Visitors get redirected to unfamiliar sites
These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.
Active security incident
If your WordPress site is redirecting visitors, showing unfamiliar content, or has administrator accounts you don't recognize, treat it as a possible security incident. We assess the symptoms for free, respond personally within four hours, and clean confirmed fixed-price cases for €699. The cleanup covers malware, persistence, accounts, database, data-exfiltration indicators, baseline hardening, and a final report.
These symptoms show up often in WordPress hacks. Any single one isn't proof on its own — several at once is a clear warning sign.
Visitors get redirected to unfamiliar sites
These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.
Google shows spam pages or a security warning
After cleanup, Google still needs to review or recrawl the site. Warnings and spam results may therefore remain visible for some time.
Your host suspended the site over malware
Unknown administrator accounts have appeared
The site is blank, slow, or throwing errors
Files or plugins reappear after being deleted
Forms or emails are behaving strangely
Ads were rejected because of a compromised site
In the first few minutes, the priority is preserving evidence and avoiding hasty changes that could make a later cleanup harder.
Our final report clearly separates what was actually established, what's merely an indicator, and where the available data reaches its limits. Examples from a typical initial assessment:
Read more about our indicator-based review on the data breach assessment page.
Site affected? We assess it for free.
The following pages explain scope, data breach assessment, pricing, and process.
Common signs include redirects to unfamiliar sites, spam content appearing in Google search results, unknown administrator accounts, warnings from Google or your host, and unexplained changes to files or plugins. When in doubt, a free assessment gives you clarity quickly.
Don't delete anything hastily, don't overwrite backups or logs, don't send passwords over WhatsApp or plain email, and request a free assessment. That preserves evidence and keeps the cleanup straightforward.
We review your information within four hours during our service hours and reply through your chosen contact channel. The four-hour window applies to the initial assessment, not the completed cleanup.
Cleanup of one confirmed WordPress installation and one clearly defined incident costs €699 including VAT. If further work is required, we send you a separate quote.
We review available files, database, user changes, logs, and outbound connections for credible indicators. A negative result means no credible indicators were found in the available data — not that data exfiltration is technically ruled out.