WordPress malware removal and hacked site cleanup
Japanese keyword hack, pharma and casino spam, hidden redirects, defaced pages. We remove the infection, find the hole it came through and close it, then get your listing in Google back to normal. You get a written report of what was found and what was changed.
Get my site checked →Most hacked WordPress sites we see fall into three groups.
The symptoms differ, the entry point is usually the same: an outdated plugin, a weak admin password, or a neighbouring site on shared hosting.
Japanese keyword hack
Google shows hundreds of Japanese-language pages under your domain, selling counterfeit goods. Your own pages disappear from the results.
- Injected pages in the sitemap
- A rogue user in Search Console
- Cloaking - the spam is served only to Googlebot
Pharma and casino spam
Your pages look untouched in the browser, but in the search results the titles and descriptions advertise pills, loans or casinos.
- Modified meta descriptions
- Hidden links in the footer
- Conditional output by user agent
Malicious redirects and defacement
Visitors land on someone else's site, or the mobile version redirects while the desktop one looks fine. In the worst case the homepage is replaced outright.
- Injected JavaScript
- Rules added to .htaccess
- Backdoors in the uploads folder
Deleting the infected files is the easy part. Keeping them out is the job.
We find the entry point
A cleanup that only removes files buys you a few days. We trace how the attacker got in - the vulnerable plugin, the leaked password, the writable directory - and close that specific hole.
We repair the Google side
Removing malware does not remove you from the spam index. We clean the sitemap, revoke the attacker's Search Console access, remove the injected URLs and file for reconsideration where a manual action was issued.
Days of monitoring after handover
You also get a written report: what was infected, which files changed, which entry point was used, what we hardened. Plain language, so you can hand it to your hosting provider or your client.
From infected to clean, step by step.
Scan and backup
We take a full copy of files and database before touching anything, then map the infection: what is modified, what is injected, when it started.
Removal
Core, plugin and theme files are compared against clean originals. Injected code is stripped, backdoors and rogue admin accounts are removed.
Closing the door
Updates, file permissions, disabled PHP execution in uploads, two-factor on the admin, and a login URL that is not /wp-admin.
Recovery in Google
Clean sitemap, removal of spam URLs, revoked attacker access in Search Console, reconsideration request, then monitoring until impressions recover.
Questions about hacked site cleanup
Not sure whether your site is infected? Send us the URL - the initial check costs nothing.
DIAGNOSISHow do I know my WordPress site has been hacked?
JAPANESE HACKWhat is the Japanese keyword hack and why did it target my site?
GOOGLEHow do I remove the "This site may have been hacked" warning from Google?
RANKINGSWill my Google rankings come back after the cleanup?
DIYCan I clean a hacked WordPress site myself?
PRICEHow much does WordPress malware removal cost?
TIMELINEHow long does the cleanup take?
PREVENTIONHow do I stop it from happening again?
Send us the URL of the affected site. The initial check is free and we tell you what we find within 24 hours - whether or not you hire us for the cleanup.
Get my site checked