Hacked site cleanup & hardening

Cleaned, closed, and explained.

Injected redirects, spam pages in your search results, a red Google warning, a suspended hosting account. I remove the payload, close the way in, and give you a written account of how it happened — because a cleanup that does not answer that question is just a delay before the next one.

Engagement One-off. No monthly subscription.
Typical turnaround One to two working days
You receive Clean site, hardened config, written incident report

01SymptomsWhat you are probably seeing

The signs, and what they usually mean.

Visitors get redirected somewhere else

Typically only some visitors — from Google, on mobile, or on their first visit only. That selectivity is deliberate: it keeps the site looking normal to the logged-in owner while monetising everyone else. If your site looks fine to you but customers say otherwise, believe the customers.

Pages you never wrote are in Google

Search site:yourdomain.com and you find pharmaceutical listings, counterfeit goods or gambling pages. This is spam injection, and it is actively burning the search reputation you spent years building.

A red warning screen before your site

Google Safe Browsing has flagged the domain. Chrome, Firefox and Safari all use it, so this effectively takes you offline for most of the internet until the site is cleaned and reviewed.

Your host suspended the account

Usually because the server is sending spam or attacking other machines. Hosts will normally restore limited access for remediation if you ask, and will want evidence the problem is resolved before lifting it fully.

Administrator accounts you do not recognise

Or a legitimate account whose email address has quietly changed. This means persistence: they intend to come back, and cleaning files alone will not remove them.

02PositionWhy this is a one-off job

Why I don't sell you a monthly subscription.

Most of this industry is built on recurring security fees. That model works well for the vendor, and it is genuinely right for some sites — large WooCommerce stores, membership platforms, anything holding payment data. For the average business site, it is selling insurance against a problem that was caused by configuration.

In my experience the entry point is almost always one of three things: a plugin or theme left unpatched against a publicly known vulnerability, an administrator or FTP password that was weak or reused, or a shared hosting account where a neighbouring site was breached first. None of those are solved by a monthly fee. All three are solved by fixing the specific thing and knowing what to keep updated.

So the deliverable here is a clean site, a closed entry point, and a document that tells you which of those it was. If after reading it you decide you do want ongoing monitoring, I will tell you honestly which tools are worth the money — including ones I do not sell.

If your site holds card data or personal data at any scale, do not treat this page as security advice. Get a proper audit, and treat a compromise as a notifiable incident until you have confirmed otherwise.

03ProcessGenuinely a sequence

How a cleanup runs.

01

Preserve the evidence

Full copy of files and database before anything is touched. Deleting the malicious code first feels productive and destroys the trail that shows how they got in.
02

Find every payload, not the obvious one

Core files compared against official checksums, themes and plugins diffed against clean copies, plus the places people forget: scheduled tasks, the options table, uploads and .htaccess.
03

Close the entry point

Patch or remove the vulnerable component, rotate every credential involved, remove unauthorised accounts, and correct file permissions. Cleanup without this step buys you about a week.
04

Harden what is left

Sensible server configuration, disabled file editing in the admin, restricted PHP execution in uploads, and the updates that were overdue. Configuration, not another plugin.
05

Get you delisted

Verify the site is clean, then submit the review through Google Search Console and deal with your host's abuse team. Google sets the timing; it is usually a few days.
06

Write it up

What was found, where, how they most likely got in, what I changed, and what you need to keep an eye on. In plain English, for a non-technical reader.

04QuestionsAsked often, answered plainly

Things people ask when this happens.

Can I just restore a backup?

Often not, and it is the most common route to being reinfected within days. A backup returns the site to a point in time — but if the way in was an outdated plugin, that plugin is in the backup too. Worse, most people do not know when the compromise actually happened, so the backup they pick frequently already contains it. Restoring is a useful step, never the whole job.

How did they get in?

That is the question worth paying for, and you get a written answer. Usually a known vulnerability in an unpatched plugin or theme, a compromised administrator or FTP password, or a shared host where another account was breached first. If I genuinely cannot determine it I will say so plainly rather than invent a story, and harden everything reachable instead.

How long does it take?

Most straightforward cases are done inside a working day or two. What extends it is a site compromised for months, several separate infections layered on top of each other, or an entry point in the hosting account rather than in WordPress. You get a realistic estimate after I have looked, not before.

Will the Google warning be removed?

I clean the site, verify it, and submit the review request through Search Console. Google controls the timing — typically a few days once the site is genuinely clean. Anyone promising a specific date is guessing on your behalf.

My host suspended the account. Can you still help?

Yes, and it happens often. Hosts will usually restore limited access for remediation on request, or provide a copy of the files and database. I have worked with the major hosts' abuse teams and can tell you what they will want to see before lifting the suspension.

Should I take the site offline right now?

If it is actively redirecting customers or serving spam, yes — a maintenance page limits the reputational damage while the cleanup happens. Take a full copy of the files and database first, before changing anything. That copy is what makes it possible to work out how they got in.

Do I need a monthly security plan afterwards?

Usually not, for an ordinary business site. Most compromises are configuration and habit problems that a subscription does not fix. Sites holding payment or personal data are a different conversation, and I will say so if yours is one of them.

If this is happening now

Send me the URL and what you are seeing.

Include your host and whether you still have admin access. I answer the same working day, IST. Once the site is clean, the speed work is often worth doing while everything is already open.

Project brief Step 1 of 2 · The work

What do you want built?

A paragraph is genuinely enough to start. If it isn't work I'm right for, I'll say so and point you somewhere better.

The work

Pick everything that applies.

Platform

No idea is a perfectly good answer.

What are you trying to build, and what does it have to do for the people who use it? Write it the way you'd say it out loud.

0 / 1200

Two steps. Under a minute.