24/7 WordPress & WooCommerce incident response

Malware removed. The way in closed. Usually the same day.

Most cleanup services delete the infected files and hand the site back. Then it comes back, because nobody looked for the door the attacker walked through. We find that door first.

2 hoursto first response
Same daytypical turnaround
$390fixed, one site

If we cannot clean it, you pay nothing.

Response time
We start within 2 hours during business hours.
Typical turnaround
A standard infection is cleaned the same working day.
Price
Fixed $390 for an emergency cleanup of one site.
If we fail
You pay nothing if the site cannot be cleaned.
Reinfection
Cleaned again free within 30 days on the recovery package.
Data
Posts, products, orders and customers are kept intact.

Is it actually hacked?

Eight things people notice first

Any one of these is worth checking the same day. Most of them are visible to your customers long before they are visible to you — a redirect hack, for instance, deliberately leaves logged-in administrators alone.

Google shows a red warning

“Deceptive site ahead” or “This site may harm your computer.” Traffic drops to almost nothing within hours.

Visitors get redirected

Mobile or first-time visitors land on pharma, casino or scam pages. Logged-in admins see nothing wrong.

Admin users you never created

New administrator accounts, often with a plausible name and a throwaway mail address.

Your mail stops arriving

The server is sending spam, so the IP gets blacklisted and order confirmations bounce.

Junk pages in Google

Search results full of pages you never wrote, often in Japanese or selling pills. Classic SEO spam injection.

Your host suspended the account

Sudden CPU spikes or an abuse report, and the host pulls the plug until the site is clean.

Files that were not there yesterday

Random PHP files in uploads, a modified index.php, or wp-config.php with an extra include at the top.

You cannot log in any more

Your password stopped working and the reset mail never arrives, because the attacker changed the admin address.

None of these, but something feels off? That is worth a look too. Infections that make money quietly are built not to be noticed.

Scan the site first

Free · no signup · 20 seconds

See what your site tells strangers

Ten passive checks against your home page and a handful of well-known WordPress paths. We read only what is already public — no logins, no forms, no probing. It is the same pass an automated scanner makes before deciding whether you are worth attacking.

Check your own site. We keep the score for ten minutes so a repeat check is instant, and nothing else.

How we clean

Copy first. Then find every foothold.

Hours are working hours from the moment we have access. A site that has been compromised for months, or several infected sites on one hosting account, takes two to three days rather than one.

  1. 0–1

    Triage and containment

    We take a full forensic copy first, then put the site behind maintenance mode if it is actively harming visitors. Nothing is deleted before it is copied.

  2. 1–3

    Find every foothold

    File integrity diff against clean WordPress, plugin and theme sources; database scan for injected scripts; review of users, scheduled tasks, must-use plugins and the uploads folder.

  3. 3–6

    Clean, not just delete

    Core, plugins and themes replaced from official sources. Custom code cleaned line by line so your site keeps working. Injected rows removed from the database.

  4. 6–8

    Close the way in

    The actual entry point gets fixed: the outdated plugin, the weak password, the leaked FTP key, the shared hosting neighbour. Every password and salt is rotated.

  5. 8–10

    Harden and de-blacklist

    Firewall, 2FA, least-privilege users, disabled file editing, offsite backups. If the site was flagged, we file and follow through the review requests with Google, McAfee, Norton and Yandex — included in Deep clean & recovery.

  6. 14–30 days

    We keep watching

    Daily scans and integrity checks — 14 days with Emergency cleanup, 30 with Deep clean & recovery. On the recovery package, anything that comes back in that window is cleaned again at no cost.

“Can’t a plugin do this?”

Partly. Here is the part it cannot.

We install a security plugin on every site we touch — they are good at what they do. They just cannot answer the one question that decides whether the infection comes back.

A security plugin

  • Matches files against known malware signatures
  • Blocks login attempts from addresses it recognises
  • Emails you when something looks wrong
  • Keeps a firewall rule set up to date
  • Cannot tell you which door was open
  • Cannot clean code it has never seen before

An engineer with access

  • Works out how the attacker actually got in
  • Reads custom code line by line instead of deleting the file
  • Finds injected rows in the database, not just in files
  • Checks scheduled tasks, must-use plugins and the uploads folder
  • Rotates every password, salt and API key that may have leaked
  • Files the blacklist reviews and follows them through
  • Tells you in writing what happened and what to change

In almost every case we investigate it is one of four things: an unpatched plugin, a weak or reused admin password, credentials leaked from a developer’s machine, or another infected site on the same hosting account. Until you know which, you are cleaning the symptom.

One minute, eight questions

How exposed are you?

The scan above sees the outside of your site. These eight questions cover the inside — the things that decide whether a break-in is a bad afternoon or a bad month.

    1. 1Is every admin account one you can name and reach today?

    2. 2Is two-factor authentication on for every administrator?

    3. 3Were core, plugins and themes updated in the last 30 days?

    4. 4Have you removed the plugins and themes you no longer use?

    5. 5Do you have an offsite backup you have actually restored?

    6. 6Is there a firewall in front of the site that blocks, not just logs?

    7. 7Is file editing disabled in the WordPress admin?

    8. 8Would you know within an hour if a file changed on the server?

    Pricing

    Fixed prices, defined scope

    One site per package. We quote before we start, and we never raise the price on work we have already begun — if the site turns out to be larger than the package, we show you the scope first and you decide.

    Emergency cleanup

    The site is infected and you need it clean today.

    $390one site, fixed price

    • Start within 2 hours on working days, within 4 at weekends
    • Full forensic copy before anything is touched
    • Malware removed from files and database
    • Entry point identified and closed
    • All passwords, salts and keys rotated
    • Plain-language report of what was found
    • 14 days of follow-up scans
    Most chosen

    Deep clean & recovery

    Blacklisted, reinfected, or the host has suspended you.

    $840one site, fixed price

    • Everything in Emergency cleanup
    • Blacklist removal: Google, McAfee, Norton, Yandex
    • Mail deliverability repaired — SPF, DKIM, DMARC
    • Search Console clean-up and reindex request
    • Full hardening pass included
    • 30 days of monitoring with alerts
    • Reinfection inside 30 days cleaned free

    Hardening

    Nothing is wrong yet, and you would like to keep it that way.

    $290one site, fixed price

    • Full security audit with a written report
    • Firewall set up and switched to blocking
    • 2FA and least-privilege user roles
    • Offsite backups, restored once to prove they work
    • File-integrity monitoring with alerts
    • Server, PHP and TLS configuration review
    • Handover call and a checklist for your team

    More than one site, or a multisite network? Tell us how many in the form and we will quote the set — it is cheaper per site, because the entry point is usually shared.

    What we stand behind

    Four promises — and your own arithmetic

    Cannot clean it? You pay nothing.

    If the site is damaged beyond cleaning we say so on day one and quote a rebuild instead. We do not bill for a cleanup we could not finish.

    Reinfected inside 30 days? We clean it again, free.

    Included with the recovery package. If it comes back in that window, we missed something — that is on us, not on you.

    Your data stays yours.

    Full copy before anything is touched. Posts, products, orders and customer accounts come through unchanged. Only the attacker’s files and accounts disappear.

    A report you can actually read.

    What was found, where it came in, what we changed, and what you should do next — in plain language, not a scanner dump.

    FAQ

    What people ask before they send the form

    Something not here? Ask it in the form — the reply comes from the engineer who would do the work, not from a sales desk.

    How quickly can you start?

    Within two hours during business hours, and usually within four outside them. A standard WordPress infection is cleaned and back online the same working day. A site that has been compromised for months, or one with several infected sites on the same hosting account, takes two to three days.

    How much does WordPress malware removal cost?

    An emergency cleanup of one site is a fixed $390. If the site is also blacklisted, sending spam or has been reinfected, the deep clean and recovery package is $840 and includes blacklist removal and 30 days of monitoring. Hardening a site that has not been hacked is $290.

    What if you cannot clean it?

    You pay nothing. In the rare case where a site is damaged beyond cleaning — usually an old install with no backups and modified core files — we say so on the first day and quote a rebuild instead. We do not bill for a cleanup we could not finish.

    Will I lose content, orders or customers?

    No. We take a full copy of files and database before touching anything, and we clean infected files rather than deleting them wholesale. Posts, products, orders and customer accounts stay exactly as they are. The only things that disappear are the attacker’s files and the accounts they created.

    Can I just use a security plugin instead?

    A plugin is good at spotting known malware signatures and at blocking future attempts, and we install one as part of every job. What it cannot do is work out how the attacker got in. If the entry point stays open — an outdated plugin, a leaked FTP password, a neighbouring site on the same account — the infection comes back within days, and the plugin reports it again.

    How do I get the Google warning removed?

    Google only lifts a Safe Browsing warning after a review, and a review only passes if the site is genuinely clean. We clean it, verify from an outside scanner, then file the review request from Search Console. Google typically clears the warning in 24 to 72 hours. We handle the same process for McAfee SiteAdvisor, Norton Safe Web and Yandex.

    What access do you need?

    SFTP or SSH, database access, and a WordPress administrator account. Hosting panel access helps if the server itself needs attention. Create the credentials fresh for us, and rotate or delete them when the job is done — we will remind you.

    How did the site get infected in the first place?

    In almost every case we investigate, it is one of four things: a plugin or theme with a known vulnerability that was not updated, a weak or reused administrator password, credentials leaked from a developer’s machine, or another infected site sharing the same hosting account. The report tells you which one it was in your case.

    Tell us what is happening

    An engineer reads this, not a bot.

    One minute to fill in. You get a reply with the next step and the access we need — and if the site is actively harming visitors, say so and it goes to the front of the queue.

    First reply within 2 hours in business hours
    Fixed $390 for a standard cleanup
    Nothing to pay if we cannot clean it
    Your content, orders and customers stay intact

    While you wait, do not reinstall WordPress and do not delete the infected files. It destroys the evidence we use to find how the attacker got in — and that is the part that stops it happening again.

    [email protected]Telegram · WhatsApp

    Your site

    What is happening?

    What are you seeing?

    Pick any optional

    Where should we reply?

    We never ask for passwords by email. When we start, you create fresh credentials and remove them when the job is done.