Security
WordPress hack cleanup: process and pricing orientation
When a site is compromised, you need a calm sequence — not a panic scan that deletes one spam page and leaves the backdoor. This page explains how I work, what drives cost, and howWP Security Ninja fits prevention versus a hands-on cleanup.
The recovery process
- 1
Contain
Limit damage: maintenance mode if needed, rotate credentials, revoke unknown admins, snapshot for forensics. Suspension by a host is not the same as a clean site.
- 2
Assess
Core checksums, uploads for PHP backdoors, recently changed theme/plugin files, database injections, cron/mu-plugins, and logs — file infection, DB spam, stolen access, or all three.
- 3
Clean
Remove malware and persistence (not only the visible spam page). Backdoors, rogue crons, poisoned .htaccess, and injected options get the same attention.
- 4
Harden
Firewall and login protection, least-privilege users, 2FA where appropriate, updates for the likely entry path, remove unused themes/plugins and public staging copies.
- 5
Verify
Re-scan, check Safe Browsing / Search Console security issues, spot-check spam URLs, test forms/checkout/mail, monitor logs. Request Google review only when you are confident.
Deeper write-ups: cleanup after a hack · first 30 minutes · how I approach WordPress security
Pricing orientation (no fake flat rate)
Cleanup pricing depends on reality on the server — not a marketing package name. I quote after I understand severity and access. These factors usually move the estimate:
- How deep the compromise goes (files only vs database + backdoors + cron)
- WooCommerce, memberships, or multi-site — more moving parts, more verification
- Whether you still have usable hosting / SFTP / database access
- Google Safe Browsing or host suspension already in play
- How urgently you need same-day triage vs a scheduled cleanup window
- Whether the entry path is obvious (outdated plugin) or still unknown
Same-day triage is often possible; full cleanup timing depends on depth. You get a realistic timeline once I have looked at the situation — not a promise that every infection is a two-hour job.
Product vs cleanup engagement
WP Security Ninja
Self-serve WordPress security plugin: firewall, malware scanner, login protection, scheduled scans. Best for prevention and ongoing hardening on sites you control.
wpsecurityninja.com →Larsik cleanup
Hands-on recovery when you are already hacked: contain, clean, harden, verify, and explain the entry path. Often followed by maintenance so updates do not slip again.
Security & cleanup service →What to prepare before you contact me
- Hosting and WordPress admin access (or SFTP + database)
- When you first noticed the issue
- Messages from Google, your host, or customers
- Whether you have a backup from before the hack
Common questions
Can you clean a hacked WordPress site?
Yes. Cleanup, hardening, and verification are core work — from the same person who builds WP Security Ninja. Start with the security & cleanup service when you are ready to engage.
How much does WordPress hack cleanup cost?
There is no honest flat price without seeing severity and access. Cost scales with depth of infection, WooCommerce/complexity, urgency, and whether credentials and backups are available. Share the site URL and what you are seeing for a concrete quote.
Is WP Security Ninja the same as hiring you for cleanup?
No. WP Security Ninja is a WordPress security plugin (firewall, scanner, login protection) you can run yourself for prevention and hardening. A Larsik cleanup engagement is hands-on recovery when you are already compromised — then we often install and configure hardening tools, including WP Security Ninja, so the door stays closed.
Will Google Safe Browsing warnings clear automatically?
Not instantly. Clean and harden first, then request a review when you are confident. Warnings that clear while malware remains just come back.
Do I need a new host after a hack?
Often not. Many compromises are outdated plugins, weak passwords, or no firewall — not a bad host. If the server itself is shared-compromised or unmanaged, I will say so.
What should I do in the first hour?
Do not keep logging in with the same password. Preserve access details for whoever will clean the site, avoid restoring a random old backup over evidence, and read the first-30-minutes checklist on the blog if you need a calm sequence.
Site compromised or showing warnings?
Tell me what you are seeing — host suspension, Google warning, spam pages — and we will take it from there.