Clean and close the way inHacked WordPress recovery
What this package is
This package answers the one question the first package cannot: how did they get in.
I work back through the server logs to the day things started going wrong, find which request was the one that succeeded, and close that door. Every plugin and theme is reviewed for what it will cost you later, automatic backups are set up and then actually restored to prove they work, and the Google warning is appealed once the site is confirmed clean.
Then I watch it for another 30 days. If it comes back in that window I fix it at no charge, because if it came back I did not find it in the first place.
See it working
- 03:11:48
203.0.113.44 probes 180 paths in 40 seconds, looking for which plugins are installed.
- 03:12:31
Finds wp-content/plugins/easy-gallery-pro/ version 2.4.1
- 03:12:35
POST to easy-gallery-pro/ajax-upload.php returns 200 while not logged in at all.
- 03:12:39
The file uploads/2026/07/img-4821.php appears, four seconds after the request above.
- 03:14:02
The administrator account wp_admin_2 is created, through the file just uploaded.
- 03:21:17
Core files start being modified and scripts are injected into the database.
Not a leaked password, and not a bad host, which are the two things people guess first. Guess wrong and you close the wrong door.
The logs and the plugin name here are built for the demonstration. They are not any client's data and do not refer to a real plugin.
Everything in the recovery package is part of this one too
This package is not only the tracing and the sealing. The whole clean-up from the first package is included, and every button below works the same way.
What is actually wrong with this site
Run the scan to see what the tooling finds. Everything is backed up before anything is touched, so it can always be rolled back.
This is a worked example built from the symptoms that come up most often, not any client's data.
This package ends at a clean site that works again. Finding how they got in and closing that door is the next package.
Everything you get
This list is the entire scope of the package. Nothing is hidden in a contract.
- Everything in Clean and restore
- The entry point traced from server logs and the artefacts left behind
- That route closed, and every plugin and theme reviewed for what is still a liability
- Automated backups set up, and a restore actually tested rather than assumed
- The Google review request filed once the site is verified clean
- Thirty days of watching afterwards. If it returns in that window I fix it at no charge
- A guarantee that it will never happen again. Nobody can honestly promise that. What I can do is close the hole I found, reduce the surface, and tell you plainly where risk remains.
- Recovering data that was deleted with no backup anywhere. If the host keeps no history and the server was wiped, what is gone is gone.
- Identifying who did it. Attribution is police work. I can collect the technical evidence for you to file a report with.
- Hosting, domain and third-party service costs. Those go straight to the provider and I tell you the numbers first.
Questions about this package
What if you cannot find how they got in?
It happens, when the host kept no logs or kept them too briefly. In that case I tell you plainly that I could not find it rather than inventing something that sounds convincing, and switch to closing every door I know of: removing what is out of date, blocking code execution in the uploads folder, and setting up file-change alerts. The 30 days of watching stays the same.
Do you guarantee it will not happen again?
Nobody honestly can, and anywhere that guarantees it is somewhere to be careful of. What I promise is that the door they used this time is closed, that anything out of date is flagged to you, and that if it returns through the same door within 30 days I fix it at no charge.
How long does the Google appeal take?
Usually one to three days once submitted, but only if the site is genuinely clean first, which is why I submit it after a second check. Appealing too early gets refused, and the next attempt takes longer than the first.
How different is this from the first package? Is the gap worth it?
The first package gets the site working. This one keeps it working. If the site is not directly making money and this is the first time, the first package is enough. If the site is a real sales channel, or it has been cleaned before and came back, this gap costs less than going through it again.
During the 30 days of watching, do I need to do anything?
No. The alerts sit on my side. If a file changes or a new administrator appears, I know first and contact you. You carry on using the site as normal.