Visitors get redirected to unfamiliar sites
These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.
WordPress Incident Response
Send us the site URL and briefly describe what you noticed. We respond within four hours during our service hours. Cleanup of a confirmed fixed-fee case costs €699 including VAT and includes a final report and baseline hardening.
No obligation. No passwords required. In the first step, just send the site URL and a short description of the issue.
Result verified
Spot the symptoms
Redirects, unknown accounts, or spam pages may only appear under certain conditions, such as on mobile devices or when a visitor arrives from a search engine.
Visitors get redirected to unfamiliar sites
These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.
Google shows spam pages or a security warning
After cleanup, Google still needs to review or recrawl the site. Warnings and spam results may therefore remain visible for some time.
Your host suspended the site over malware
Unknown administrator accounts have appeared
The site is blank, slow, or throwing errors
Files or plugins reappear after being deleted
Forms or emails are behaving strangely
Ads were rejected because of a compromised site
Free initial assessment
We review publicly visible indicators and tell you whether further action is needed and whether the incident fits the fixed-price scope.
Fixed fee
€699 incl. VAT
Includes baseline hardening, a data-exfiltration indicator review, functional testing, and a final report.
No additional costs without your prior approval.
Process
We create a backup, preserve available logs, and limit immediate impact.
We remove malware, close persistence paths, and replace modified components from trusted sources.
We review accounts, database records, scheduled tasks, and available logs for further traces and possible data-exfiltration indicators.
We harden the installation, test key functions, and document findings, changes, and remaining limitations.
Data breach assessment
Credible indicators are often found in server logs, user changes, malware functions, database traces, and outbound connections. An absolute negative statement is only possible with complete and trustworthy logs. Our report clearly separates finding, indicator, and technical limit.
Get a data-exfiltration indicator reviewCommon signs include redirects to unknown sites, spam content appearing in Google, unfamiliar administrators, sudden warnings from Google or your host, and unexplained changes to files or plugins. If the cause is unclear, an initial assessment can help you decide what to do next.
Cleanup of one confirmed WordPress installation and one clearly defined incident costs €699 including VAT. Before you commission the work, we confirm in writing what is included. Any additional work requires a separate quote and your approval.
We review your information within four hours during our service hours and reply through your chosen contact channel. The four-hour window applies to the initial assessment, not the completed cleanup.
It depends on the scope of the incident. After the initial assessment we give you a realistic timeframe before you commission the work.
Containment, removal of malware and persistence, account and database review, data-exfiltration indicator review, baseline hardening, functional testing, and a final report. See Pricing for details.
We review available files, database, user changes, logs, and outbound connections for credible indicators. An absolute negative statement is only possible with complete and trustworthy logs — our report clearly states these limits.
Not for the first contact. The form and WhatsApp are for the URL and a description of the symptoms only. If access is required later, we confirm the secure handover method separately.
Send us the URL and a short description. We only need credentials after the initial assessment.