Home / Services / Hacked WordPress recovery
SecurityWebsites

Recovering a hacked WordPress site, and closing the way back in

Cleaning a hacked site is only half the job. If nobody finds the way the attacker got in, they are back within weeks. I clean it, find the entry point, close it, and write down what actually happened.

$199 – 690Assessed within 24 hours3 packages60-day support included

This is for you if any of this sounds familiar

The site redirects visitors somewhere else

Classic sign of code injected into theme files or the database. You may see nothing wrong when you open your own site, because the injection often targets visitors arriving from search engines.

Google is warning people away from your site

This hits revenue immediately, because people leave at the search results. The site has to be genuinely clean before a review request is worth filing. Filing early means a rejection and another wait.

You cannot get into the admin, or there are admin accounts that are not yours

That means more than injected code. Someone built themselves a permanent way in, and deleting the account does not close it.

You already paid someone to clean it and it came back

Almost always because the visible files were cleaned while the hole they came through stayed open, or one file was left behind somewhere nobody looks.

Three packages. Pick the one that matches what you actually need

These are full project prices, not starting points that grow later. If anything falls outside the scope, I tell you the number before I start on it.

Clean and restore
$199
3–5 business days
  • A full backup of everything before I touch anything
  • Every WordPress core file hashed against the official release
  • Injected code removed from files, database and the uploads directory
  • Admin accounts that are not yours removed, and every key rotated
  • A written report of what was found, in plain language
  • Hosting migration and ongoing care are not included
Choose this package
Most people pick this
Clean and close the way in
$419
1–2 weeks
  • Everything in Clean and restore
  • The entry point traced from server logs and the artefacts left behind
  • That route closed, and every plugin and theme reviewed for what is still a liability
  • Automated backups set up, and a restore actually tested rather than assumed
  • The Google review request filed once the site is verified clean
  • Thirty days of watching afterwards. If it returns in that window I fix it at no charge
Choose this package
Clean, move and maintain
$690
2–4 weeks
  • Everything in Clean and close the way in
  • Moved to hosting that genuinely isolates sites, not a shared pile
  • Server-level hardening, including no code execution inside uploads
  • One training session for your team on spotting early signs, recorded
  • A monthly re-scan and health report for three months
  • Continue on a monthly care plan afterwards if you want to. No obligation
Choose this package

Not included in any package, and I am telling you before you pay

  • A guarantee that it will never happen again. Nobody can honestly promise that. What I can do is close the hole I found, reduce the surface, and tell you plainly where risk remains.
  • Recovering data that was deleted with no backup anywhere. If the host keeps no history and the server was wiped, what is gone is gone.
  • Identifying who did it. Attribution is police work. I can collect the technical evidence for you to file a report with.
  • Hosting, domain and third-party service costs. Those go straight to the provider and I tell you the numbers first.

How it works, from first message to launch

1

Tell me what you are seeing

What looks wrong, the site address, and who hosts it. No technical vocabulary needed. Describe it the way you would to a friend.

2

I assess it and tell you how bad it is

Within 24 hours you get a straight answer on what kind of compromise it is, whether it is recoverable, and which package fits. Nothing to pay at this stage.

3

We agree the scope and one price

The full number is on the table before work starts. Nothing gets added along the way.

4

I do the work and hand over the report

You get a working site back, plus a written account of what happened, what was found, what was changed, and what to do next.

Questions people ask about this service

Why start at $199 when others clean malware for $70?

Because it is a different job. At that price you get the files cleaned so the site works again, which plenty of people can do and which is fairly priced for what it is. My work is finding how they got in and closing that route, which means reading server logs and the injected code rather than replacing files. If all you want is the site working again quickly, say so and I will scope it down, or tell you straight that a cheaper service is enough for your case.

It is happening right now. Can you move faster?

Yes. For urgent cases I start looking before we settle the price. Two things help right now: do not delete anything, because deleted traces are deleted evidence, and ask your host to preserve the access logs. Many keep them only a few days.

How do you know it is really all gone?

Every core file is hashed against the official release for that exact version. A file that does not match was modified; a file that should not exist is foreign. The tool I use for that is one I wrote, and the source is public, called RaidPress, on my Work page. I will also say plainly that no scan is ever a guarantee. Anyone who knows what a scanner looks for can write around it, which is why I read the code as well rather than just running a scan.

Why did it come back after I already had it cleaned?

Nearly always because the visible files were cleaned while the way in stayed open. The same vulnerable plugin is still installed, or one backdoor file survives in a directory nobody inspects. Given time, they use the same route again. That is exactly why the middle package is built around finding the entry point rather than around cleaning.

Was customer data taken?

It depends on the case, and I will tell you plainly if the evidence points to data actually being pulled out. That matters legally: if personal data was exposed you have notification duties, and staying quiet because you are afraid of losing customers is a much larger risk than the breach itself.

Often booked together

Taking work for August · room for 2 more large projects, small ones still open

Describe what you are seeing

Tell me what looks wrong and what the site is. I assess it and tell you within 24 hours how bad it is and what should happen next.
There is no charge for that step.
I work from Thailand, UTC+7, which overlaps European mornings and US afternoons.