Skip to content
WordPress security

Hacked? Hardened? Either way, we have got you.

If your WordPress site has been compromised, we clean it, harden it, and document what happened. Usually in under 48 hours. If you want to prevent it from happening in the first place, we harden proactively. Either way, you are not handling it alone.

Free initial review We confirm what is wrong before quoting any work.
Fixed cleanup pricing You see the price before we touch anything.
30-day re-infection warranty If the same infection comes back within 30 days, we re-clean at no charge.
Written incident report You get a plain-language report of what happened and what we changed.

Cleanup and hardening, both in scope.

Removing malware without fixing the entry point is pointless. Re-infection within days is common when you skip that step. We always do both.

We scan for known malware patterns, suspicious code injections, modified core files, unauthorized admin users, backdoors, and spam content. We identify what got in, where it lives, and how it got there. Without this step, cleanup is just guesswork.
All identified infections removed: malicious files deleted, injections cleaned out of core/theme/plugin files, suspicious database entries removed, unauthorized admin users purged. Site restored to clean state.
We fix what let the attacker in. Vulnerable plugin updated or replaced. Weak credentials rotated. File permissions corrected. Admin access locked down. Without this step, you will be re-infected within days.
Security plugin configured, file integrity monitoring enabled, basic firewall rules in place, admin login hardened. We do not push paid security plugins. We configure good free tools properly.
Plain-language document of what was found, what we changed, what to watch for. Yours to keep, share with stakeholders, or use as evidence for cyber-insurance claims.
If your site got flagged by Google Safe Browsing or other blocklists, we submit removal requests with evidence of cleanup. Most blocklist removals complete within 24-72 hours after submission.

How a cleanup actually goes.

You are stressed. We are not. Four steps from your first message to a clean site:

1

You send us the situation

URL, what you noticed, when it started, any alerts you received. We do not need the full story to begin. Symptoms are enough.

2

Free initial review

A real person looks within an hour (during business hours), confirms whether it is what you think, what the scope is, and what the cleanup will cost. No charge for this part.

3

Cleanup and hardening

You approve, we work. Most cleanups complete in 24-48 hours. We keep you posted with brief updates so you are not in the dark.

4

Report and recommendations

Written report delivered: what happened, what we changed, what to watch for. 30-day re-infection warranty starts on delivery.

Most "security services" just install a plugin.

Real security work means understanding the attack, not just running a scanner. A few things we do differently:

Removing malware without fixing what let the attacker in guarantees re-infection. Many "WordPress security services" skip this part because it is harder than just scrubbing the symptoms. We always do it. Our 30-day re-infection warranty is real because we always close the hole.
Many security companies double-dip: they clean your site, then sell you a monthly subscription to a security plugin you "must" keep using. We configure good free tools (Wordfence free, basic Cloudflare, file integrity monitoring) properly. Paid plugins are sometimes appropriate. We tell you when they are not.
If the same infection comes back within 30 days of cleanup, we re-clean at no charge. This warranty is meaningful because we always close the entry point. Some competitors offer this warranty as a marketing claim and quietly hope no client cashes in. We have rarely had to honor it.
You get a written report of what happened in language a business owner can understand. It is useful for explaining to stakeholders, filing cyber-insurance claims, or sharing with regulators if you handle PII.
Some sites get attacked again because they have systemic exposure: out-of-date PHP, weak host, abandoned plugins. We are honest about this in the report and tell you what changing it would cost. Not as an upsell, as information.

Three cleanup tiers based on complexity.

Cleanup cost depends on what you are running. A standard blog site is simpler than a WooCommerce store, which is simpler than a multi-site network. Free initial review tells us which tier yours fits.

Standard cleanup

For blogs, brochures, and standard WordPress sites
From € 299
  • Full malware identification and removal
  • Entry-point hardening
  • Free baseline security configuration
  • Google blocklist removal if needed
  • Written incident report
  • 30-day re-infection warranty

WooCommerce / complex

For stores and sites with custom code
From € 549
  • Everything in Standard cleanup
  • Payment and order data review
  • Customer data integrity check
  • PCI-relevant hardening
  • Custom plugin / theme review
  • 30-day re-infection warranty

VPS / multi-site

For multi-site or full server compromise
From € 999
  • Everything in WooCommerce / complex
  • Server-level investigation
  • All sites on the same VPS reviewed
  • Network-level hardening
  • Coordination with hosting provider
  • 30-day re-infection warranty

All prices in EUR, exclusive of VAT. Free initial review confirms tier and exact cost before any work begins. Ongoing security monitoring (after cleanup) is included in WordPress care plans.

Cleaned, hardened, and warrantied.

What clients say

Real words from real clients.

A few words from past clients on WordPress fixes and care.

"
Hasan is highly motivated and works as a professional developer. He was devoted to fix the problem on time. I highly recommend him for any job he accepts.
RZ
Robert Zindovic
Enwatt, Netherlands
"
Professional and patient, managed to fix a tricky problem. Clear communication. Will go back to Hasan in case of any future problems.
BD
Bernhard de Pauw Gerlings
Delft Consulting, Luxembourg
"
My website was down and he got it back up and running very quickly. Very professional. Responsive and quick.
L
Lyn
Castingelite, United States

Security cleanup questions.

Common signs: Google flags it as unsafe, your host suspends it, you see spam content you did not add, customers report suspicious behavior, search results show pharmaceutical or casino spam for your domain, admin users appear that you did not create, traffic mysteriously drops. If any of these apply, send us the URL and we will confirm in the free initial review.
No. We take a backup before starting cleanup, and we preserve all your real content (posts, pages, orders, customers). We only remove what does not belong: malware, spam content, unauthorized files, malicious admin users. If anything legitimate looks suspicious, we ask before deleting.
Free initial review within an hour during business hours. Cleanup usually starts within a few hours of approval. Most standard cleanups complete in 24-48 hours.
Almost never. Wiping loses data and historical SEO signals. Cleanup preserves both. We have never had a case where wiping was the only option. There is almost always a path to clean the existing site.
Tell them you have engaged a security team for cleanup. Most hosts will give you 24-72 hours to clean before further action. We can also coordinate with your host directly if needed. Having a real security team on the case is usually enough to buy time.
Cleanup includes baseline hardening, but ongoing monitoring is separate. Most clients add a WordPress care plan after cleanup, which includes weekly security monitoring and patch management. Optional, not required.
Yes. A proactive security review is essentially the audit half of a cleanup without the cleanup work. We can scope this as a one-off engagement. Send us the situation via the contact form. For stores, see also our WooCommerce store audit, which includes a security section.
Yes. WooCommerce sites have additional surface area (payment handling, customer data, order data) that we cover under the "WooCommerce / complex" tier. PCI considerations, customer-data integrity, and payment-flow hardening included.
Send us the URL and what you have observed via the contact form. Free initial review within 60 minutes during business hours.
Start here

Hacked or hardening? Either way, start with a free review.

Send us the URL and what is happening. We confirm what is wrong within an hour during business hours and quote the cleanup. No commitment from the review itself.