WordPress site hacked? I remove the malware and get Google to trust it again
If your WordPress site was hacked, the order matters: first lock the attacker out, then remove the malware from the files and the database, then close the hole they came in through, and only then ask Google to review the site. I do the four steps, usually within 24 to 48 hours, for a fixed price from 59 USD.
One WordPress site with a typical infection. If it is deeper than that (reinfection from other sites on the same hosting, hundreds of modified files) I tell you the final price before I start.
Sound familiar?
- Visitors get redirected to spam, casino or pharmacy sites, often only on mobile or only from Google.
- Google shows "This site may be hacked" or Chrome shows "Deceptive site ahead".
- Google Ads disapproved your ads for "Compromised site".
- There are administrator users you did not create, or your password stopped working.
- Your hosting suspended the account or warned you about malware or spam emails.
- Strange PHP files inside wp-content/uploads or new plugins you never installed.
Why it happens
- An outdated plugin or theme. This is the most common entry point. Attackers scan for known holes in old versions of popular plugins.
- A nulled or pirated theme. Paid themes downloaded from unofficial sites often come with a backdoor already inside.
- Weak or reused passwords. Admin, hosting, FTP or database passwords reused from another service that was leaked.
- Another site on the same hosting. On shared hosting, one infected site can reinfect every other site in the same account.
How I fix it
Full backup of the infected site as it is, so nothing is lost and there is a record of what was found.
Lock the attacker out: new passwords for WordPress, hosting, database and FTP, unknown admins removed and sessions closed.
Clean: WordPress core replaced with a clean copy, plugins and themes reinstalled from official sources, uploads and database checked for injected code.
Close the hole: updates, abandoned plugins removed and basic hardening, such as disabling file editing from the dashboard.
Ask Google to review: security issues in Search Console and, if your ads were stopped, a review request for the compromised site policy in Google Ads.
What is included
- Malware removal from files and database.
- Attacker locked out and all credentials changed.
- Updates and hardening so it does not happen again the same way.
- Review requests in Search Console and Google Ads.
- A short report: how they got in, what was found and what was changed.
- If it comes back through the same hole, I clean it again at no cost.
Client blog on WordPress with cPanel hosting: the site was infected and the attacker had changed the database password. I recovered access through cPanel and phpMyAdmin, then cleaned the site, updated it and hardened it against new attacks.
Guides
Frequently asked questions
How long until Google removes the warning?
Once the site is clean I send the review request in Search Console. Google usually answers in a few days; for Google Ads, the ads run again after Google re-checks the site and approves it.
Will I lose my content?
No. Posts, pages, products and orders stay. Only infected files and injected code are removed, and there is a full backup before I touch anything.
My Google Ads were disapproved for "Compromised site". Is that the same problem?
Yes. Google found malware or hacked content on your landing page. The ads can't be approved again until the site is clean, so the cleanup comes first and the review request in Google Ads comes right after.
What access do you need?
A WordPress administrator user and hosting access (cPanel, hPanel or FTP). You change all the passwords again when the job is done.
Do I need to pay for a security plugin?
Not necessarily. Keeping everything updated and using strong, unique passwords prevents most attacks. If your site needs a firewall I tell you which one and why.
Other services
Something broken or worth automating?
Tell me what is happening. You get an answer the same day with what I see and a proposal.