WordPress Malware Removal

Remove the injected files. Rebuild the server if root was taken.

Unknown admins, a pharma redirect, a cron you did not add. Cleanup starts at €149. A miner or a new SSH key is not a plugin cleanup.

What we look for

Users, files, cron. In that order.

Unknown admins

A user created the night of the redirect. We remove it, rotate the salts and the database password, and check the web user cannot write wp-config.php.

Injected files

PHP in uploads, a modified core file, a theme function that loads a remote script. Core is replaced from a clean copy. Uploads are not bulk-deleted.

Cron and the OS

A crontab under the web user, or a process that is not PHP. If the OS has a new UID 0 or an SSH key you did not add, cleanup of the site is the wrong job.

When €149 is not the job

A rooted box is a rebuild

We say that after the first look, before billing a file-by-file clean of a host that will reinfect itself. Sites and mail come back from a copy that predates the break-in, onto a new server. That is quoted.

Server security → · Server recovery →

Price

From €149 for a site. The OS is a different quote.

One WordPress install, files and users. Several sites, or WooCommerce with a large upload directory, is quoted after the size is known. We do not sell a “cleaned forever” guarantee. A nulled plugin will bring it back.

WordPress support → · Pricing →

Redirect, warning in Search Console, or a user you did not create?

Tell us the host and what you saw. No admin password in the first message.

Request Support → Contact Us