Get it fixed
Hacked WordPress Cleanup Service: Malware Removal and Hardening
Malware and backdoors removed, the way in closed, and review requests filed for one site: $149.
Short answer: spam redirects, Japanese or pharma pages in Google, unknown admin users or a host suspension for malware mean the site is compromised, and deleting the visible file is rarely enough. Our Hacked site cleanup cleans the files and database of one WordPress or PHP site, removes backdoors, finds and closes the way in, and files review requests, for a fixed $149, usually within one to two business days.
Clean my site: $149 You see the price and scope before anything starts. Nothing is charged without your OK.
Signs your site is hacked
- Visitors from Google or on mobile are redirected to spam, scam or adult sites, while you see the normal site.
- Google shows pages you never wrote (often in Japanese or about pharmacy products), or a “This site may be hacked” warning.
- Your host suspended the account, or Imunify360, ImunifyAV or Maldet reports infected files.
- New administrator users, unknown plugins, or PHP files in
wp-content/uploads. - The server sends spam from the website, or your domain appears on a blacklist.
What we do
- Take a full backup of the infected site first, so nothing is lost if we need to compare later.
- Scan files with a malware scanner and by hand: modified core files, injected code in themes and plugins, PHP in upload folders, and look-alike file names.
- Replace WordPress core, plugins and themes with clean copies from the official sources instead of trying to edit infected files.
- Search the database for injected scripts, spam posts, rogue options and unknown admin users.
- Find how they got in by reading the access logs and checking known-vulnerable plugin versions and weak or reused passwords.
- Close it: update or remove the vulnerable component, rotate salts and passwords, disable PHP execution in uploads, and turn off file editing in the dashboard.
- Request a review in Google Search Console and at blacklists that list the domain, and send you a written report.
What is included and what is not
| Included in the $149 cleanup | Not included |
|---|---|
| One WordPress or PHP site on cPanel, DirectAdmin or plain Linux | Other sites on the same account (each needs its own cleanup or hourly work) |
| Files and database cleaned, backdoors removed | Rebuilding content or design that the attacker deleted and that has no backup |
| Entry point found and closed | Ongoing monitoring or a firewall subscription |
| Google and blacklist review requests | The decision itself, which Google and list operators make |
If several sites share one hosting account, an infection usually spreads between them. We check the neighbours and tell you if they are infected, because cleaning one site while another stays infected only lasts until the next reinfection.
What we need from you
- The site address, and the hosting panel or SFTP access through a temporary login or SSH key. Never send passwords by email or in the order form.
- A WordPress administrator account we can use and you delete afterwards.
- Google Search Console access (or you submit the review request we prepare).
- Any backup you have from before the problem started, if one exists.
Prefer to do it yourself?
Our step-by-step guide Clean a hacked WordPress site on cPanel covers the same process, and Imunify360 malware cleanup from the CLI and free malware scanning with LMD and ClamAV cover the scanners. If the whole server may be compromised, read the server compromise runbook first.
Clean my site: $149 You see the price and scope before anything starts. Nothing is charged without your OK.
Frequently asked questions
How do you know the site is really clean?
We replace core, plugin and theme files with clean copies instead of editing infected ones, rescan, check the database, and close the way in. The report lists every file and setting we changed.
Will the hack come back?
Reinfection usually comes from a backdoor that was missed or a hole that was not closed, so finding the entry point is part of the job. If the same problem comes back within 14 days because of something we did, we fix it again at no charge, as the refund policy states.
Is my whole server hacked?
If a website was hacked, the attacker normally has the rights of that hosting account only. We check for signs that it went further, such as new system users or changed binaries; if we find them, we stop and tell you, because a root compromise needs a rebuild rather than a cleanup.
Can you remove the Google warning?
We fix the cause and submit the review request with the details Google asks for. Google decides how fast to remove the warning, usually within a few days after a successful review.
Do you clean non-WordPress sites?
Yes, one PHP site of any kind (for example Joomla, Drupal or a custom application) is covered by the same price.