WordPress Hacked? Cleanup and Recovery Without Guesswork
Redirects to unknown sites, spam in the source code, a browser warning or a suspended hosting account: we contain the incident, remove the malicious functions we find, close the entry point and restore operations — at a fixed price from €390 net after a free initial assessment.
72 h
notification deadline (Art. 33 GDPR)
6
phases in the cleanup process
30 days
backup retention under contract
24/7
monitoring after the cleanup
A compromised WordPress installation is rarely a single problem. In most cases a known flaw in an extension was exploited, after which the attacker created further access: an additional administrator account, a manipulated theme file, a scheduled task that rewrites the malicious function after every cleanup. Deleting the one conspicuous file does not end the incident, it postpones it. That is why we always work in the same order: contain, preserve, analyze, clean, harden, monitor. This page describes the process in detail. The general framework — availability, response times and prices — is on the emergency support page, and ongoing care afterwards on the WordPress maintenance page.
Acute suspicion? Call before you delete anything
+49 5123 9579000Reachable Mon–Fri 9 am to 5 pm. Maintenance customers beyond that according to their SLA — the Enterprise tier includes weekends and public holidays.
Or report the incident online- initial assessment of the case
- free
- fixed-price cleanup
- from €390
- immediate help per hour
- €95
How a WordPress Cleanup Runs
How to Tell That WordPress Has Been Compromised
Not every incident announces itself with an obviously defaced homepage. Many attacks are designed to stay undetected as long as possible, because the site can then be used longer as a spam relay, a redirect target or a store for foreign files. The following signs occur most frequently in practice. If one of them applies, you should stop repairing the site yourself and first preserve its current state.
Warning in the browser or in search
Visitors see a security warning, or search results carry a notice about harmful content. This is usually the late symptom of an infection that has existed for some time.
Redirects to unknown sites
The site redirects visitors to foreign addresses — often only on certain devices, from certain countries or when the visit comes from a search engine.
Unknown user accounts
Administrator accounts appear in the user list that nobody created. Often with inconspicuous names that look like system accounts at first glance.
Mass mail sending
The hosting provider reports outgoing spam or blocks mail sending. The site is abused as a relay, which damages the deliverability of your genuine mail.
Foreign pages in the search index
Pages suddenly appear under your domain that have nothing to do with your offering. A classic sign of injected directories.
Unexplained load and errors
The site slows down without a traffic increase, the error log grows, or the host reports unusual process load. Foreign scripts are often running in the background.
What not to do in the first minutes
Our Cleanup Process Step by Step
Initial assessment and classification
We look at the site from the outside, check suspicious responses, injected scripts and the state of availability. We then tell you what we see, how urgent it is and which fixed price applies to the cleanup. This assessment is free and commits you to nothing.
Containment and evidence preservation
Before the first intervention we secure the filesystem and database as a forensic copy. We then contain the incident: terminate foreign sessions, disable unknown administrator accounts, rotate keys and passwords and, where needed, activate a maintenance page.
Analysis of files and database
We compare core files against the official checksums, search themes, extensions and upload directories for malicious patterns and check the database for injected content, manipulated options and scheduled tasks that would undo a cleanup.
Determine cause and entry point
From access logs, file timestamps and version levels we reconstruct how the access came about: an outdated extension, a weak administrator password, a stolen credential or a neighbouring system in the same hosting package. Without this step, a cleanup is only cosmetic.
Cleanup and restoration
We replace core, themes and extensions with clean original versions, remove the malicious functions we found, clean the database and restore missing content from a verified backup. We then test login, forms and — where present — the order path.
Hardening, monitoring and report
Finally we harden the installation, set up file integrity and availability monitoring and hand over a report with findings, cause, measures taken and open recommendations. That report is also the basis for notifications to a supervisory authority or insurer.
We look at the site from the outside, check suspicious responses, injected scripts and the state of availability. We then tell you what we see, how urgent it is and which fixed price applies to the cleanup. This assessment is free and commits you to nothing.
Before the first intervention we secure the filesystem and database as a forensic copy. We then contain the incident: terminate foreign sessions, disable unknown administrator accounts, rotate keys and passwords and, where needed, activate a maintenance page.
We compare core files against the official checksums, search themes, extensions and upload directories for malicious patterns and check the database for injected content, manipulated options and scheduled tasks that would undo a cleanup.
From access logs, file timestamps and version levels we reconstruct how the access came about: an outdated extension, a weak administrator password, a stolen credential or a neighbouring system in the same hosting package. Without this step, a cleanup is only cosmetic.
We replace core, themes and extensions with clean original versions, remove the malicious functions we found, clean the database and restore missing content from a verified backup. We then test login, forms and — where present — the order path.
Finally we harden the installation, set up file integrity and availability monitoring and hand over a report with findings, cause, measures taken and open recommendations. That report is also the basis for notifications to a supervisory authority or insurer.
Why the Cause Matters More Than the Symptom
The visible consequences of an attack can often be removed within an hour. The real problem is the path through which the access happened. As long as that path is open, the same attack returns — frequently automated and within days, because compromised systems are passed around in the relevant lists. This is precisely why our cleanup always includes the analysis and not just the tidying up.
In practice most incidents trace back to a small number of patterns: an extension with a known and long-patched vulnerability; an administrator account without a second factor whose password came from someone else's data leak; a theme file untouched for years containing an unsafe file function; or another system in the same hosting package through which the attacker moved sideways into your installation. Which variant applies determines which hardening makes sense afterwards — and whether a cleanup is enough at all or a clean rebuild would be the more honest route.
Cleaning up means knowing the state, not guessing it
A comparison against original checksums shows exactly which files were altered. Whatever remains is assessed individually instead of being deleted wholesale. Your own customizations survive and the foreign components disappear.
- Core files compared against official checksums
- Themes, extensions and uploads searched for malicious patterns
- Database checked for injected content and scheduled tasks
- Every change documented traceably in the closing report
After the Cleanup: What Necessarily Belongs to It
Removing the malicious functions does not yet put a website back into normal operation. Credentials must be treated as compromised, trust relationships renewed and visibility in search engines restored. The following points are part of every cleanup we do, regardless of the scale of the incident.
- All administrator passwords reset and a second factor set up
- Installation security keys and database credentials renewed
- Foreign user accounts, scheduled tasks and redirects removed
- Unmaintained or unused extensions removed rather than merely disabled
- File permissions, execution rights in the upload directory and directory protection corrected
- Review of removal from security lists and cleanup of the search index
- File integrity and availability monitoring activated via our monitoring service
- A verified backup chain established through our backup service
Notification Duties and Legal Consequences
If personal data could be affected by an incident — contact forms, user accounts, order data, newsletter addresses — Art. 33 GDPR applies: the competent supervisory authority must be informed without undue delay and where feasible within 72 hours of becoming aware, provided there is a risk to the individuals concerned. If the risk is high, Art. 34 GDPR adds notification of those individuals. Both deadlines start at the moment you gain knowledge — not when the cleanup is complete.
We are not a law firm and do not replace legal advice. What we deliver is the technical basis for your decision: documented findings, the period of the incident, the affected areas and the measures taken. These are exactly the records that supervisory authorities and insurers ask for. Which evidence is expected is covered in our article Cyber Insurance: Which Maintenance Records Count. For systems under ongoing maintenance these records accumulate as a by-product, because every maintenance cycle is logged anyway — details on the GDPR updates page.
Fixed Prices for the Cleanup
We name the price before we start. The basis is the free initial assessment: only once we have seen how extensive the infection is and how many system components are affected do we make a binding commitment. If the analysis reveals a significantly larger scope than expected — several installations in the same hosting package, for instance — we raise that before additional effort is incurred. All prices are net plus VAT.
Fixed-Price Cleanup, Also Without a Maintenance Contract
After a free initial assessment. Included are evidence preservation, analysis, cleanup, hardening and the written closing report. An overview of all terms is on the pricing page.
Website
For WordPress websites without ordering and payment functions.
- Evidence preservation before the first intervention
- Integrity check of core, theme and extensions
- Removal of the malicious functions found
- Credential, key and permission correction
- Closing report with cause and measures
Small online shop
For smaller WordPress shops holding customer and order data.
- All services of the website cleanup
- Review of order, customer and payment data
- Check of the checkout path for foreign scripts
- Verification of payment and shipping integrations
- Records for the notification under Art. 33 GDPR
Online shop
For revenue-critical shops with a larger set of extensions.
- All services of the shop cleanup
- Forensic evidence collection and incident timeline
- Individual assessment of every installed extension
- Restoration from a verified backup
- Follow-up check after 14 days included
All prices net plus VAT. Individual assignments without a cleanup order are billed as immediate help at €95 per hour in 15-minute units. For customers with an ongoing maintenance contract, emergency support is included in the SLA (from €199 per month) — see SLA maintenance contract.
Clean Up, Restore a Backup or Rebuild?
Three Routes Out of a Compromised System
Which route is right is decided by the findings — not by the wish to be finished quickly.
Restore a backup
- Included: Back online within minutes if a clean state exists
- Included: No analysis of foreign files required
- Not included: If the break-in dates back further, the backup is infected too
- Not included: Content and orders since the backup point are missing
- Not included: The entry point stays open — the attack repeats
Cleanup in place
- Included: Content, orders and customizations are preserved
- Included: The cause is named and the entry point closed
- Included: Closing report as evidence for authorities and insurers
- Included: Hardening and monitoring follow immediately
- Not included: Takes more time than simply restoring a backup
Clean rebuild
- Included: A clear cut when manipulations run deep
- Included: An opportunity to finally drop outdated extensions
- Not included: More effort, because content must be migrated in a controlled way
- Not included: Custom modifications have to be rebuilt
- Not included: Without determining the cause, a rebuild achieves nothing
Preventing a Repeat: Hardening and Ongoing Maintenance
After an incident is a good moment to get the fundamentals in order. Most attacks on WordPress do not target a specific website but scan the web automatically for known vulnerabilities. Anyone who reduces the attack surface and applies updates reliably drops out of that pattern. We implement the following measures after every cleanup — under an ongoing SLA maintenance contract they stay active permanently.
Secure the credentials
A second factor for all administrator accounts, limits on failed login attempts and separation of editorial from administrative rights. Details in the article Securing Shop Admin Access.
Updates on a fixed cadence
Critical security updates prioritized, everything else in a planned cycle with prior testing on a staging environment. The process is described on the security updates page.
Thin out the extension set
Every additional extension enlarges the attack surface. We assess the inventory by maintenance quality and remove what is not needed — instead of merely disabling it.
Server-side hardening
Remove execution rights in the upload directory, protect configuration files, close remote interfaces and set security headers. Background in the article HTTP Security Headers.
Monitoring instead of chance
File integrity, availability and response times monitored continuously, so a renewed change is noticed immediately rather than through a customer report.
A verified backup chain
Daily backups with checksums, separate storage and regular restore tests. Only a tested backup is a backup when it counts.
Suspect an incident? We will take a look
The initial assessment costs nothing and commits you to nothing. You receive an honest evaluation of how extensive the infection is and which route would be the right one.
One-off Cleanup or Ongoing Care?
| Aspect | One-off cleanup | Cleanup plus maintenance contract |
|---|---|---|
| Trigger | The incident has already happened | The incident is handled and the repeat is addressed |
| Cost | One-off from €390 net | Cleanup once, then from €199 per month net |
| Response time on a new incident | Subject to availability, no commitment | 8 hours, 4 hours or 45 minutes depending on tier |
| Monitoring afterwards | Ends when the assignment ends | File integrity and availability monitored continuously |
| Updates | State at the time of the cleanup | Fixed cycle with a test before every deploy |
| Records | Closing report on the incident | Closing report plus monthly maintenance logs |
If you want to rehearse the process before it happens, our article Emergency Plan: What to Do When Your Website Is Hacked works as a guide. How malicious software is detected and removed technically is described in Malware Scanning and Cleanup for Online Shops, and how short the window is between the disclosure of a flaw and the first attack attempts is shown in WordPress Patch Window: 5 Hours to Attack. The hardening measures are summarized in WordPress Security 2026, recovery after severe incidents in Disaster Recovery. For Shopware installations facing a version jump, the Shopware major upgrade page is the right entry point.
Three Incidents, Three Different Routes
How findings differ in practice
Illustrative, anonymized cases from our cleanup practice (project experience) — concrete figures and references are shared in a personal conversation.
Key Takeaways
- Preserve first, then clean: deleting suspicious files immediately destroys the traces that lead to the cause
- Without determining the entry point the attack repeats — analysis is part of every cleanup
- Fixed prices after a free initial assessment: website from €390, small shop from €990, online shop from €1,490 net
- If personal data is affected, the 72-hour deadline under Art. 33 GDPR runs from awareness, not from completion of the cleanup
- After the cleanup come hardening, monitoring and a verified backup chain — under a maintenance contract from €199 per month