Skip to content
Proactive security updates

WordPress Hacked? Cleanup and Recovery Without Guesswork

Redirects to unknown sites, spam in the source code, a browser warning or a suspended hosting account: we contain the incident, remove the malicious functions we find, close the entry point and restore operations — at a fixed price from €390 net after a free initial assessment.

Free initial assessment Fixed price from €390 net Also without a maintenance contract

72 h

notification deadline (Art. 33 GDPR)

6

phases in the cleanup process

30 days

backup retention under contract

24/7

monitoring after the cleanup

A compromised WordPress installation is rarely a single problem. In most cases a known flaw in an extension was exploited, after which the attacker created further access: an additional administrator account, a manipulated theme file, a scheduled task that rewrites the malicious function after every cleanup. Deleting the one conspicuous file does not end the incident, it postpones it. That is why we always work in the same order: contain, preserve, analyze, clean, harden, monitor. This page describes the process in detail. The general framework — availability, response times and prices — is on the emergency support page, and ongoing care afterwards on the WordPress maintenance page.

Acute suspicion? Call before you delete anything

+49 5123 9579000

Reachable Mon–Fri 9 am to 5 pm. Maintenance customers beyond that according to their SLA — the Enterprise tier includes weekends and public holidays.

Or report the incident online
initial assessment of the case
free
fixed-price cleanup
from €390
immediate help per hour
€95

How a WordPress Cleanup Runs

Incident, cleanup, hardening
What happens between report and release
Every step is logged — including for later evidence towards a supervisory authority or insurer.
Report
Containment
Analysis
Cleanup
Hardening
Forensic copy of files and database secured before anything is changed
Foreign administrator accounts disabled, keys and passwords rotated
Core files compared against checksums, 3 manipulated files identified
Entry point named: outdated extension with a known vulnerability
Hardening active, monitoring set up, closing report handed over
Foreign admin accounts2removed
Manipulated files3replaced
Entry pointnamedclosed
Initial assessmentfree, no commitment
Conclusionreport with cause and measures
The path from the report to a cleaned, hardened system — with interim states you can inspect at any time. Example view of an incident timeline.

How to Tell That WordPress Has Been Compromised

Not every incident announces itself with an obviously defaced homepage. Many attacks are designed to stay undetected as long as possible, because the site can then be used longer as a spam relay, a redirect target or a store for foreign files. The following signs occur most frequently in practice. If one of them applies, you should stop repairing the site yourself and first preserve its current state.

Warning in the browser or in search

Visitors see a security warning, or search results carry a notice about harmful content. This is usually the late symptom of an infection that has existed for some time.

Redirects to unknown sites

The site redirects visitors to foreign addresses — often only on certain devices, from certain countries or when the visit comes from a search engine.

Unknown user accounts

Administrator accounts appear in the user list that nobody created. Often with inconspicuous names that look like system accounts at first glance.

Mass mail sending

The hosting provider reports outgoing spam or blocks mail sending. The site is abused as a relay, which damages the deliverability of your genuine mail.

Foreign pages in the search index

Pages suddenly appear under your domain that have nothing to do with your offering. A classic sign of injected directories.

Unexplained load and errors

The site slows down without a traffic increase, the error log grows, or the host reports unusual process load. Foreign scripts are often running in the background.

What not to do in the first minutes

Do not delete suspicious files, do not restore a backup and do not uninstall an extension before the state has been preserved. Each of these actions destroys traces needed to determine the cause — and a backup from after the break-in often simply brings the malicious function back. Preserve the current state instead and report the incident.

Our Cleanup Process Step by Step

We look at the site from the outside, check suspicious responses, injected scripts and the state of availability. We then tell you what we see, how urgent it is and which fixed price applies to the cleanup. This assessment is free and commits you to nothing.

Why the Cause Matters More Than the Symptom

The visible consequences of an attack can often be removed within an hour. The real problem is the path through which the access happened. As long as that path is open, the same attack returns — frequently automated and within days, because compromised systems are passed around in the relevant lists. This is precisely why our cleanup always includes the analysis and not just the tidying up.

In practice most incidents trace back to a small number of patterns: an extension with a known and long-patched vulnerability; an administrator account without a second factor whose password came from someone else's data leak; a theme file untouched for years containing an unsafe file function; or another system in the same hosting package through which the attacker moved sideways into your installation. Which variant applies determines which hardening makes sense afterwards — and whether a cleanup is enough at all or a clean rebuild would be the more honest route.

Cleaning up means knowing the state, not guessing it

A comparison against original checksums shows exactly which files were altered. Whatever remains is assessed individually instead of being deleted wholesale. Your own customizations survive and the foreign components disappear.

  • Core files compared against official checksums
  • Themes, extensions and uploads searched for malicious patterns
  • Database checked for injected content and scheduled tasks
  • Every change documented traceably in the closing report
Result of an integrity checkdeviations found
Core files3 altered
Theme files1 suspicious
Upload directory2 foreign scripts
Scheduled tasks1 unknown entry
Administrator accounts2 foreign
Preserved before every changeforensic copy stored

After the Cleanup: What Necessarily Belongs to It

Removing the malicious functions does not yet put a website back into normal operation. Credentials must be treated as compromised, trust relationships renewed and visibility in search engines restored. The following points are part of every cleanup we do, regardless of the scale of the incident.

  • All administrator passwords reset and a second factor set up
  • Installation security keys and database credentials renewed
  • Foreign user accounts, scheduled tasks and redirects removed
  • Unmaintained or unused extensions removed rather than merely disabled
  • File permissions, execution rights in the upload directory and directory protection corrected
  • Review of removal from security lists and cleanup of the search index
  • File integrity and availability monitoring activated via our monitoring service
  • A verified backup chain established through our backup service

If personal data could be affected by an incident — contact forms, user accounts, order data, newsletter addresses — Art. 33 GDPR applies: the competent supervisory authority must be informed without undue delay and where feasible within 72 hours of becoming aware, provided there is a risk to the individuals concerned. If the risk is high, Art. 34 GDPR adds notification of those individuals. Both deadlines start at the moment you gain knowledge — not when the cleanup is complete.

We are not a law firm and do not replace legal advice. What we deliver is the technical basis for your decision: documented findings, the period of the incident, the affected areas and the measures taken. These are exactly the records that supervisory authorities and insurers ask for. Which evidence is expected is covered in our article Cyber Insurance: Which Maintenance Records Count. For systems under ongoing maintenance these records accumulate as a by-product, because every maintenance cycle is logged anyway — details on the GDPR updates page.

Fixed Prices for the Cleanup

We name the price before we start. The basis is the free initial assessment: only once we have seen how extensive the infection is and how many system components are affected do we make a binding commitment. If the analysis reveals a significantly larger scope than expected — several installations in the same hosting package, for instance — we raise that before additional effort is incurred. All prices are net plus VAT.

Fixed-Price Cleanup, Also Without a Maintenance Contract

After a free initial assessment. Included are evidence preservation, analysis, cleanup, hardening and the written closing report. An overview of all terms is on the pricing page.

Website

For WordPress websites without ordering and payment functions.

€390 one-off, net
  • Evidence preservation before the first intervention
  • Integrity check of core, theme and extensions
  • Removal of the malicious functions found
  • Credential, key and permission correction
  • Closing report with cause and measures
Request Website Cleanup
Most common case

Small online shop

For smaller WordPress shops holding customer and order data.

€990 one-off, net
  • All services of the website cleanup
  • Review of order, customer and payment data
  • Check of the checkout path for foreign scripts
  • Verification of payment and shipping integrations
  • Records for the notification under Art. 33 GDPR
Request Shop Cleanup

Online shop

For revenue-critical shops with a larger set of extensions.

€1,490 one-off, net
  • All services of the shop cleanup
  • Forensic evidence collection and incident timeline
  • Individual assessment of every installed extension
  • Restoration from a verified backup
  • Follow-up check after 14 days included
Request Cleanup

All prices net plus VAT. Individual assignments without a cleanup order are billed as immediate help at €95 per hour in 15-minute units. For customers with an ongoing maintenance contract, emergency support is included in the SLA (from €199 per month) — see SLA maintenance contract.

Clean Up, Restore a Backup or Rebuild?

Three Routes Out of a Compromised System

Which route is right is decided by the findings — not by the wish to be finished quickly.

Short route

Restore a backup

  • Included: Back online within minutes if a clean state exists
  • Included: No analysis of foreign files required
  • Not included: If the break-in dates back further, the backup is infected too
  • Not included: Content and orders since the backup point are missing
  • Not included: The entry point stays open — the attack repeats
Our default

Cleanup in place

  • Included: Content, orders and customizations are preserved
  • Included: The cause is named and the entry point closed
  • Included: Closing report as evidence for authorities and insurers
  • Included: Hardening and monitoring follow immediately
  • Not included: Takes more time than simply restoring a backup
For severe infection

Clean rebuild

  • Included: A clear cut when manipulations run deep
  • Included: An opportunity to finally drop outdated extensions
  • Not included: More effort, because content must be migrated in a controlled way
  • Not included: Custom modifications have to be rebuilt
  • Not included: Without determining the cause, a rebuild achieves nothing

Preventing a Repeat: Hardening and Ongoing Maintenance

After an incident is a good moment to get the fundamentals in order. Most attacks on WordPress do not target a specific website but scan the web automatically for known vulnerabilities. Anyone who reduces the attack surface and applies updates reliably drops out of that pattern. We implement the following measures after every cleanup — under an ongoing SLA maintenance contract they stay active permanently.

Secure the credentials

A second factor for all administrator accounts, limits on failed login attempts and separation of editorial from administrative rights. Details in the article Securing Shop Admin Access.

Updates on a fixed cadence

Critical security updates prioritized, everything else in a planned cycle with prior testing on a staging environment. The process is described on the security updates page.

Thin out the extension set

Every additional extension enlarges the attack surface. We assess the inventory by maintenance quality and remove what is not needed — instead of merely disabling it.

Server-side hardening

Remove execution rights in the upload directory, protect configuration files, close remote interfaces and set security headers. Background in the article HTTP Security Headers.

Monitoring instead of chance

File integrity, availability and response times monitored continuously, so a renewed change is noticed immediately rather than through a customer report.

A verified backup chain

Daily backups with checksums, separate storage and regular restore tests. Only a tested backup is a backup when it counts.

Suspect an incident? We will take a look

The initial assessment costs nothing and commits you to nothing. You receive an honest evaluation of how extensive the infection is and which route would be the right one.

One-off Cleanup or Ongoing Care?

AspectOne-off cleanupCleanup plus maintenance contract
TriggerThe incident has already happenedThe incident is handled and the repeat is addressed
CostOne-off from €390 netCleanup once, then from €199 per month net
Response time on a new incidentSubject to availability, no commitment8 hours, 4 hours or 45 minutes depending on tier
Monitoring afterwardsEnds when the assignment endsFile integrity and availability monitored continuously
UpdatesState at the time of the cleanupFixed cycle with a test before every deploy
RecordsClosing report on the incidentClosing report plus monthly maintenance logs

If you want to rehearse the process before it happens, our article Emergency Plan: What to Do When Your Website Is Hacked works as a guide. How malicious software is detected and removed technically is described in Malware Scanning and Cleanup for Online Shops, and how short the window is between the disclosure of a flaw and the first attack attempts is shown in WordPress Patch Window: 5 Hours to Attack. The hardening measures are summarized in WordPress Security 2026, recovery after severe incidents in Disaster Recovery. For Shopware installations facing a version jump, the Shopware major upgrade page is the right entry point.

Three Incidents, Three Different Routes

How findings differ in practice

Redirect only for search visitors
Starting point
Visits coming from a search engine landed on a foreign page while typing the address directly worked normally — the operator saw nothing unusual for weeks.
Measure
Evidence preservation, comparison of program files against checksums and analysis of the access logs down to the entry point in an outdated extension.
Result
The redirect is removed, the entry point closed and the extension replaced; the findings are documented in the closing report.
Blocked mail sending
Starting point
The hosting provider blocked mail sending because of outgoing spam. Order and contact confirmations no longer reached their recipients.
Measure
Containment, removal of the sending routine, rotation of all credentials and subsequent hardening of forms and the login area.
Result
Mail is delivered through the regular route again; the form path is protected against automated abuse.
The backup was already infected
Starting point
After a first repair attempt the malicious function returned — the restored backup dated from after the break-in.
Measure
Cleanup in place instead of another restore, then a verified backup chain with restore tests through our backup service.
Result
The state is stable, and for future cases a backup chain is in place whose restoration has actually been tested.

Illustrative, anonymized cases from our cleanup practice (project experience) — concrete figures and references are shared in a personal conversation.

Key Takeaways

  • Preserve first, then clean: deleting suspicious files immediately destroys the traces that lead to the cause
  • Without determining the entry point the attack repeats — analysis is part of every cleanup
  • Fixed prices after a free initial assessment: website from €390, small shop from €990, online shop from €1,490 net
  • If personal data is affected, the 72-hour deadline under Art. 33 GDPR runs from awareness, not from completion of the cleanup
  • After the cleanup come hardening, monitoring and a verified backup chain — under a maintenance contract from €199 per month

Frequently Asked Questions About Hacked WordPress Sites

What can we help you with?

One click is enough — everything after that is optional.

Tell us briefly about the project

Everything on this step is optional.

When would you like to start? (optional)
How can we reach you?

We usually get back to you within one business day.

By submitting you consent to the processing of your details to handle this request. Details in our privacy policy.

Related industries and regions