Your WordPress site is hacked. Here’s what to do.

Don’t panic, and don’t start deleting things. Email us with HACKED in the subject line through our contact page, describing what you’re seeing, and we’ll take responsibility for the rest.

Three things to do before you touch anything.

First, don’t delete files, plugins or the whole site hoping that fixes it, because every file the attacker touched is evidence we need to work out how they got in and whether they’re still inside somewhere else.

Second, don’t restore an old backup over the top of the hacked site, since that can destroy the very evidence a proper clean-up depends on, and if the same hole let them in once, it’ll let them in again.

Third, email us through our contact page with HACKED in the subject line, and tell us what’s happening: a browser warning, weird redirects, spam pages in Google, a suspended hosting account, anything unusual. We’ll ask for access and get started.

A proper clean-up, not a plugin scan and a prayer.

Isolate the site

We stop the bleeding first, restricting what an attacker can still reach while the investigation is under way.

Full malware scan and manual review

Automated scanning catches the known signatures, and we also read the code by hand, because the most damaging infections are written specifically to hide from scanners.

Clean everything

Core files, themes, plugins, the uploads folder and the database, inspected line by line wherever the infection could plausibly hide.

Remove backdoors and rogue admins

Attackers routinely plant hidden ways back into a compromised site, so we locate and remove every one, including administrator accounts nobody at your organisation created.

Rotate every credential

WordPress logins, database passwords, hosting and FTP access and API keys are all replaced, so nothing the attacker captured remains valid.

Patch the entry point

We identify exactly how the attacker got in and close that particular hole, rather than treating the symptom you happened to notice.

How the repair runs.

Access and assessment

You send hosting and WordPress access, and we assess the scope of the compromise and give you a fixed price before beginning any paid work.

Isolate and scan

We limit further damage, then run a full scan of every file and database table against known and unknown threats.

Clean and patch

We remove the malware, close every backdoor, patch the original entry point and rotate all credentials.

Harden and request review

We apply baseline hardening, then request a Google Search Console review if your site was blacklisted, and ask your host to lift any suspension.

Written report

You get a plain-English report on how it happened, what we did and what to change to stop it happening again.

A fixed price, quoted before we start.

Repair pricing is fixed once we have assessed the scope, which takes a look at the site rather than a form. You will know the number before any paid work begins, with no hourly surprises attached to a job you never chose to need in the first place. Email us and we’ll assess it.

Once it’s clean, keep it that way.

A repair fixes what is broken today, but on its own it does nothing about tomorrow’s attempt. Most sites we clean up were running outdated plugins, reused passwords or no monitoring whatsoever, which is precisely the combination that let the attacker in originally.

Two ways to close that gap: our WordPress security service adds hardening, a firewall and ongoing vulnerability monitoring, and our maintenance plans keep everything patched and backed up so you’re not relying on memory to stay safe.

  • We tell you plainly how the attacker got in, not a vague “keep everything updated”.
  • Every credential is rotated, so nothing left behind gives the attacker a second attempt.
  • Scanning for known malware patterns is AI-assisted, which counts when the clock is running and there are forty thousand files to read.

FAQ

Questions we get asked

How fast can you fix my site?

It depends on how deep the infection is, but we start the same day where possible and most straightforward clean-ups are finished within a day or two. A badly compromised site with multiple backdoors can take longer. We’ll tell you honestly once we’ve looked.

Will I lose data?

Usually not, because we work from your existing files and database rather than wiping the site, so your posts, pages, orders and media stay intact. If your host or a previous fix already deleted something, we’ll tell you exactly what’s missing.

Will Google unflag my site?

Once the malware is gone and the entry point is patched, we request a review through Google Search Console so the blacklist warning is lifted. That review is run by Google, not us, so we can’t set a fixed timeline, but we submit it the same day we finish the clean-up.

How did this happen?

Almost always through an outdated plugin or theme, a weak or reused password, or a vulnerable script left over from an old build. Our written incident report names the actual entry point we found, not a guess.

Will it happen again?

Not if the entry point stays patched and someone keeps the site updated. That’s what our WordPress security service and maintenance plans are for. A one-off repair fixes today’s problem; ongoing hardening stops the next one.

Can you help if my host has suspended my account?

Yes, and this happens often, because hosts commonly suspend sites automatically once a malware scan flags them. We can usually work with you to get the suspension lifted once we’ve cleaned the site, or work directly with your host’s abuse team if they need proof of the fix.

Do you need my hosting login?

Yes, along with WordPress admin access. We can’t clean files, check the database or patch the entry point without it. We rotate every credential we touch as part of the job, so you’re not left with the same passwords that let the attacker in.

WordPress

More WordPress services

All WordPress services →

Site compromised right now?

Email us with HACKED in the subject line and a link to the site. Tell us what you’re seeing: a warning page, strange redirects, spam in search results, a suspended host account, anything. We’ll reply as fast as we can and get to work.