Your WordPress site is hacked. Here’s what to do.
Don’t panic, and don’t start deleting things. Email us with HACKED in the subject line through our contact page, describing what you’re seeing, and we’ll take responsibility for the rest.
Right now
Three things to do before you touch anything.
First, don’t delete files, plugins or the whole site hoping that fixes it, because every file the attacker touched is evidence we need to work out how they got in and whether they’re still inside somewhere else.
Second, don’t restore an old backup over the top of the hacked site, since that can destroy the very evidence a proper clean-up depends on, and if the same hole let them in once, it’ll let them in again.
Third, email us through our contact page with HACKED in the subject line, and tell us what’s happening: a browser warning, weird redirects, spam pages in Google, a suspended hosting account, anything unusual. We’ll ask for access and get started.
What we do
A proper clean-up, not a plugin scan and a prayer.
Isolate the site
We stop the bleeding first, restricting what an attacker can still reach while the investigation is under way.
Full malware scan and manual review
Automated scanning catches the known signatures, and we also read the code by hand, because the most damaging infections are written specifically to hide from scanners.
Clean everything
Core files, themes, plugins, the uploads folder and the database, inspected line by line wherever the infection could plausibly hide.
Remove backdoors and rogue admins
Attackers routinely plant hidden ways back into a compromised site, so we locate and remove every one, including administrator accounts nobody at your organisation created.
Rotate every credential
WordPress logins, database passwords, hosting and FTP access and API keys are all replaced, so nothing the attacker captured remains valid.
Patch the entry point
We identify exactly how the attacker got in and close that particular hole, rather than treating the symptom you happened to notice.
Process
How the repair runs.
Access and assessment
You send hosting and WordPress access, and we assess the scope of the compromise and give you a fixed price before beginning any paid work.
Isolate and scan
We limit further damage, then run a full scan of every file and database table against known and unknown threats.
Clean and patch
We remove the malware, close every backdoor, patch the original entry point and rotate all credentials.
Harden and request review
We apply baseline hardening, then request a Google Search Console review if your site was blacklisted, and ask your host to lift any suspension.
Written report
You get a plain-English report on how it happened, what we did and what to change to stop it happening again.
Pricing
A fixed price, quoted before we start.
Repair pricing is fixed once we have assessed the scope, which takes a look at the site rather than a form. You will know the number before any paid work begins, with no hourly surprises attached to a job you never chose to need in the first place. Email us and we’ll assess it.
Prevention
Once it’s clean, keep it that way.
A repair fixes what is broken today, but on its own it does nothing about tomorrow’s attempt. Most sites we clean up were running outdated plugins, reused passwords or no monitoring whatsoever, which is precisely the combination that let the attacker in originally.
Two ways to close that gap: our WordPress security service adds hardening, a firewall and ongoing vulnerability monitoring, and our maintenance plans keep everything patched and backed up so you’re not relying on memory to stay safe.
- We tell you plainly how the attacker got in, not a vague “keep everything updated”.
- Every credential is rotated, so nothing left behind gives the attacker a second attempt.
- Scanning for known malware patterns is AI-assisted, which counts when the clock is running and there are forty thousand files to read.
FAQ
Questions we get asked
How fast can you fix my site?
It depends on how deep the infection is, but we start the same day where possible and most straightforward clean-ups are finished within a day or two. A badly compromised site with multiple backdoors can take longer. We’ll tell you honestly once we’ve looked.
Will I lose data?
Usually not, because we work from your existing files and database rather than wiping the site, so your posts, pages, orders and media stay intact. If your host or a previous fix already deleted something, we’ll tell you exactly what’s missing.
Will Google unflag my site?
Once the malware is gone and the entry point is patched, we request a review through Google Search Console so the blacklist warning is lifted. That review is run by Google, not us, so we can’t set a fixed timeline, but we submit it the same day we finish the clean-up.
How did this happen?
Almost always through an outdated plugin or theme, a weak or reused password, or a vulnerable script left over from an old build. Our written incident report names the actual entry point we found, not a guess.
Will it happen again?
Not if the entry point stays patched and someone keeps the site updated. That’s what our WordPress security service and maintenance plans are for. A one-off repair fixes today’s problem; ongoing hardening stops the next one.
Can you help if my host has suspended my account?
Yes, and this happens often, because hosts commonly suspend sites automatically once a malware scan flags them. We can usually work with you to get the suspension lifted once we’ve cleaned the site, or work directly with your host’s abuse team if they need proof of the fix.
Do you need my hosting login?
Yes, along with WordPress admin access. We can’t clean files, check the database or patch the entry point without it. We rotate every credential we touch as part of the job, so you’re not left with the same passwords that let the attacker in.
WordPress
More WordPress services
-
Custom WordPress development
Custom themes, plugins and integrations, built with code or a page builder, whichever suits the job.
-
WordPress theme development
Custom block themes designed for your brand and built for editors to actually use.
-
WordPress plugin development
Bespoke plugins, REST endpoints, admin tooling and integrations with the systems you run.
-
WordPress hosting
Managed Australian hosting tuned for WordPress, with backups, updates and a human on call.
-
WordPress security
Hardening, monitoring and patching as an ongoing service, so you don't need repairs.
-
WordPress maintenance plans
Monthly care plans covering updates, security, backups, monitoring and small changes.
-
WordPress support
Help with sites we didn't build. Broken, inherited, half-finished or just neglected.
-
WordPress speed optimisation
Core Web Vitals, caching, images and database work that makes a slow site fast.
-
WooCommerce development
Online stores that load fast, convert and connect to the systems behind the counter.
-
WordPress migrations
Move hosts, move platforms or rebuild in place. No downtime, no lost rankings.
-
WordPress multisite
Networks of sites on one install: build, migrate, manage and keep them all updated.
-
Headless WordPress
WordPress as the CMS, a modern front end on top. Built and maintained as one system.
-
WordPress audit
A fixed-price technical audit with a written report you can act on, with or without us.
Engage
Site compromised right now?
Email us with HACKED in the subject line and a link to the site. Tell us what you’re seeing: a warning page, strange redirects, spam in search results, a suspended host account, anything. We’ll reply as fast as we can and get to work.