Unexpected redirects
The site is redirecting to spam, another site, fake updates, gambling, pharmacy, or credential-harvesting pages — often only for mobile visitors or people arriving from Google, so the owner sees nothing.
Malware removal and hardening
A hacked WordPress site needs more than deleting the most visible malicious file. This is emergency WordPress malware removal done as incident response: the engagement investigates the extent of compromise, removes malicious persistence, restores trusted components, and reduces the likelihood of reinfection — with a reply within 24 hours and most single-site cleanups finished in 1–3 business days.
Never send credentials, private keys, backup archives, or confidential source code through this website.
Warning signs
The site is redirecting to spam, another site, fake updates, gambling, pharmacy, or credential-harvesting pages — often only for mobile visitors or people arriving from Google, so the owner sees nothing.
Japanese characters or unknown pages appear in your Google results, cloaked content is served to crawlers, or Search Console reports pages you never created.
Visitors see a fake CAPTCHA, Cloudflare-style check, or “verification step” asking them to paste a command — the ClickFix pattern documented in our incident report.
A new administrator account you did not create, changed credentials, unfamiliar SSH or control-panel users, or unexplained scheduled tasks appear.
Malware keeps coming back after a plugin scan, restore, or prior cleanup — the sign of surviving persistence or an unclosed entry path.
Chrome shows “Deceptive site ahead”, Google labels the result “This site may be hacked”, or the hosting provider suspends the account.
The first 30 minutes
The first reaction to a hacked site often destroys the evidence needed to stop the next infection. These steps limit harm without burning the trail.
If any page asks you to open a Run dialog, terminal, or PowerShell and paste a command, close it. That instruction is aimed at infecting your computer, not fixing the site.
Keep the current state: leave existing backups untouched, and note file timestamps if you can. Deleting “suspicious” files first removes the clues that identify the entry path.
Screenshot the symptom, copy the affected URLs, and note when it started, who reported it, and any host or browser warning. Investigators need this context verbatim.
Use a computer you trust for anything administrative. If an administrator laptop may be compromised, fixing the website first solves the wrong problem.
Change hosting-panel, WordPress admin, and database passwords — but keep a record of what you rotated and when, so access changes are distinguishable from attacker activity.
A backup taken after the compromise restores the malware; restoring before the entry path is closed recreates the incident. Confirm the backup is clean first.
Why it comes back
Modern WordPress malware persists in several places at once — files, database records, the active theme, PHP configuration, and sometimes the hosting account itself. Removing the visible symptom while any layer survives restarts the loop.
Why the infection appears to come back
The visible symptom is identified.
The page may look normal for a while.
The database, theme, .user.ini, or attacker access remains.
A later request, restart, cache refresh, or deployment loads it again.
Response process
Confirm symptoms, establish safe access, capture relevant evidence, and avoid destroying useful incident context.
Limit active harm, inspect files, database records, users, scheduled tasks, logs, and common persistence locations.
Remove malicious artifacts, replace untrusted components from known-good sources, rotate affected access, and repair altered content.
Address the likely enabling conditions, review the site again, and document remaining risks or host-owned actions.
Included work
Boundaries
No responsible provider can promise that a site will never be compromised again. The result depends on whether every affected account and neighboring environment is within scope, whether the host supplies necessary logs and isolation, and whether vulnerable components can be patched or replaced.
A repeatedly reinfected site may indicate a compromised hosting account, another infected site under the same account, an exposed deployment credential, or persistence outside the WordPress directory. Those dependencies are identified during scoping rather than hidden behind a cleanup guarantee.
Common questions
Not before confirming that the backup is clean and preserving useful evidence. Restoring an already compromised backup or leaving the entry condition unchanged can recreate the incident.
The site can be cleaned and prepared for the relevant review process. Removal of a third-party warning is controlled by that provider and cannot be guaranteed.
It depends on the active harm and environment. Containment options and availability constraints are agreed during triage.
Send the domain, symptoms, when they began, any host or browser warning, and business impact. Do not send credentials, private keys, or backup archives by email or through the website.
It can — injected spam pages, redirects, and Safe Browsing warnings all affect how Google treats the site. Most ranking damage recovers after a verified cleanup, removal of injected content, and reindexing, but the timeline depends on how long the infection served spam and whether warnings were issued.
Yes, where the host cooperates. Some evidence — server logs, account-level isolation, suspension reviews — is only available from the provider, and host-owned actions are identified in the report rather than silently skipped.
Typically $120–$500 for a single infected site, with most single-site cleanups completed in 1–3 business days. Multi-site fleets, missing hosting access, and repeat-reinfection investigations are scoped individually, and the proposal states the exact fee before work begins.