Has your WordPress site been ‘hacked’?
The first 15 minutes
✅ Do this
1. Decide if the site should remain live.
If the site is stealing visitor data, redirecting to scam websites, or serving malware, deactivate it. A maintenance page for a few hours is much less serious than continuing to infect your visitors and buyers.
2. Notify your hosting provider.
Ask two specific things: if they detect the infection from their side, and if they have the access and FTP/SSH logs for the last 30 days. Request them now and save them. Many providers only keep them for one or two weeks, and these files help clarify how they got in.
3. Make a full copy of the infected site.
Yes, infected. Files and database, exactly as they are. This is not for restoration: it is the crime scene. Without it, it is impossible to know what happened or prove when it started.
4. Review administrator users.
In Users, sort by registration date. If there is any administrator you do not recognize, take note of it.
5. Check if Google already knows.
Search for site:tudominio.com on Google and see if strange results appear. Also check the Security section in Search Console.
❌ Don’t do this
1. Don’t just restore an old backup and forget about it.
This is the most common mistake. If you restore without knowing how they got in, you are also restoring the open door. They will return, sometimes within hours. A backup can be part of the solution, but never the complete solution.
2. Don’t delete suspicious files as you find them.
Every strange file is a clue about how they entered and what else they touched. Deleting things randomly destroys the trail and almost never eliminates the entire infection: it is common for there to be several backdoors spread out, some inside the database or hidden in common files.
3. Don’t install three security plugins at once.
A scanner will tell you something is there. It won’t tell you how it got in, nor will it find well-obfuscated code or clean the site. Furthermore, running several at once will cause them to interfere with each other and complicate the diagnosis.
4. Don’t just change all passwords and consider the matter closed.
Do it, but only after closing the entry point. If the backdoor is still there, new passwords only last as long as it takes the attacker to read them again.
5. Don’t delete logs or history.
Not the server logs, the panel logs, nor the hosting emails. Even if you don’t understand them, they can be useful.
Signs that your WordPress is compromised
- Google marks your site as “dangerous” or the browser shows a red warning screen.
- When searching for your website on Google, results appear in another language or for products you don’t sell.
- The site redirects to another page, but only sometimes: from mobile, or only if you arrive from Google.
- Administrator users appear that no one created.
- Your email provider starts rejecting your emails, or you end up on spam blacklists.
- There are modified files with dates that don’t match any updates.
- The server is inexplicably slow or CPU consumption spikes without more traffic.
- Your hosting has suspended your account or sent you an abuse notice.
- You see
.phpfiles or plugins that do not belong to the website.
If you recognize two or more, it’s not a false positive. Also keep in mind that the absence of these signs does not mean the site is not compromised; they may have access but haven’t used it yet.
What we do when we handle an incident like this
1. Containment
The first thing is to stop the bleeding: isolate the site if necessary, close compromised access points, and ensure the infection doesn’t continue spreading to other sites on the same server.
2. Diagnosis
We analyze files, database, and logs to better understand what happened: where they entered, when, and how far they got. Without this, any cleanup is temporary.
3. Manual cleanup
There is no button or plugin that works here. We review the code by hand, including obfuscated code and code hidden in places a scanner doesn’t look: the database, configuration files, legitimate-looking plugins, and code embedded in core files. We remove the malicious code while preserving your content and data.
4. Closing the entry point
Updating or replacing the vulnerable component, reviewing permissions and users, and hardening the configuration. In short, securing the site to prevent it from happening again. Additionally, we will recommend a maintenance service so it doesn’t happen again.
5. Recovery and verification
Site back up and running, request for review to Google if it had marked the site as malicious, and subsequent verification that nothing has returned. We explain what happened, what we found, and what we recommend to prevent a recurrence.
We start by finding out what happened
We cannot give you a cleanup price without looking. Anyone who gives you one over the phone is guessing: there are infections resolved in two hours and others that require a reconstruction.
That’s why the first step is a fixed-price diagnosis: €450 + VAT. It includes:
- Analysis of available files, database, and logs.
- Identification of the possible entry point and the actual scope of the intrusion.
- Description of what we found and what it implies.
- Quote for cleanup and securing, if you decide to proceed.
No obligation to continue. If, after the report, you prefer your team to resolve it, it’s yours and we’ll explain it to you.
We’ve done this before
Manual cleanup, not automatic.
Scanners detect what is known. Well-obfuscated code, backdoors, database changes, and files with innocent names are found by reading, not scanning.
You speak directly with the person touching the code.
There is no first level, no bouncing tickets, and no summary lost along the way. In an emergency, every bounce between departments costs hours.
We know WordPress inside out.
We are part of the WordPress.org plugin review team, which maintains the official repository with over 60,000 active plugins. We see plugin code every week and know which patterns end up being a problem.
Over a decade of critical WordPress projects, including rescues of installations that no one else wanted to touch.
Real case
Vulnerability in a hosting provider: multiple sites infected at once.
A breach in the provider’s infrastructure compromised several sites simultaneously. Manual cleanup of each, removing hidden and obfuscated malicious code, and coordination for the provider to close the actual hole.
Prevent it from happening again
A clean site today is not a secure site tomorrow. Most intrusions we see are not targeted attacks: they are bots roaming the internet testing known vulnerabilities in outdated plugins. Real defense consists of keeping things up to date.
When we finish a cleanup, we give you instructions to keep your site secure for the future. And if you prefer not to handle it yourself, our technical maintenance service includes managed updates, monitoring, and continuous security reviews.
Frequently Asked Questions
Can’t my hosting provider clean it?
Sometimes yes, and if that’s your case, go ahead. Usually, they restore a previous backup, which brings the site back to life but doesn’t close the vulnerability. If it has already happened to you twice, that is exactly what occurred.
What about a security plugin like Wordfence or Sucuri?
They are good tools and we use them. But they detect known patterns: they don’t analyze how they got in, they don’t find well-obfuscated code, and they don’t clean the database. They serve to let you know you have a problem, not to solve it.
Will I lose content?
It’s the first thing we preserve. We work on copies and the goal is always to clean without touching your content or data. In extreme cases, there may be isolated losses; if that were the scenario, you would know before we did anything.
How long does it take?
It depends on how they got in and how long they’ve been inside. A clear case can be resolved in hours; a months-long infection on a large site takes days. We will give you a time estimate in the diagnosis.
Will I recover my Google ranking?
Usually yes, if action is taken quickly. The more time that passes with injected content or the “dangerous site” label, the harder it is. This is the main reason not to leave it until Monday.
They may have accessed my customers’ data. Do I need to do anything?
Possibly yes. The GDPR requires the data controller to notify certain security breaches to the supervisory authority—in Spain, the AEPD—within 72 hours of becoming aware of it, and in some cases, to inform the affected individuals as well. We are not legal advisors, and that assessment corresponds to your legal team.
It’s Friday afternoon / the weekend. What do I do?
Write to us anyway; the form is always open and will be attended to first thing the next business day. Sometimes even sooner. In the meantime, apply the “First 15 minutes” advice above: with that, you contain the damage and preserve the evidence. If the site is serving malware to your visitors, deactivate it and wait; a few hours of a maintenance page won’t fix anything, but it won’t make anything worse either.
Tell us what happened
The more context you give us, the faster we can tell you if and how we can help.
Security incidents take priority over all other matters: you will receive a quick response, possibly outside of regular business hours.
Talk to us
Briefly tell us what you need: what is happening, what type of project it is and, if possible, its scope. The more context you provide, the better we can advise you.