One-time project · Security

Hacked site cleanup: get it clean, get it off the blacklist, keep it that way.

A red warning in Chrome, spam pages appearing on your domain, or an email from your host about malicious files. It is stressful, it is usually not your fault, and it is fixable. We clean the site, get the warnings lifted, and close the door the attacker came through.

Most hacked WordPress sites are not targeted. They are found by automated scanners looking for an outdated plugin with a known hole, and the same script infects thousands of sites in one pass. Yours was one of them. That is worth knowing, because it means the fix is systematic rather than mysterious.

Cleanup means finding every infected file — not just the obvious ones — removing the backdoors that let the attacker return, and then fixing the weakness that was used in the first place. Cleaning without hardening means being hacked again within weeks, which is why we do not offer one without the other.

If Google has flagged the site, we submit it for review after cleanup so the warning is lifted. That review is Google’s process and typically takes a day or two.

Cleaning the site without closing the door it came through is a two-week fix.
REMOVED HARDENED

Every infected file removed, then the weakness that let it in closed

Scope

What’s included in the price.

Everything below is part of the project. Nothing is added to your invoice without a written quote you have approved first.

  • Full scan of every file and the database, not just the plugin folder
  • Malware, injected code, spam pages and backdoors removed
  • Core WordPress files replaced with clean copies
  • Every plugin and theme updated or replaced; abandoned ones removed
  • All passwords reset: admin accounts, database, FTP and hosting
  • Unknown admin users and rogue scheduled tasks deleted
  • Security plugin installed and configured, with file-change alerts to your email
  • Login protection: attempt limits, the default admin username removed
  • File permissions corrected and PHP execution blocked in upload folders
  • Google Safe Browsing and Search Console review requested if the site was flagged
  • A plain-English report of what was found and what was changed
  • 30 days of monitoring and correction — if it comes back in that window, we deal with it

Not included: Recovering content that the attacker deleted and that was not in any backup. Ongoing monitoring beyond 30 days, which is part of a care plan. Cleaning other sites on the same hosting account, which are quoted individually because they are usually also infected.

How it works

Step by step.

Contain

The site is put into maintenance mode if it is actively serving spam or malware, and a full backup of the infected state is taken as evidence and as a safety net.

Find everything

File scan, database scan, and a manual review of the places automated tools miss: theme functions files, upload folders, wp-config, scheduled tasks.

Clean and replace

Infected files cleaned or replaced from clean sources. Core, plugins and themes reinstalled from official versions rather than patched.

Close the door

The entry point — almost always an outdated plugin or a weak password — is fixed. Then general hardening so the next scanner finds nothing to use.

Lift the warnings and report

Google review requested if flagged. You receive a written report and a short list of what to do differently, which is usually just: keep it updated.

What we need from you

Four things, and we can start.

Access, urgently
Hosting control panel and WordPress admin, or whatever you can still get into
What you saw
The warning, the email from your host, the spam page — screenshots help
Backups
Any backup you have, even old, in case content needs restoring
Other sites
Whether anything else lives on the same hosting account

Typical timeline: Usually started same business day; 1–3 business days to complete. Your written quote states the actual date for your project.

Pricing

Defined scope, defined price.

From $300
USD · one-time · for the base scope below

Base scope: One WordPress site: full file and database scan, malware and backdoor removal, core and plugin reinstall, password resets, hardening, written report, 30 days of monitoring.

Anything beyond the base scope is priced from the add-on list, and your written quote shows the line items and one total. That total is what is charged — nothing more. No payment is taken on this website: once you approve the quote, a secure Stripe payment link is sent by email. US clients are billed in USD; Canadian clients in CAD or USD by agreement, plus applicable GST/HST.

Add-ons, priced up front

Database-level infection$150
Each additional site on the same hosting account$150
Google Safe Browsing / Search Console review submission$60
Content restore from your backup$90
ExampleTwo sites on one account, one with a database infection: $300 + $150 + $150 = $600.

Questions

Things people ask before booking this.

How quickly can you start?

Contact us with the details and we will usually start the same business day. A hacked site gets worse the longer it runs — more spam indexed, more visitors warned off — so we treat it as urgent.

Should I just delete everything and start over?

Sometimes that is the honest answer, and we will tell you if it is. But most sites are worth cleaning, because the content and the domain history are worth more than a fresh install. Deleting also does not fix the cause, so a fresh site with the same weak password gets hacked the same way.

Why was I hacked?

Almost always an outdated plugin with a public vulnerability, or a password that was guessed. Rarely anything personal. The report will name the likely entry point where we can identify it.

Will it happen again?

Not through the same door. Sites get re-infected when the cause is not fixed or when a backdoor is missed, and both are what the hardening and 30-day monitoring are for. After that, keeping plugins updated is most of the job.

Scroll to Top