Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

WordPress Incident Response

Hacked WordPress site? We assess the incident and clean up your website.

Send us the site URL and briefly describe what you noticed. We respond within four hours during our service hours. Cleanup of a confirmed fixed-fee case costs €699 including VAT and includes a final report and baseline hardening.

No obligation. No passwords required. In the first step, just send the site URL and a short description of the issue.

SAMPLE #2026-0815Verified
  1. 14:02:11scan.beginwp-content/uploads/**
  2. 14:04:37malware.found/wp-content/uploads/2024/wp-x7f.php
  3. 14:06:52admin.reviewunknown user found
  4. 14:09:02contained✓ persistence removed

Result verified

Manually assessed€699 including VATBackups before any changeNo credentials in first contactPlain-language final report

Spot the symptoms

Common signs of a WordPress compromise

Redirects, unknown accounts, or spam pages may only appear under certain conditions, such as on mobile devices or when a visitor arrives from a search engine.

Acute

Visitors get redirected to unfamiliar sites

These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.

Suspected

Google shows spam pages or a security warning

After cleanup, Google still needs to review or recrawl the site. Warnings and spam results may therefore remain visible for some time.

Acute

Your host suspended the site over malware

Acute

Unknown administrator accounts have appeared

Impact

The site is blank, slow, or throwing errors

Suspected

Files or plugins reappear after being deleted

Suspected

Forms or emails are behaving strangely

Impact

Ads were rejected because of a compromised site

Free initial assessment

What the free initial assessment establishes

We review publicly visible indicators and tell you whether further action is needed and whether the incident fits the fixed-price scope.

What we check

  • visible signs of tampering
  • redirects and status codes
  • blacklist and search-index signals
  • known public indicators
  • your description of the issue
  • urgency and fixed-price eligibility

Not included in the initial assessment

  • logging in to or changing your website
  • active vulnerability, port, or load testing
  • access to the file system, database, or server
  • a conclusive assessment of possible data exfiltration
  • accepting passwords through the form or WhatsApp

Fixed fee

€699 incl. VAT

Cleanup of a confirmed WordPress installation

Includes baseline hardening, a data-exfiltration indicator review, functional testing, and a final report.

No additional costs without your prior approval.

Process

What happens during the cleanup

  1. Preserve the initial state

    Threat identified

    We create a backup, preserve available logs, and limit immediate impact.

  2. Remove malicious code

    Cleanup in progress

    We remove malware, close persistence paths, and replace modified components from trusted sources.

  3. Assess cause and scope

    Impact contained

    We review accounts, database records, scheduled tasks, and available logs for further traces and possible data-exfiltration indicators.

  4. Test and hand over

    Verified

    We harden the installation, test key functions, and document findings, changes, and remaining limitations.

Data breach assessment

Can you tell whether sensitive data was exfiltrated?

Credible indicators are often found in server logs, user changes, malware functions, database traces, and outbound connections. An absolute negative statement is only possible with complete and trustworthy logs. Our report clearly separates finding, indicator, and technical limit.

Get a data-exfiltration indicator review

Final report

What you receive after the cleanup

Our fictional sample report shows how we document findings, work performed, data-exfiltration indicators, evidential limits, and remaining follow-up tasks.

View the sample report

What's next

Which safeguards make sense after cleanup

Depending on your hosting and risk profile, WordPress hardening, server security, a firewall or WAF, tested backups, and monitoring can complement the recovery.

See hardening services

Frequently asked questions

How do I know if my WordPress site has been hacked?

Common signs include redirects to unknown sites, spam content appearing in Google, unfamiliar administrators, sudden warnings from Google or your host, and unexplained changes to files or plugins. If the cause is unclear, an initial assessment can help you decide what to do next.

How much does the cleanup cost?

Cleanup of one confirmed WordPress installation and one clearly defined incident costs €699 including VAT. Before you commission the work, we confirm in writing what is included. Any additional work requires a separate quote and your approval.

What does "response within four hours" mean?

We review your information within four hours during our service hours and reply through your chosen contact channel. The four-hour window applies to the initial assessment, not the completed cleanup.

How long does the actual cleanup take?

It depends on the scope of the incident. After the initial assessment we give you a realistic timeframe before you commission the work.

What's included in the fixed price?

Containment, removal of malware and persistence, account and database review, data-exfiltration indicator review, baseline hardening, functional testing, and a final report. See Pricing for details.

Can you determine whether data was exfiltrated?

We review available files, database, user changes, logs, and outbound connections for credible indicators. An absolute negative statement is only possible with complete and trustworthy logs — our report clearly states these limits.

Do you need my login credentials?

Not for the first contact. The form and WhatsApp are for the URL and a description of the symptoms only. If access is required later, we confirm the secure handover method separately.

Is your site redirecting visitors, showing spam, or listing unknown accounts?

Send us the URL and a short description. We only need credentials after the initial assessment.