One-time project · Security
A red warning in Chrome, spam pages appearing on your domain, or an email from your host about malicious files. It is stressful, it is usually not your fault, and it is fixable. We clean the site, get the warnings lifted, and close the door the attacker came through.
Most hacked WordPress sites are not targeted. They are found by automated scanners looking for an outdated plugin with a known hole, and the same script infects thousands of sites in one pass. Yours was one of them. That is worth knowing, because it means the fix is systematic rather than mysterious.
Cleanup means finding every infected file — not just the obvious ones — removing the backdoors that let the attacker return, and then fixing the weakness that was used in the first place. Cleaning without hardening means being hacked again within weeks, which is why we do not offer one without the other.
If Google has flagged the site, we submit it for review after cleanup so the warning is lifted. That review is Google’s process and typically takes a day or two.
Every infected file removed, then the weakness that let it in closed
Scope
Everything below is part of the project. Nothing is added to your invoice without a written quote you have approved first.
Not included: Recovering content that the attacker deleted and that was not in any backup. Ongoing monitoring beyond 30 days, which is part of a care plan. Cleaning other sites on the same hosting account, which are quoted individually because they are usually also infected.
How it works
The site is put into maintenance mode if it is actively serving spam or malware, and a full backup of the infected state is taken as evidence and as a safety net.
File scan, database scan, and a manual review of the places automated tools miss: theme functions files, upload folders, wp-config, scheduled tasks.
Infected files cleaned or replaced from clean sources. Core, plugins and themes reinstalled from official versions rather than patched.
The entry point — almost always an outdated plugin or a weak password — is fixed. Then general hardening so the next scanner finds nothing to use.
Google review requested if flagged. You receive a written report and a short list of what to do differently, which is usually just: keep it updated.
What we need from you
Typical timeline: Usually started same business day; 1–3 business days to complete. Your written quote states the actual date for your project.
Pricing
Base scope: One WordPress site: full file and database scan, malware and backdoor removal, core and plugin reinstall, password resets, hardening, written report, 30 days of monitoring.
Anything beyond the base scope is priced from the add-on list, and your written quote shows the line items and one total. That total is what is charged — nothing more. No payment is taken on this website: once you approve the quote, a secure Stripe payment link is sent by email. US clients are billed in USD; Canadian clients in CAD or USD by agreement, plus applicable GST/HST.
Questions
Contact us with the details and we will usually start the same business day. A hacked site gets worse the longer it runs — more spam indexed, more visitors warned off — so we treat it as urgent.
Sometimes that is the honest answer, and we will tell you if it is. But most sites are worth cleaning, because the content and the domain history are worth more than a fresh install. Deleting also does not fix the cause, so a fresh site with the same weak password gets hacked the same way.
Almost always an outdated plugin with a public vulnerability, or a password that was guessed. Rarely anything personal. The report will name the likely entry point where we can identify it.
Not through the same door. Sites get re-infected when the cause is not fixed or when a backdoor is missed, and both are what the hardening and 30-day monitoring are for. After that, keeping plugins updated is most of the job.