Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Methodology

How we investigate and clean up WordPress incidents

We capture the baseline state first, contain the active incident, then systematically review files, database, accounts, and scheduled tasks. Detected malware and persistence mechanisms are removed, integrity is checked against vendor checksums where available, and the site is functionally tested at the end. Every step is documented in the final report.

Our step-by-step approach

This sequence protects evidence from accidental alteration and prevents a site from being handed back without final verification.

Sample incident report

Every completed case is documented in a plain-language report. Every report includes these sections:

Example of the timeline in a final report. The displayed data is fictional:

Illustrative structureVerified
  1. T+0hbackup.createdbaseline captured
  2. T+1hcontainedactive damage stopped
  3. T+—malware.removedpersistence removed
  4. T+—report.delivered✓ final report

Anonymized sample report

The sample report contains fictional data only. It shows the structure and level of detail used in a final report.
Open sample report →

Active incident? We assess it for free.