form