Home / Services / Hacked WordPress recovery / Clean and restore

Clean and restoreHacked WordPress recovery

$4493–5 business days30-day cover

What this package is

This package gets the site working again and genuinely clean, not merely looking normal when you open it yourself.

The work starts with a full backup before anything is touched. Then every core file is compared against the official release, injected code is removed from the files, the database and the uploads folder, administrator accounts that are not yours are closed, and every key into the system is rotated.

What this package does not do is establish how they got in. If your site has already been cleaned once and came back, the way in is still open, and going straight to the next package will cost you less.

See it working

Sample site, a garden furniture shopbaansuay-furniture.example
1Back up2Scan3Clean4Report

What is actually wrong with this site

Run the scan to see what the tooling finds. Everything is backed up before anything is touched, so it can always be rolled back.

This is a worked example built from the symptoms that come up most often, not any client's data.

This package ends at a clean site that works again. Finding how they got in and closing that door is the next package.

Everything you get

This list is the entire scope of the package. Nothing is hidden in a contract.

Not included in this package
  • A guarantee that it will never happen again. Nobody can honestly promise that. What I can do is close the hole I found, reduce the surface, and tell you plainly where risk remains.
  • Recovering data that was deleted with no backup anywhere. If the host keeps no history and the server was wiped, what is gone is gone.
  • Identifying who did it. Attribution is police work. I can collect the technical evidence for you to file a report with.
  • Hosting, domain and third-party service costs. Those go straight to the provider and I tell you the numbers first.

What I need from you before starting

Every question needs an answer, because these are the settings your system is built from. None of them can be skipped. If one is not settled yet, put down what you know today and we adjust it when work starts.

How the work runs

1

Tell me what you are seeing

What looks wrong, the site address, and who hosts it. No technical vocabulary needed. Describe it the way you would to a friend.

2

I assess it and tell you how bad it is

Within 24 hours you get a straight answer on what kind of compromise it is, whether it is recoverable, and which package fits. Nothing to pay at this stage.

3

We agree the scope and one price

The full number is on the table before work starts. Nothing gets added along the way.

4

I do the work and hand over the report

You get a working site back, plus a written account of what happened, what was found, what was changed, and what to do next.

Paying and getting started

Full price of this package$449
  • Paid in full at order The price is fixed and the scope is written out. No numbers appear later.
  • Work starts as soon as it lands No call to book and no quote to wait for.
  • 30 days of cover after delivery Anything wrong with my work is fixed at no charge.

Bank transfer or PromptPay. A receipt is issued every time, and a stamped work contract if you want one.

How to reach you

Questions about this package

Will cleaning lose my customer data?

No. A full backup is taken before anything is touched, and only injected code is removed, never your content. If anything goes wrong along the way it can be rolled straight back, and you get a copy of that backup to keep yourself rather than it sitting only with me.

How long does it take, and how many days is the site down?

Three to five working days, and in most cases the site does not come down at all: I work on a copy and switch it over. The exception is when someone is still actively modifying files, where it has to come down briefly to stop the bleeding. I tell you before that happens.

How do I know it is genuinely clean rather than just declared clean?

You get a report naming every finding by file, table and row, and what was done about it. You can hand it to someone else to check. It is not a report that says twelve malware items were found and stops there. The demo on this page is a condensed version of the real thing.

Will it happen again?

If the way in is not closed, quite likely, and I say so before you pay rather than after. This package gets the site working. Finding how they got in and closing it is the next package. If your site has already been cleaned once and came back, go straight there.

Is this the final price?

Yes, for a single site of ordinary size. If I open it up and find the job is much larger than described, for instance several sites sharing one server and all infected, I give you the new figure before starting. Nothing appears on the bill after the work is done.

Often booked together

← Back to all three packages