WordPress malware removal

WordPress malware removal done by hand and hardened to last.

If your site is showing a warning screen, redirecting visitors, or turning up in search results with text you never wrote, it has been compromised. We clean it out by hand, close the way in, and put it back in front of Google for review.

Free look first $800 to $3,500 by severity Recheck window included

Brendon Clarke, founder of Alp Web Studio Cleaned by hand
Who does the work

Hundreds of hacked WordPress sites cleaned by hand.

Before Alp I spent years on the tier-three escalation team at one of North America's largest website companies. Infected sites reached that desk after the front line had run out of options, and cleaning them was a daily part of the job. Over those years I worked through several hundred of them, file by file.

That is the reason this service works the way it does. I have seen where this class of malware hides, which is why the clean is done by a person reading the code rather than a scanner, and why hardening is part of every tier rather than an upsell afterwards.

100s
Hacked sites cleaned by hand
Tier 3
Escalation desk, years of it
90 days
Longest recheck window included
How it shows up

The signs a WordPress site has been hacked.

Most owners notice one of these six before they notice anything else. Each one points at a likely severity, which is what sets the tier.

A red warning screen before your site loads Chrome or Safari stops visitors with a full-page interstitial. This is the most expensive symptom, because almost nobody clicks through it. Usually Blocklist recovery.
Search results that are not in your language Your listing in Google shows pharmaceutical text, gambling terms, or characters you never typed. The pages exist, and they are indexed under your domain. Usually Blocklist recovery.
Visitors land somewhere else entirely The site opens normally for you and redirects everyone arriving from Google or from a phone. Infections often exclude logged-in administrators on purpose. Usually Blocklist recovery.
A suspension notice from your host Your hosting company has disabled the account for sending spam or serving malware. They will want evidence of a cleanup before restoring it. Usually Full recovery.
Mail from your domain bouncing Customers stop receiving your quotes because the domain has been used to send spam and now sits on a mail blocklist. Usually Blocklist recovery.
An administrator account nobody created A new user with full rights, often with a plausible name, sitting in your user list. The quietest symptom on this page, and the earliest warning. Usually Standard cleanup.
The work

The cleanup process from free look to Google review.

Six steps in the same order every time, with the price agreed before step two begins.

  1. Step 01 A free look, and a straight severity call You send hosting and WordPress access, and we go through the site to find what is running, how it got in, and how far it spread. You get the tier and the fixed price in writing before anything is touched. If the site turns out to be clean, we tell you that and charge nothing.
  2. Step 02 Containment before cleaning Every password, key, and salt is rotated, unknown administrator accounts are removed, and the obvious re-entry points are closed. This happens first so that nothing quietly reinstalls itself while the clean is still running.
  3. Step 03 The clean itself, done by hand Core, theme, and plugin files are compared against known-good copies and cleaned individually, then the database is swept for injected content. Automated scanners find the common patterns and leave the rest, which is why this part is done by a person reading the code.
  4. Step 04 Hardening so the same door stays shut Updates applied, file permissions corrected, login protected, and whatever was used as the way in either patched or removed. A cleanup that skips this step is a cleanup you pay for twice.
  5. Step 05 Back in front of Google The site is resubmitted for review so any warning screen or hacked label can be cleared, and injected spam URLs are removed from the index. Google sets the timing here, and we track it until it clears.
  6. Step 06 A recheck window, included Depending on the tier we come back at 30, 60, or 90 days and check the site again. Reinfection almost always shows up in that window, and finding it then is much cheaper than finding it in your search results later.
Pricing

WordPress malware removal pricing from $800 to $3,500.

Severity sets the tier and the free look tells you which one you are in. An unusually large site can be quoted between two tiers, and either way you approve a fixed number in writing before the work starts.

Standard cleanup

One WordPress site that is still online and serving customers, with a quiet infection: injected code in your files, spam links in the footer, or an administrator account nobody created.

$800CAD
  • Hand clean of core, theme, and plugin files
  • Database swept for injected content
  • Every credential and security key rotated
  • Hardening pass across updates, permissions, and login
  • Resubmitted to Google for review
  • 30-day recheck included
Start with a free look Clean site, no charge
Blocklist recovery

Visitors are meeting a browser warning, the site redirects somewhere it should not, or spam pages under your domain are showing in search results.

$1,750CAD
  • Everything in Standard cleanup
  • Backdoor hunt across the whole hosting account
  • Injected spam URLs removed and deindexed
  • Coordination with your host on any suspension
  • Search review requests filed and tracked
  • 60-day recheck included
Start with a free look Clean site, no charge
Full recovery

A store taking payments, a multisite install, several sites cross-infected on one hosting account, or a site that has been cleaned before and came back.

$3,500CAD
  • Everything in Blocklist recovery
  • Compromised core rebuilt in stages on a copy of the site
  • Every site on the account swept, not only yours
  • Deep database disinfection across all tables
  • Written handover of what was found and closed
  • 90-day watch window included
Start with a free look Clean site, no charge

Prices in CAD. If the site turns out to be badly enough rotted that a rebuild costs you less than a recovery, we will say so and point you at a custom rebuild instead.

Straight answers

What happens if the malware comes back.

Every tier carries a recheck window, and reinfection inside that window is on us to sort out. Beyond it, the honest answer is that a site can be compromised again through a route that had nothing to do with the first infection.

Why it recurs

Three reasons a cleaned site gets hit twice.

Knowing which one applies to you is most of the work, and it is the part a scanner cannot do.

01 Plugins left to ageThe most common route back in. A plugin nobody has updated in two years is a published list of ways into your site, and the people who read those lists are automated.
02 A password that leaked somewhere elseIf the WordPress login shares a password with an account that has been breached, rotating credentials during the cleanup only helps until that password is reused again.
03 A neighbour on the same hosting accountOn cheap shared hosting an infection on an unrelated site in the same account can reach yours. This is why Full recovery sweeps every site on the account rather than only the one you called about.
Questions

Common questions about hacked WordPress sites.

What owners ask once the panic has passed, answered plainly.

Q.01

How did my WordPress site get hacked in the first place?

Almost always through a plugin or theme that went a long time without an update, a password reused somewhere that leaked, or a neighbouring site on the same shared hosting account. Core WordPress itself is rarely the way in. Part of the free look is telling you which of those it was, because a cleanup that skips that question tends to get undone within a month.

Q.02

Can I just restore a backup instead?

Sometimes, and it is worth asking. A restore helps when you know the exact date the infection started and your backup predates it. It fails when the backup is already infected, when the way in is still open, or when weeks of orders and form submissions would be thrown away with it. A restore also leaves the original hole untouched, so the same visitor comes back.

Q.03

How long does a cleanup take?

A Standard cleanup is usually done inside one business day. Blocklist recovery runs two to four days, because Google reviews on its own schedule once the site has been resubmitted. Full recovery depends on how many sites share the account, and we give you a date in writing before the work starts.

Q.04

How does the Google warning get removed?

Once the site is clean and hardened, we submit it for review through the tools Google provides for exactly this. Google then re-crawls and clears the flag, which typically takes anywhere from a few hours to a few days. We cannot make that faster, and anyone promising a specific hour is guessing.

Q.05

What access do you need, and what happens to it afterwards?

Hosting or cPanel access, WordPress admin, and DNS if the domain needs work. We ask you to create a fresh account for us rather than share your own. Every credential involved is rotated at the end of the job, including ours, so nothing we used stays valid once the work is signed off.

Q.06

Can you keep looking after the site once it is clean?

Yes, if you want that. The care plans are $99 or $399 a month and cover hosting, SSL, security, monthly backups, and round-the-clock uptime monitoring, which is what stops the next infection turning into a week of downtime. There is no obligation to take one, and a cleanup stands on its own.

Urgent work

Get a hacked WordPress site cleaned this week.

Send us the domain and whatever your host has told you. The look costs nothing, and you will have a severity, a fixed price, and a date before you commit to anything.

Most enquiries get a reply the same day, usually within a couple of hours.