pixelgravitas
Report a Hack

Home/Website Maintenance/Malware Removal

Malware removal

WordPress malware removal services that close the way in, not just clean the files.

Short answer: hacked WordPress sites are cleaned, the entry point is found and fixed, and Google, browser and host warnings are lifted once the site is clean. Without a plan, the job is quoted as a fixed fee before any work starts. On the Care + Secure plan, a hack is an emergency with a response target of 2 hours in business hours and 4 hours outside them.

Fixed fee quoted before work starts A written report of what was found
Emergency2 hrsTarget in business hours, on Care + Secure
Out of hours4 hrsNights and weekends, on Care + Secure
PricingFixed feeQuoted before any work starts
AfterwardsWrittenWhat happened, what was fixed, what prevents it

Is it hacked?

Signs your WordPress site
has malware.

A hacked WordPress site rarely announces itself. These are the signs that bring most owners to us, usually after a customer or Google notices first.

Redirects to spamVisitors, often only on mobile or from Google, get sent to pharmacy, casino or scam sites.
Google warnings"This site may be hacked" in search results, or a red "Deceptive site ahead" screen in the browser.
Spam pages in searchThousands of pages you never wrote, often in Japanese or selling products, showing under your domain.
Host suspensionYour hosting company disables the account or a folder because it found malicious files.
Admins you didn't createUnknown administrator accounts, or your own password suddenly stops working.
Email going to spamYour domain lands on blocklists because the server has been used to send spam.

The first hour

What to do right now
if your WordPress site is hacked.

Whether or not you hire anyone, these four steps make WordPress malware removal faster and stop the damage spreading. What not to do matters as much.

1Don't

Don't delete everything

Wiping files or restoring blindly destroys the evidence of how they got in, so it happens again.

2Copy

Keep a copy as it is

Download the files and database in their infected state, or ask your host for a snapshot.

3Lock

Change key passwords

Hosting control panel, WordPress admins, database and FTP/SFTP. From a clean device.

4Tell

Report it once

Send the site address and what you've seen. One clear message beats five partial ones.

Report a hacked site →

How the cleanup works

How we remove malware
from a WordPress site.

Most reinfections happen because the malware was cleaned but the way in was left open. Our WordPress malware removal services are built around finding and closing that entry point.

1 · ContainStop the damageRedirects, spam pages and injected scripts stopped first, so visitors and search engines stop seeing them.Containfirst
2 · FindFiles, database, users, scheduled tasksAutomated scans plus a manual review, because obfuscated backdoors are routinely missed by scanners alone.Scan + manualboth
3 · CleanReplace, don't patchWordPress core, plugins and themes replaced with clean copies from their official sources; infected database entries removed.Clean copiesofficial sources
4 · CloseThe way inThe vulnerable plugin, weak login, leaked password or outdated PHP that let it happen, fixed. Security keys rotated and sessions logged out.Entry pointfixed
5 · LiftWarnings & blocklistsReview requests to Google once the site is clean, and help with host or blocklist removals.Warningsrequested off
6 · ReportIn writingWhat was found, how they got in, what was changed and what stops it recurring.Reportwritten

Why sites get reinfected

A quick clean-up vs
a proper one.

 Quick clean-upHow we clean a hacked WordPress site
Infected filesDeleted where a scanner flags them.Core, plugins and themes replaced from clean sources.
BackdoorsOften missed, so the attacker walks back in.Searched for manually in files, database and scheduled tasks.
Entry pointRarely identified.Found and fixed, and named in the report.
Passwords & keysLeft as they were.Changed, security keys rotated, sessions logged out.
Google & host warningsLeft for you to sort out.Review requested once the site is clean.
What you get"It's clean now."A written report you can keep.

Plugin or service?

When a malware plugin is enough,
and when it isn't.

Security plugins are good at detecting known malware. Removing it safely, and closing the way in, is what WordPress malware removal services are for.

A plugin is often enoughA single flagged file, caught early, on a site you can restore from a known clean backup.
Get help when…Google or your host has flagged the site, it keeps coming back, you can't log in, or customer or payment data may be involved.
Either wayUpdate everything, remove plugins you don't use, and turn on two-factor login for every admin.

After the cleanup

Keeping it clean
once it's fixed.

One-off, then on your ownYou get the report and the recommendations, and carry on from there.
Care + SecureContinuous malware monitoring, hardening, daily off-site backups and an emergency response target if it ever happens again.Compare plans →
Not only WordPressWooCommerce stores and custom PHP sites are cleaned the same way; checkout and payments are tested before the site reopens.Emergency support →

Who you're dealing with

Who cleans
your site.

You're handing someone the keys to your website. You should know who they are.

NK

Naveen Kumar

Founder & lead engineer · Based in Chennai, India, working with clients across the US, UK, Europe and Australia

I built and ran WordPress, WooCommerce and custom-coded sites for clients directly for years before starting PixelGravitas — writing the code, managing the servers, staying on call when something broke. If your site goes down, you're talking to the person who fixes it, not a support queue. More about how I work →

Questions, answered

WordPress malware removal:
common questions.

How much does WordPress malware removal cost?

Without a plan, our WordPress malware removal services are quoted as a fixed fee before any work starts, based on the size of the site and how deep the infection goes. You know the price before you say yes. Malware monitoring and emergency response are part of the Care + Secure plan.

How fast can you respond to a hacked site?

On Care + Secure, a hacked site is an emergency with a response target of 2 hours in business hours and 4 hours outside them, including nights and weekends. Without a plan, you get a fixed quote first and work starts once you approve it.

How do I know if my WordPress site is hacked?

Common signs are redirects to spam sites, a Google warning in search results or the browser, spam pages under your domain, unknown admin users, a host suspension, or your email suddenly landing in spam.

Can I remove WordPress malware myself?

Sometimes. If a security plugin flags a single file early and you have a known clean backup, you may be able to. If Google or your host has flagged the site, it keeps coming back, or customer data may be involved, a proper cleanup that closes the way in is safer.

Why does malware keep coming back after a cleanup?

Usually because a backdoor was missed or the entry point, such as a vulnerable plugin or a leaked password, was never fixed. Finding and closing that entry point is the main part of the job.

Will you remove the Google 'This site may be hacked' warning?

Once the site is clean, a review is requested through Google Search Console. Google decides how quickly the warning is lifted; it is usually faster when the request shows what was fixed.

Do I need to restore from a backup?

Not always, and not blindly. A backup may already be infected. Restoring can be part of the fix once we know when the infection started and which copy is clean.

Will I lose content, orders or form entries?

The aim is to keep everything legitimate. Core, plugins and themes are replaced, while your content and database are cleaned rather than rolled back, so recent orders and entries are preserved where possible.

Do you clean sites that aren't WordPress?

Yes. WooCommerce stores and custom PHP sites are cleaned the same way. For WooCommerce, checkout and payments are tested before the site reopens.

What do I get at the end?

A written report: what was found, how the attacker got in, what was changed, and what to do to stop it happening again.

Start here

Report a hacked site.

Send the site address and what you've seen. You get a fixed quote before any work starts, and nothing is touched until you approve it.

  • 1We check the live site for the signs you describe, from the outside.
  • 2You get a fixed quote for the cleanup, in writing, before anything starts.
  • 3You approve it, we clean it, and you get the written report.

Report a hacked site

Three fields on purpose. We reply within one business day, and we don't add you to a mailing list.

Report a hacked site