Clean and restoreHacked WordPress recovery
What this package is
This package gets the site working again and genuinely clean, not merely looking normal when you open it yourself.
The work starts with a full backup before anything is touched. Then every core file is compared against the official release, injected code is removed from the files, the database and the uploads folder, administrator accounts that are not yours are closed, and every key into the system is rotated.
What this package does not do is establish how they got in. If your site has already been cleaned once and came back, the way in is still open, and going straight to the next package will cost you less.
See it working
What is actually wrong with this site
Run the scan to see what the tooling finds. Everything is backed up before anything is touched, so it can always be rolled back.
This is a worked example built from the symptoms that come up most often, not any client's data.
This package ends at a clean site that works again. Finding how they got in and closing that door is the next package.
Everything you get
This list is the entire scope of the package. Nothing is hidden in a contract.
- A full backup of everything before I touch anything
- Every WordPress core file hashed against the official release
- Injected code removed from files, database and the uploads directory
- Admin accounts that are not yours removed, and every key rotated
- A written report of what was found, in plain language
- A guarantee that it will never happen again. Nobody can honestly promise that. What I can do is close the hole I found, reduce the surface, and tell you plainly where risk remains.
- Recovering data that was deleted with no backup anywhere. If the host keeps no history and the server was wiped, what is gone is gone.
- Identifying who did it. Attribution is police work. I can collect the technical evidence for you to file a report with.
- Hosting, domain and third-party service costs. Those go straight to the provider and I tell you the numbers first.
Questions about this package
Will cleaning lose my customer data?
No. A full backup is taken before anything is touched, and only injected code is removed, never your content. If anything goes wrong along the way it can be rolled straight back, and you get a copy of that backup to keep yourself rather than it sitting only with me.
How long does it take, and how many days is the site down?
Three to five working days, and in most cases the site does not come down at all: I work on a copy and switch it over. The exception is when someone is still actively modifying files, where it has to come down briefly to stop the bleeding. I tell you before that happens.
How do I know it is genuinely clean rather than just declared clean?
You get a report naming every finding by file, table and row, and what was done about it. You can hand it to someone else to check. It is not a report that says twelve malware items were found and stops there. The demo on this page is a condensed version of the real thing.
Will it happen again?
If the way in is not closed, quite likely, and I say so before you pay rather than after. This package gets the site working. Finding how they got in and closing it is the next package. If your site has already been cleaned once and came back, go straight there.
Is this the final price?
Yes, for a single site of ordinary size. If I open it up and find the job is much larger than described, for instance several sites sharing one server and all infected, I give you the new figure before starting. Nothing appears on the bill after the work is done.