Skip to content
Hacked site recovery

Hacked WordPress site? Let's get it back.

We remove the malware, close the entry point, get your site off Google's blocklists and hand you a report with evidence of everything. A typical case takes 24 to 72 hours from the moment we have access.

Is your site down or flagged by Google right now? We respond faster on WhatsApp.

The problem

How to tell if your site has been hacked

Maybe Google is already showing a red “Deceptive site ahead” screen before anyone reaches your page. Maybe your site redirects to casinos or pharmacies, your host suspended the account, or a customer emailed to say “your website has a virus”. The symptom varies; the effect is the same: your site is working against you, and every passing hour costs sales, rankings and trust.

Typical signs of a hacked WordPress site:

  • Google flags your site with “This site may be hacked” or a red security warning.
  • Your site redirects visitors somewhere else: gambling, pharmacies, adult content.
  • Pages, links or text in other languages appear that you never created - sometimes visible only to Google, not to you.
  • Your host suspended the account, or notified you about spam being sent from your domain.
  • You can’t get into the admin panel, or you see administrator accounts you don’t recognize.
  • The site is slow, throwing errors, or simply won’t load.

Two things worth knowing before you go on. First: this is not necessarily your fault. 91% of new WordPress vulnerabilities are in plugins, and the attacks are run by bots probing thousands of sites an hour - your site wasn’t chosen, it was found. Second: deleting files or reinstalling blindly usually makes things worse, because it destroys the evidence of how they got in and can leave the backdoor untouched. If you can, don’t touch anything else and write to us: the diagnosis tells you exactly how bad it is before you have to decide anything.

What's included

The full scope, no fine print

Every item is concrete, verifiable work. If something doesn't apply to your case, we say so in the diagnosis - not in an invoice.

  • Diagnosis of the real scope of the infection: files, database and user accounts
  • Forensic copy of the infected site before anything is touched - it preserves the evidence and gives us a way back
  • Malware removal across the WordPress core, themes, plugins and the database
  • Search for and removal of backdoors and rogue administrator accounts
  • Identification and closure of the entry point: a vulnerable plugin, stolen credentials or an exposed configuration
  • Full credential rotation: WordPress, database, SFTP and the security keys (salts) in wp-config.php
  • Core, theme and plugin updates to versions with no known vulnerabilities
  • Review request to Google Safe Browsing and Search Console to get the red warning lifted
  • Coordination with your hosting provider to lift the suspension, if your account was shut down
  • Basic post-cleanup hardening: two-factor authentication (2FA), correct file permissions and a web application firewall (WAF) where your hosting allows it
  • Final verification of the cleanup with independent external scanners
Process

How we do it

Steps in order, with honest timelines. When a deadline depends on a third party, we say so.

  1. 01

    Diagnosis

    With access to your site and your hosting we assess the scope of the infection, then give you a fixed quote and a concrete timeline. Nothing starts without your go-ahead.

    2–6 hours from the moment we get access
  2. 02

    Containment and forensic copy

    We save an exact copy of the infected site - the evidence of how they got in - and, if your site is actively harming its visitors, we put it into maintenance mode to stop the damage.

    about 1 hour
  3. 03

    Cleanup and lockout

    We remove the malware from files and database, pull out backdoors and rogue users, close the entry point and rotate every credential.

    24–48 hours depending on the infection
  4. 04

    Verification and blocklist removal

    We verify the cleanup with external scanners and request Google's review to get the warning lifted. That part of the timeline is up to Google - and we tell you so, plainly.

    an additional 24–72 hours if your site was flagged
  5. 05

    Report and handover

    You get your site back up and running, plus a technical report: what we found, how they got in, what was cleaned and what we recommend so it doesn't happen again.

    at the close of the job
Deliverables

What you get at the end

The job doesn't end with "done" - it ends with something you can read, keep and verify.

  • Your site clean and running, verified with external scanners
  • The Google review handled for you, and the unsuspension coordinated with your hosting provider if they shut the account down
  • A technical report with evidence: what was found, how they got in and what was fixed
  • A full set of new credentials, delivered through a secure channel
  • Concrete, prioritized recommendations so this doesn't happen twice
  • A 30-day guarantee: if the same infection comes back, we clean it again at no cost
Questions

Frequently asked questions

How much does it cost to recover a hacked site?

It depends on the scope of the infection - which is why the first step is a diagnosis. With it, you get a fixed quote before we start: no open-ended hourly billing, no surprises at the end.

What if I can't even log in to my own site?

It happens all the time: attackers change passwords, and some hosts suspend the account the moment they detect malware. We can work from your hosting or domain access instead - and if you don't have those at hand either, we'll walk you through recovering them.

Will my Google rankings take a hit?

If you act quickly, the impact is usually recoverable. The longer your site stays flagged or redirecting spam, the more ground it loses - which is why the Google Safe Browsing and Search Console review is part of the service, not an extra.

What if the site gets hacked again after the cleanup?

The cleanup includes a 30-day guarantee: if the same infection reappears, we clean it again at no cost. And because security is a process rather than a one-off event, you get concrete recommendations at handover - if you'd rather have us manage them for you, that's what the monthly plans are for.

Recover my site

Tell us what's going on with your site and we'll reply within one business day. The diagnosis gives you a fixed quote before anything starts.

Would you rather this never happened again?

The monthly plans include continuous monitoring, backups and incident response - the managed version of the recommendations in your report.

View plans