Your WordPress site was hacked. Here's how we take it back.
Defaced pages, spam redirects, a Google Safe Browsing warning, or a hosting account suspended for abuse — we remove the infection, find how it got in, and rebuild the site to a state that doesn't get reinfected in a week.
If any of this sounds familiar, don't wait on it
WordPress compromises rarely announce themselves cleanly. They usually look like one of these.
Defacement or spam content
Pages showing content you didn't publish, injected links to unrelated sites, or a completely replaced homepage.
Blacklisted or flagged
Google Safe Browsing warnings, "this site may be hacked" in search results, or your host disabling the account for abuse complaints.
Strange redirects or new admins
Visitors landing on pharma or gambling spam, unfamiliar WordPress admin accounts, or scheduled tasks you didn't create.
Not just "delete the malware" — a proper incident response
Removing a visible symptom without finding the entry point just buys you a repeat infection. Here's the full process.
-
Contain and snapshot
We take the site offline or isolate it if needed, and snapshot the current state before touching anything — so nothing is lost and we have evidence of what changed.
-
Identify the entry point
Core file comparison against the official WordPress repository, plugin and theme integrity checks, and a review of access logs to find the actual vulnerability — an outdated plugin, a leaked credential, a vulnerable form handler, or an exposed
wp-config.php. -
Remove the infection completely
Backdoors, injected code in theme/plugin files, rogue admin users, malicious cron jobs, and database-level injections (spam links, redirect scripts) — cleared, not just hidden.
-
Restore and verify
Clean content restored from backups or rebuilt where needed, every plugin and theme updated, and the site checked end-to-end before it goes back live.
-
Get you off blacklists
Google Safe Browsing and Search Console review requests filed, and any host-side suspension addressed directly with your provider.
-
Harden against reinfection
Web application firewall rules, file-integrity monitoring, login hardening, and a patching schedule so this doesn't happen again in a month.
Hardening, not just a one-time fix
A cleaned site with the same weak points will get reinfected. Every recovery includes hardening so the same door doesn't open twice.
- Admin login protected against brute-force attempts
- File integrity monitoring for unauthorised changes
- Web application firewall rules for known WordPress attack patterns
- Plugin and core update schedule, so known vulnerabilities get patched
- Offsite backups configured, so a future incident isn't a full rebuild
Common entry points we find
| Vector | How it's exploited |
|---|---|
| Outdated plugins | Known CVEs left unpatched |
| Weak admin credentials | Brute-force or credential reuse |
| Nulled themes/plugins | Backdoors bundled in "free" copies |
| Exposed wp-config.php | Server misconfiguration |
| Vulnerable contact forms | File upload or injection flaws |
Frequently asked
Can you clean the site without taking it offline?
Usually yes, though if the infection is actively serving malware to visitors or is under a Safe Browsing warning, we'll recommend a short controlled outage rather than leaving it exposed.
Do you need my hosting or WordPress access?
We'll need hosting control panel or SSH access, and a WordPress admin login. If you've lost access as part of the compromise, we can usually work with your host to recover it.
What if I don't have a clean backup?
We can still clean the site in place by identifying and removing malicious code directly, though a recent clean backup makes the process faster and more certain.
How do you stop it from happening again?
Every recovery ends with hardening — firewall rules, monitoring, and a patch schedule — specifically targeting the vulnerability that let the attacker in the first time.
Tell us what you're seeing — we'll tell you what it means
The first assessment is free. Describe the symptoms and we'll give you a straight read on what's happened and what it takes to fix.