Service & scope of work
WordPress malware removal: a documented cleanup for a fixed fee
We clean a confirmed WordPress installation for a fixed fee of €699 including VAT. That covers containment, removal of malware and persistence, account and database review, an indicator-based data-exfiltration review, baseline hardening, functional testing, and a plain-language final report. You get the initial assessment for this within four hours.
Fixed fee
€699 incl. VAT
The price covers one WordPress installation and one clearly defined incident. If further work is required, we send you a separate quote and wait for your approval before starting.
Full pricing overview →What's included in the fixed fee
The fixed fee covers the following assessment, cleanup, and handover work:
- Baseline capture before any changes are made
- Controlled containment of the active incident
- File, database, user, and cron review
- Removal of detected malware, web shells, and persistence
- Replacement of tampered WordPress core files
- Review and clean replacement of verifiable plugins and themes
- Review of uploads, cache, and backup areas for executable malicious code
- Review for suspicious administrators, sessions, and application passwords
- Rotation, or guidance for rotating, key WordPress secrets
- Indicator-based data-exfiltration review within the available data and logs
- Baseline WordPress and file-permission hardening
- Baseline blocks on PHP execution in unsuitable runtime directories
- Frontend, login, REST, and core functionality testing
- Checksum / integrity verification, where vendor data is available
- A plain-language final report covering findings, actions, limits, and follow-up tasks
Not included in the fixed fee
These cases fall outside the fixed-fee scope or require a separate quote before work starts:
- Multiple websites or a WordPress multisite installation
- A compromised operating system, root account, or entire hosting account
- DDoS mitigation and ongoing active network-level attacks
- Extensive repair of custom-developed plugins or themes
- Recovery of lost business or store data
- Paid plugin, theme, CDN, or security licenses
- Cleanup of external email, registrar, cloud, or advertising accounts
- Legally admissible forensic reports and chain-of-custody evidence
- Data protection or legal advice
- Extensive Google Ads, Merchant Center, or Search Console rehabilitation
- Server migrations or infrastructure rebuilds
- Cases with no trustworthy package source available
Process
What happens during the cleanup
Preserve the initial state
Threat identifiedWe create a backup, preserve available logs, and limit immediate impact.
Remove malicious code
Cleanup in progressWe remove malware, close persistence paths, and replace modified components from trusted sources.
Assess cause and scope
Impact containedWe review accounts, database records, scheduled tasks, and available logs for further traces and possible data-exfiltration indicators.
Test and hand over
VerifiedWe harden the installation, test key functions, and document findings, changes, and remaining limitations.
Ready for your initial assessment?