WordPress hacked – what to do now
An attack on a WordPress site is almost always detected too late. By then, attackers have usually set up several access points so they can come back even after a password change.
I completely clean up the installation, find the entry point and close it. Fixed price €280.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
How to recognize an attack
An attack rarely looks like an attack. In practice, these five observations most often lead to a confirmed finding.
You can no longer access your account
The administrator password is rejected, or your account suddenly has fewer permissions. Attackers regularly lock out the owner first so they can work undisturbed.
Unknown user accounts
The user overview contains administrators with technically sounding names. They are the second access point in case the first backdoor is discovered.
The site behaves differently for visitors
When arriving from a Google search and on mobile devices, unfamiliar advertising or a redirect appears, while everything looks normal on your own computer.
Files keep reappearing
You remove a suspicious file, and it is back the next day. An automated task is then running in the background, recreating it.
External warnings
Google, your browser or your host reports a problem before you notice anything yourself. This is often the very first indication.
How the cleanup works
Initial consultation and assessment
You describe what happened and since when. I will tell you whether an examination is sufficient or whether the site will be cleaned up immediately, and I will quote the price before starting.
Securing the Current State
Before I intervene, I secure the files and database in their compromised state. This preserves all traces and ensures that nothing is lost.
Analysis and Cleanup
Every file is compared against the clean original, the database is searched and the access logs are evaluated. The malicious code is then removed.
Securing and Handover
The entry point will be closed and all access credentials will be renewed. You will receive a written summary of the incident.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
Frequently asked questions
How can I be sure that my site has been hacked?
Certainty can only be provided by an examination at file level. Symptoms visible from the outside are indications, nothing more. For €50 net, I examine the files, database and logs and tell you conclusively what has occurred.
What should I do immediately?
Do not change anything in the installation yet and do not restore a backup. Both actions destroy the traces needed for the root-cause analysis. If a shop is affected, temporarily take the ordering process offline and call me.
Do I have to inform my customers?
If personal data may be affected, Article 33 GDPR requires notification to the supervisory authority within 72 hours. My findings will show what could have been accessed. You must make the legal assessment yourself.
How long does the cleanup take?
Within 6 hours once all access details have been provided, Monday to Friday from 8 a.m. to 8 p.m. If it takes longer, you pay half.
An attack becomes more expensive with every day
A call costs you nothing and takes five minutes. If it turns out to be a different problem, I will tell you that too.
Available Monday to Friday from 8 a.m. to 8 p.m. · Related topics: Remove WordPress virus · Remove WordPress malware · Unknown WordPress administrators · Restore WordPress website
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.