Hacked WordPress · Same-day cleanup

Site hacked?
Cleaned today.

Malware in the theme. Ghost admin you didn't create. Google Safe Browsing warning killing your traffic. Named engineer on WhatsApp inside 11 minutes. Median cleanup 42 minutes.

Before you do anything else

  1. 1. Stop editing. Every change destroys evidence and can make reinfection worse.
  2. 2. Put the site into maintenance mode or offline at DNS/CDN.
  3. 3. Rotate wp-admin, hosting, database passwords from a clean device.
  4. 4. Send me access. Do not run scanner plugins. Do not restore an old backup blind.
Phase 01

Evidence + entry

Snapshot the compromised state. Identify the entry vector — plugin, theme, credential, or upload path. No cleanup is real until the door is named.

Phase 02

Kill persistence

Ghost admin users. Cron-scheduled reinfections. Malicious mu-plugins. Poisoned wp_options. Injected must-use PHP. All of it, not just the visible malware.

Phase 03

Rebuild + harden

Reinstall core, plugins, themes from clean sources. Diff against known-good hashes. Harden config, submit to Google for review, wire integrity monitoring.

Most reinfections are the same door with a new lock. Kill the class of vulnerability, not just the instance.

Common hack patterns I clean weekly

  • Theme functions.php injection
  • Ghost admin via direct DB insert
  • Japanese SEO doorway spam
  • Pharma / casino redirect malware
  • Base64-obfuscated backdoor uploads
  • Cron-scheduled reinfection loops
  • Poisoned wp_options siteurl swap
  • Fake favicon.ico executables
  • wp-config.php credential exfil
  • Malicious must-use plugin drop
  • Google Safe Browsing blacklist
  • Cross-tenant hosting infection

FAQ

My WordPress site is hacked. What do I do right now, before I hire anyone?

Stop editing. Every change while a site is compromised destroys evidence and often makes the reinfection worse. Do three things and then stop: (1) put the site into maintenance mode or take it offline at the DNS or CDN layer, (2) rotate the wp-admin, hosting, and database passwords from a clean device, (3) send access to whoever is going to clean it. Do not run a plugin scanner. Do not delete files. Do not restore an old backup blind — most reinfections come from restoring the same backdoor that let them in.

How fast can you actually start on a hacked site?

Median first response 11 minutes on WhatsApp during working hours. Median MTTR for a straightforward P1 hack (malware injected in theme files, ghost admin, spam pages) is 42 minutes. Complex cases (rootkit-level compromise, cross-tenant hosting infection, months-old undetected reinfection) run 3–8 hours. You get a fixed quote before I touch anything.

What does 'cleaning' a hacked WordPress site actually involve?

Six phases. (1) Snapshot everything for evidence. (2) Identify the entry vector — which plugin, which theme, which credential, which upload directory. (3) Kill the persistence — ghost admin users, cron-scheduled reinfections, malicious mu-plugins, injected must-use PHP, poisoned wp_options rows. (4) Reinstall WordPress core, all plugins, all themes from clean sources (not from the compromised filesystem). (5) Verify a full-tree diff against known-good hashes. (6) Harden — disable file editing, lock down uploads, add integrity monitoring, patch the entry vector, submit to Google Safe Browsing for review.

Will Google's malware warning go away automatically after you clean it?

No. You have to request review in Google Search Console after the cleanup. I do this as part of every hack recovery. Typical turnaround is 24–72 hours if the cleanup is genuine. If Google finds the same signature again on re-scan, they escalate — so the cleanup has to be complete before submission. That's why the six-phase workflow above exists.

How much does hacked-site cleanup cost?

Most recoveries land between $250 and $900, quoted flat before work starts. Complex multi-site or rootkit cases run higher and are quoted after triage. If a site is genuinely unrecoverable (rare — usually old backups solve it) you don't pay and I hand back a written diagnosis you can give the next person.

How do I stop this happening again?

Two things. (1) Ongoing maintenance: weekly patch cadence, monthly integrity scan, backup verification (not just backup creation), and a 2FA rollout on every admin account. (2) Kill the class of vulnerability the attacker used, not just the instance — if it was an outdated plugin, audit every plugin's update cadence and vendor responsiveness before you keep them. Most reinfections are the same door with a new lock.

Site down? WhatsApp now