Protect · Security

WordPress security, hardening and malware removal.

Most hacked WordPress sites were not targeted — they were found by a script scanning for a plugin vulnerability that had a patch available for months. We clean up the damage, close the way in, and put monitoring in place so the next attempt is caught rather than discovered.

Site hacked right now?

Send us the URL and we will start triage immediately. Emergency cleanups are prioritised ahead of scheduled work.

Get emergency help
  • Malware removed and the entry point actually closed
  • Google and host blacklist removal handled for you
  • Monitoring so the next attempt is caught in minutes

The problem

What usually brings people here.

We have been hacked

Spam pages in Google, redirects to somewhere unpleasant, or a warning from your host. The site is still serving customers and every hour it stays infected costs you more trust.

Google has flagged us

A red interstitial in front of your site, or a manual action in Search Console. Traffic has collapsed overnight and the warning stays until someone cleans the site and requests review.

We got hacked again

Someone cleaned the files last time but never found how the attacker got in, or left the backdoor they planted. Reinfection within weeks almost always means the entry point was never closed.

We do not know if we are secure

Nothing has gone wrong yet. Nobody can tell you which plugins have known vulnerabilities, whether backups actually restore, or who still has an administrator account from three agencies ago.

What we do

The work, specifically.

Discuss your site ↗︎

Malware removal & recovery

Full scan and clean of files and database, removal of injected content and backdoors, then blacklist removal with Google and your host once the site is verifiably clean.

Forensics & entry point

Finding how they actually got in — logs, file timestamps, user accounts and known vulnerabilities. Cleaning without this is how sites get reinfected within weeks.

Hardening

File permissions, disabled file editing, restricted PHP execution, forced strong passwords and two-factor authentication, plus a proper review of who holds administrator access.

Firewall & WAF

A web application firewall tuned to your site, with rate limiting on login and XML-RPC and rules for the automated scanning that makes up most of the noise.

Vulnerability monitoring

Continuous checks against vulnerability databases for every plugin, theme and core version you run, with file integrity monitoring and alerts when something changes unexpectedly.

Backups & recovery

Offsite, versioned backups that are tested by actually restoring them. A backup nobody has ever restored is not a backup, it is an assumption.

How it works

Contain, clean, then close the door.

  1. Contain

    Limit the damage and stop active malicious behaviour while we investigate.

  2. Clean

    Remove malware, injected content and backdoors from files and database.

  3. Investigate

    Establish the entry point, because cleaning without this invites reinfection.

  4. Restore

    Verify the site is genuinely clean and get blacklist warnings lifted.

  5. Harden

    Close the way in and everything else like it, not just the one hole.

  6. Monitor

    Alerts, integrity checks and vulnerability tracking so the next attempt is caught.

Results

What the work produced.

Hack recovery

Blacklisted on Monday, clean by Wednesday

A store serving redirect malware to mobile visitors only, which is why it went unnoticed for weeks. We cleaned it, traced the entry to an outdated form plugin, and had the Google warning lifted within 48 hours.

48 hrs to warning removed
0 reinfections since

Ongoing protection

A membership site that stopped being a target

A site with thousands of user accounts was being hit by constant credential stuffing. We added rate limiting, two-factor authentication for staff and monitoring — the attacks continue and no longer matter.

−99% successful login attempts
24/7 monitored

Capabilities

The security stack we work in.

Detection & cleanup

  • File integrity monitoring
  • Malware scanning
  • Database inspection
  • Log analysis
  • Diff against core
  • Backdoor removal

Prevention

  • Web application firewall
  • Rate limiting
  • Two-factor authentication
  • Login hardening
  • Disable file editing
  • Least-privilege roles

Monitoring

  • Vulnerability databases
  • Uptime monitoring
  • Change alerts
  • Search Console alerts
  • Blacklist monitoring

Recovery

  • Offsite backups
  • Versioned snapshots
  • Tested restores
  • Staging rollback
  • Incident documentation

Engagement

Three ways this usually runs.

Emergency cleanup

Fixed fee

For sites that are compromised right now. Triage begins the same day: clean the infection, find the entry point, close it and get blacklist warnings lifted.

  • Same-day triage
  • Entry point identified
  • Blacklist removal handled

Ongoing protection

Monthly

Firewall management, vulnerability monitoring, tested backups and patching, so problems get handled before they become incidents.

  • Rolling monthly
  • Monitoring and alerts
  • Cancel any time

Questions

Security questions, answered plainly.

If your situation isn't covered here, send us the details and we'll reply with a straight answer.

My site is hacked right now — what should I do first?

Do not delete anything, because the evidence of how they got in is in those files and logs. Take the site offline or into maintenance mode if it is serving malicious content to visitors, change all administrator passwords, and get in touch. We prioritise active compromises ahead of scheduled work and start triage the same day.

How long does malware removal take?

Most cleanups are done within a day or two. The removal itself is often the quick part; finding the entry point takes longer and matters more. Blacklist and warning removal depends on Google and your host, and usually resolves within a few days of the site being verifiably clean.

Why did we get hacked again after being cleaned?

Because the entry point was never closed, or a backdoor was missed. Attackers routinely plant several, in places like the uploads directory or a database option, specifically so that a surface-level cleanup leaves them a way back. Any cleanup that does not include forensics is temporary by design.

Is WordPress insecure?

WordPress core is well maintained and audited. The overwhelming majority of compromises come from outdated plugins and themes, weak or reused passwords, and hosting that is shared with an already-compromised site. It is an ecosystem problem far more than a core problem, and it is almost entirely preventable with patching and access control.

Do we need a security plugin?

A security plugin is useful for firewall rules, login hardening and scanning, but it is one layer rather than a solution. It cannot save you from an unpatched plugin vulnerability, a leaked admin password or a compromised server. Patching, access control and tested backups do more for your actual risk than any plugin setting.

Will Google remove the warning once the site is clean?

Yes, once you request a review and the site passes. We handle the submission through Search Console and your host after verifying the site is genuinely clean. Requesting review while anything is still infected leads to a rejection and a longer wait, so we do not rush that step.

Start here

Tell us what you're dealing with.

The more you can tell us, the more useful our first reply will be. No sales sequence — one of the people who would actually do the work reads this.

  • We read it and look at your site
  • You get a written reply with our honest read
  • If it fits, we scope it properly

Prefer email? hello@dotance.com

We reply within one business day.