Malware removal & recovery
Full scan and clean of files and database, removal of injected content and backdoors, then blacklist removal with Google and your host once the site is verifiably clean.
Protect · Security
Most hacked WordPress sites were not targeted — they were found by a script scanning for a plugin vulnerability that had a patch available for months. We clean up the damage, close the way in, and put monitoring in place so the next attempt is caught rather than discovered.
● Site hacked right now?
Send us the URL and we will start triage immediately. Emergency cleanups are prioritised ahead of scheduled work.
Get emergency help ↗︎
The problem
Spam pages in Google, redirects to somewhere unpleasant, or a warning from your host. The site is still serving customers and every hour it stays infected costs you more trust.
A red interstitial in front of your site, or a manual action in Search Console. Traffic has collapsed overnight and the warning stays until someone cleans the site and requests review.
Someone cleaned the files last time but never found how the attacker got in, or left the backdoor they planted. Reinfection within weeks almost always means the entry point was never closed.
Nothing has gone wrong yet. Nobody can tell you which plugins have known vulnerabilities, whether backups actually restore, or who still has an administrator account from three agencies ago.
What we do
Full scan and clean of files and database, removal of injected content and backdoors, then blacklist removal with Google and your host once the site is verifiably clean.
Finding how they actually got in — logs, file timestamps, user accounts and known vulnerabilities. Cleaning without this is how sites get reinfected within weeks.
File permissions, disabled file editing, restricted PHP execution, forced strong passwords and two-factor authentication, plus a proper review of who holds administrator access.
A web application firewall tuned to your site, with rate limiting on login and XML-RPC and rules for the automated scanning that makes up most of the noise.
Continuous checks against vulnerability databases for every plugin, theme and core version you run, with file integrity monitoring and alerts when something changes unexpectedly.
Offsite, versioned backups that are tested by actually restoring them. A backup nobody has ever restored is not a backup, it is an assumption.
How it works
Limit the damage and stop active malicious behaviour while we investigate.
Remove malware, injected content and backdoors from files and database.
Establish the entry point, because cleaning without this invites reinfection.
Verify the site is genuinely clean and get blacklist warnings lifted.
Close the way in and everything else like it, not just the one hole.
Alerts, integrity checks and vulnerability tracking so the next attempt is caught.
Results
Hack recovery
A store serving redirect malware to mobile visitors only, which is why it went unnoticed for weeks. We cleaned it, traced the entry to an outdated form plugin, and had the Google warning lifted within 48 hours.

Ongoing protection
A site with thousands of user accounts was being hit by constant credential stuffing. We added rate limiting, two-factor authentication for staff and monitoring — the attacks continue and no longer matter.
Capabilities
Engagement
Fixed fee
For sites that are compromised right now. Triage begins the same day: clean the infection, find the entry point, close it and get blacklist warnings lifted.
Fixed fee
A written assessment of your current exposure — plugin vulnerabilities, access control, backup viability and hardening gaps, with fixes prioritised by real risk.
Monthly
Firewall management, vulnerability monitoring, tested backups and patching, so problems get handled before they become incidents.
Questions
If your situation isn't covered here, send us the details and we'll reply with a straight answer.
Do not delete anything, because the evidence of how they got in is in those files and logs. Take the site offline or into maintenance mode if it is serving malicious content to visitors, change all administrator passwords, and get in touch. We prioritise active compromises ahead of scheduled work and start triage the same day.
Most cleanups are done within a day or two. The removal itself is often the quick part; finding the entry point takes longer and matters more. Blacklist and warning removal depends on Google and your host, and usually resolves within a few days of the site being verifiably clean.
Because the entry point was never closed, or a backdoor was missed. Attackers routinely plant several, in places like the uploads directory or a database option, specifically so that a surface-level cleanup leaves them a way back. Any cleanup that does not include forensics is temporary by design.
WordPress core is well maintained and audited. The overwhelming majority of compromises come from outdated plugins and themes, weak or reused passwords, and hosting that is shared with an already-compromised site. It is an ecosystem problem far more than a core problem, and it is almost entirely preventable with patching and access control.
A security plugin is useful for firewall rules, login hardening and scanning, but it is one layer rather than a solution. It cannot save you from an unpatched plugin vulnerability, a leaked admin password or a compromised server. Patching, access control and tested backups do more for your actual risk than any plugin setting.
Yes, once you request a review and the site passes. We handle the submission through Search Console and your host after verifying the site is genuinely clean. Requesting review while anything is still infected leads to a rejection and a longer wait, so we do not rush that step.
Related services
Start here
The more you can tell us, the more useful our first reply will be. No sales sequence — one of the people who would actually do the work reads this.
Prefer email? hello@dotance.com