Skip to content
WP Hack FixEst. 2005

How it works

From hacked to handled

No jargon, no guesswork. Here's exactly what happens after you reach out.

  1. 1

    Tell us what's wrong

    Pick a plan and tell us what you're seeing. We reply within 1 business day with a secure, self-destructing link for your logins.

  2. 2

    We clean it

    We remove the malware, backdoors, spam, and rogue users by hand, and check the files, database, and scheduled tasks that automated scanners miss.

  3. 3

    We lock it down

    We update what's outdated, close the hole they came in through, harden the site, and request removal from Google and browser blocklists.

  4. 4

    You get a report

    A plain-English report of what we found, how they got in, what we fixed, and what we recommend next.

Step 1 in detail

Your passwords never sit in an email

To clean your site we need your WordPress admin login and your hosting login (or SFTP details). We send you a secure, self-destructing link to share them. It can be read once, then it's gone.

When we're done, we'll remind you to change your passwords and remove any temporary accounts.

What we'll ask for

  • WordPress admin login (or a temporary admin account for us)
  • Hosting control panel login, or SFTP/SSH access
  • Your hosting company's name

Step 2 in detail

What we check

Malware rarely lives in one place. We go through every spot it tends to hide, by hand, so it doesn't come back a week later.

Files

WordPress core, themes, plugins, and uploads, compared against known-good copies to find modified and injected files.

Database

Posts, options, and widgets, checked for injected scripts, spam links, and hidden redirects.

Users

Rogue administrator accounts and changed permissions.

Scheduled tasks

WordPress cron jobs and server tasks that quietly reinstall malware.

Server config

.htaccess rules, must-use plugins, and PHP settings that hide redirects or backdoors.

Blocklists

Google Safe Browsing and other blocklists, with removal requests once the site is clean.

Step 3 in detail

How we lock it down

  • Update WordPress, themes, and plugins, and remove anything abandoned or unused
  • Reset WordPress security keys, which logs everyone out
  • Remove unknown admin users and tighten user roles
  • Lock down file permissions and disable file editing in the dashboard
  • Close the specific hole they used to get in, when we can identify it

Step 4 in detail

What's in your report

  • What we found, and where
  • How they most likely got in
  • Everything we removed and fixed
  • Hardening we applied
  • Blocklist status
  • What you should do next

Written in plain English, so you can share it with your host, your team, or your customers.

After the cleanup

One-time cleanups include 14 days of coverage. If you'd rather not worry about it again, a Protect plan keeps your site updated, backed up, and monitored, and we re-clean it at no charge if anything gets through.

Cleanups are typically completed within 1–2 business days of receiving access.

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)