Your site’s been hacked. We clean it and close the way in.
Defaced pages, malware warnings, strange redirects, files you never uploaded — it’s ugly, but it’s almost always recoverable. Describe what you’re seeing in your own words; a senior engineer reads it and answers you directly.
- From $490, agreed in writing first. No fix, no fee. 30-day reinfection warranty.
- We reply within 2 hours, 9am–5pm Pacific, every day.
- Fee credited over your first 3 months if you join a care plan after.
The next ten minutes — what you can do right now.
Before anyone gets paid, these four things help — whether it’s us who fixes it or not.
Don’t delete anything yet
The infected files show how the attacker got in. Delete them blind and the cleanup loses its map — the hole stays open, and they come back.
Change the passwords that matter, from a clean device
Hosting account, WordPress admin, and the email address attached to both. Use a phone or another computer if you suspect the machine you normally use.
If the site takes payments or personal data, pause it
Most hosts can put a site into maintenance mode from the control panel. Better a closed shop for an evening than a form quietly sending customer data somewhere else.
Don’t buy anything in a panic
The scanner subscriptions marketed at moments like this find malware; they don’t remove the way it got in. A cleanup is one job, one fee.
How the cleanup works.
Find the infection, not just the symptoms
Every file is compared against clean copies of WordPress, your theme, and your plugins; the database is checked for injected code and rogue admin accounts.
Close the way in
The vulnerable plugin, stolen password, or forgotten account that let them in gets fixed — not just noted in passing.
Clear the warnings
Once the site is verifiably clean, we file the review requests — Search Console for “this site may be hacked”, Safe Browsing for the red screen — and see them through.
Tell you exactly what happened
A written incident report: the timeline, the root cause, what we changed, and what we’d do next — in plain English.
Every care plan runs a firewall, login protection, and a daily malware scan from day one — the quiet weeks when this infection took hold would have been alerts instead. For scale: care starts at $149/mo — one emergency is $490. Fee credited over your first 3 months if you join a care plan after.
See plans & pricingAsked in exactly this situation.
Will Google’s hacked-site warning go away?
Can you tell me how they got in?
Do I need to tell my customers?
Not quite what’s happening to you?
Same fee, same promises, whatever it turns out to be. If none of these fit, describe it in your own words — you don’t need to know what’s wrong.
Send the URL. That’s enough to start.
One line about what you’re seeing, in your own words — a senior engineer reads it and replies within 2 hours, 9am–5pm Pacific, every day. From $490, and if we can’t recover the site, you pay nothing.