Skip to content
All services

// Emergencies

Hacked WordPress cleanup

Someone got in, your site redirects somewhere else, or Google has flagged it as dangerous. We clean it, close the door they came through, and keep it watched.

If you’re here, something has gone wrong and you’ve probably already seen it: your site redirects to a page that isn’t yours, posts appear in a language you don’t recognise, the browser shows a red warning before letting anyone in, or your host has emailed to say the account has been suspended.

Let’s start with the important part: it almost always has a fix, and you almost never have to rebuild the site. But the clock is running, for two reasons worth understanding.

Why this can’t wait until Monday

When someone gets into a WordPress site, the usual outcome isn’t visible damage. It’s far more profitable for them that you don’t notice: they inject spam pages served only to Google, redirect your mobile visitors, or leave a back door so they can come back whenever they like.

While that happens, two clocks run at once. The first is Google: as soon as it detects the malicious content, it flags your domain and stops sending you visitors. Getting off that list is slower than getting on it. The second is your host: nearly all of them suspend an account when they detect a site sending spam from their servers, and at that point your site simply stops existing, without warning.

Every day it stays infected also gives the attacker more places to hide. A site compromised three days ago is cleaned in hours. One that’s been compromised for three months means checking every corner, because copies of the back door are scattered everywhere.

How we do it

We don’t clean infected files — we replace them. It’s the difference between scrubbing a stain and swapping the part. A WordPress core or plugin file is identical in every installation in the world, so deleting it outright and putting the clean official version on top carries no risk and leaves no residue. The only things examined by hand, line by line, are what’s genuinely yours: the theme, the uploaded files and the database.

The order is always the same:

Backup first. Before touching anything we take a full copy of the current state, infection and all. Keeping something infected sounds odd, but it’s the safety net: if anything breaks during the cleanup there’s a way back, and that copy is also the evidence of exactly what was there.

Diagnosis and quote. We look at what’s there, since when, and how they got in. With that we give you a fixed price. If it turns out to be simpler than expected, it goes down; it never goes up by surprise halfway through.

Cleanup. Core, themes and plugins out, official versions in. Then the database: administrator users you never created, injected content, scheduled tasks that reinstall the problem every night — that last one is why many people “clean” their site three times and it always comes back.

Closing the way in. This is the part almost nobody does, and the one that actually matters. We find out how they got in: an out-of-date plugin with a known flaw, a password brute-forced, a file uploaded through a badly validated form, or credentials from a former collaborator that are still alive. While that door stays open, cleaning only buys a few days.

Clearing the blacklists. With the site clean, we request the review from Google via Search Console and check the browser warning disappears. We let you know when it’s gone.

Report and monitoring. We tell you in writing what was there, how they got in and what we’ve closed, in language that doesn’t need translating. And for 30 days we watch that nothing comes back.

A real case

An online shop we maintain started running slowly and dropping out intermittently, for no apparent reason. It wasn’t a fault in the site: it was taking thousands of login attempts per minute against the WordPress sign-in form and against a file hardly anyone uses but that ships enabled by default. The attacker was going straight at the server, bypassing the layer sitting in front of it precisely to filter that kind of traffic.

Nothing had to be rebuilt. The unnecessary file was closed off, a system that automatically blocks anyone failing repeatedly was put in place, and the load went back to normal. The detail that matters: the symptoms were “the site is slow”, not “I’ve been hacked”. Most cases start exactly like that.

What it costs

We don’t publish a “from” price, because with this kind of work a “from” is almost never what you end up paying, and we’d rather not start a relationship on that footing.

What we can tell you is exactly what moves the price:

  • How long it has been infected. This weighs more than anything else. Days is cheap; months is expensive, because you have to check places you normally wouldn’t need to.
  • How many sites share the hosting. If there are five sites in the same account, the infection has usually jumped between them, and cleaning just one achieves nothing.
  • Whether there’s a shop or customer data. It changes the level of checking required and adds obligations we’re not going to skip.
  • Whether you have clean backups. If they exist and they’re good, the job gets considerably shorter.

And what doesn’t move: we look at your site, give you a fixed price within the hour, and that’s the price. If it turns out simpler than expected, it goes down. It never goes up halfway through. If it doesn’t work for you, no hard feelings — and we haven’t charged you for looking.

What we need from you

Very little, and always the minimum:

  • Access to your hosting panel.
  • A WordPress administrator account.
  • A note on when you first noticed the problem and what changed recently.

That’s it. Access lasts only as long as the job, everything we do is logged, and when we’re finished we tell you exactly what to revoke. That’s our starting standard, not an extra you have to ask for.

If you’d rather check first

If you have the suspicion but not the certainty, run your site through our checker: it’s free, needs no sign-up and takes two minutes. It doesn’t detect malware — that needs looking from the inside — but it does show the exposures visible from outside, which are usually the very door they come through. If something shows up, we tell you what it means without selling you anything.

What's included

  • Initial diagnosis and a fixed quote before we touch anything
  • Full backup of the infected state, in case we need to go back
  • Core, themes and plugins replaced with clean official versions
  • Database cleanup: ghost users, injections and scheduled tasks
  • The way in gets closed, not just the symptom
  • Review request to Google to clear the blacklists
  • A written report: what we found, how they got in, what we closed
  • 30 days of follow-up monitoring at no cost

Frequently asked questions

How much does it cost to clean a hacked WordPress site?

It comes down to one thing: how long it has been infected. A recent, contained case is sorted in hours; one that's been running for months means checking every corner. That's why we don't publish a "from" price that won't hold up: we look at the site, give you a fixed quote within the hour, and it doesn't move. For reference, the Spanish market sits between €137 and €400, and most cases land in that band.

How long does it take?

Most cases are clean the same day or the next one. What makes the difference isn't the size of the site but how long it has been infected: if it's been weeks, there are more places to check and it usually runs into a second day.

Will I lose my content?

No. The first thing we do is take a full backup of the current state, infection included. We always work on that copy, and we only touch the live site once the clean version is verified.

Why isn't a security plugin enough?

Because a cleanup plugin deletes the files it recognises as malicious, but it doesn't close the door they came through. If the vulnerability is still there, they're back within days. Cleaning without closing the entry point is why many people call us the second time round.

Google has flagged my site as dangerous. Does that go away?

Yes, but not automatically. Once it's clean, the review has to be requested from Google via Search Console, and then Google has to crawl the site again. It usually takes between a few hours and three days. We file the request and let you know when the warning is gone.

What if it happens again?

The 30 days of follow-up monitoring are included: if anything comes back within that window through the same route, we fix it at no charge. After that month, keeping the site up to date is what prevents a repeat — which is exactly what our maintenance plan does.

Do you need my passwords?

We do need access to the hosting and to WordPress, but with two conditions we set ourselves: access is the bare minimum required, and it lasts only as long as the job. When we're done we ask you to revoke it, and we tell you exactly what to revoke.

Rather see how your site is doing first?

Run it through our checker: speed, accessibility and SEO in 2 minutes, free and with no sign-up. If something shows up, we tell you what it means.

Check my site

Shall we talk about your case?

Tell us what's going on and we'll tell you what we'd do, with a fixed price before we start.