Emergency response

malware removal.

Your site got hacked. We’ll get it back, and lock it down so it doesn’t happen twice.

[Where]

Remote, wherever you’re hosted

[Who]

You don’t need to have been a client

Warning signs

How you know it’s happening.

Most owners find out from a customer, or from Google, rather than from the site itself. Any one of these is enough to call us.

Google is warning people

A red interstitial before your site loads, or a “this site may be hacked” label under your search result.

Pages you didn’t write

Usually pharmaceuticals, replica goods or casinos, often only visible to search engines and not to you.

Redirects on mobile only

The site behaves normally on your laptop and sends phone visitors somewhere else entirely.

Admin users you don’t recognise

New accounts with administrator rights, or your own password no longer working.

The host suspended you

Often the first signal: an email saying outbound spam or resource abuse was detected.

It got slow, suddenly

Someone else’s traffic is running through your server. Mining and spam are not free.

Start here.

Send us the URL and what you’re seeing. We’ll scan it and tell you what we’ve found before you commit to anything.

  • We scan before we quote
  • You hear what we found in plain words
  • You don’t have to be an existing client

The process

What we actually do.

In order. You get told what we found at every step, in plain words, not a scanner report.

Scan and confirm

We take a full copy of the site and database, then compare every core, theme and plugin file against a known-good version. That tells us what was changed and roughly when.

Contain it

The site goes behind a holding page if it’s serving anything harmful, so visitors and Google stop seeing it while we work. Your email and hosting keep running.

Restore, or clean

If there’s a clean backup from before the intrusion, restoring is faster and safer than picking malware out by hand. When there isn’t, we remove the injected code file by file and rebuild what was overwritten.

Close the door

We look for how it got in: an outdated plugin, a reused password, a stale admin account, or file permissions that let PHP write to itself. Server logs don’t always go back far enough to say for certain, so we close every likely door, not just the one we suspect.

Rotate everything

New passwords and keys for WordPress admins, the database, hosting, SFTP and any API credentials that were sitting in the config file.

Get you un-flagged

We submit the site for review with Google Search Console and any blocklist that picked it up, then watch it for a fortnight to be sure nothing reappears.

Hardening

Then we lock it down.

Cleaning a site that stays open the way it was gets you a second call in a month. Hardening is part of the job, not an upsell.

No file editing from the browser

Disabling the theme and plugin editors removes the easiest way to run code with a stolen admin login.

Sensible file permissions

Nothing writable that doesn’t need to be, and PHP execution blocked in the uploads folder.

Updates that actually happen

Core, plugins and themes on a schedule someone is accountable for, with a staging copy to test against.

Backups you can restore

Off-server, versioned, and tested by restoring one. An untested backup is a guess.

Fewer ways in

Removing abandoned plugins, unused themes and dormant admin accounts. Most sites are carrying years of them.

Login protection

Rate limiting, two-factor for administrators, and a login URL that isn’t the first thing every bot tries.

What it costs

A fixed number, after the scan.

Most single-site cleanups land in the same range, and we quote it before we start. If the site turns out to be beyond saving we’ll say so and rebuild instead — you won’t pay us to keep digging.

Afterwards

Contact

Tell us what’s broken.

Send the URL and what you’re seeing. We’ll scan it and tell you what we found before you commit to anything.

    I need