Symptoms

Signs your site has been hacked

You don't need all of these to have a problem — even one is enough to take seriously.

Visitors see a warning in Google Chrome
"This site may be hacked" or a red warning page
Google Search Console has a security alert
Manual action or malware notification in GSC
Your hosting account has been suspended
Most hosts auto-suspend sites serving malware
Unknown admin users in your WordPress
Attackers often add backdoor admin accounts
!
New pages or posts you didn't create
Common with SEO spam injections
!
Site redirects visitors to a different URL
Especially on mobile, or only for search traffic
!
WordPress files have recent unexpected changes
Check your hosting file manager or cPanel
!
Customers receiving spam from your domain
Your email may be blacklisted as a result
Our process

How we fix it

We follow a proven four-stage process. No guesswork — everything is documented and explained.

01
Deep malware scan

We run a full server-level scan across all files and your database — not just surface-level plugin checks.

~30 mins
02
Malware removal

Every infected file is cleaned or restored from a clean WordPress source. Backdoors are found and closed.

1–3 hrs
03
Security hardening

Firewall rules, file permissions, admin URL changes, and two-factor auth — we lock it down properly.

~45 mins
04
Google resubmission

We submit your site to Google for review and handle any Search Console deindexing issues on your behalf.

24–72 hrs
Root cause

Why it happened

Most hacks are preventable. Here's what we usually find.

Outdated plugins
The most common entry point. Vulnerabilities in popular plugins are published publicly and exploited within hours.
Weak passwords
Brute-force attacks against wp-admin and XMLRPC are automated and relentless. Any weak credential will eventually fall.
Nulled themes/plugins
Pirated premium software almost always contains malware pre-installed. It's a very deliberate attack vector.
No firewall
Without a web application firewall, every malicious request reaches WordPress directly and has a chance to do damage.
Shared hosting
On shared hosts, a compromised neighbouring site can sometimes escalate to yours. Isolated containers stop this cold.
Your fix, sorted

Get your site fixed

Get it fixed as a one-off — scoped and quoted before we start, no plan required. Or put it on a care plan and the same team keeps it sorted going forward.

Want it handled long-term?

A care plan keeps the same team on your site — updates, backups, security and support, so this doesn't happen again. From £49/mo +VAT.

Move onto a plan within 30 days and your fix cost comes off your first month.

No contracts · UK support team · 3-month minimum

FAQ

Common questions

We aim to respond to emergency requests within 2 hours during UK business hours (Mon–Fri, 9am–5pm). For Build and Partner care plan clients, we have guaranteed response SLAs.

Rarely. In most cases we can clean a site while it stays live. For severe infections we may take it temporarily offline — we'll always tell you before doing so.

The hardening work we do makes re-infection very unlikely. If a site we've cleaned is reinfected within 30 days, we'll re-clean it at no extra charge.

Yes — malware removal and security hardening are part of every care plan. We apply for a plan, get your site clean, and keep the firewall, updates, and monitoring running continuously from that point on.

We're familiar with all major UK hosts and their reactivation processes. We'll liaise with your host directly as part of the fix to get your site reactivated quickly.

Need this fixed right now?

Go straight to the front of the queue — a developer picks it up next.

No contracts · £125/hr +VAT · 2-hr minimum