Is it hacked?
Signs your WordPress site
has malware.
A hacked WordPress site rarely announces itself. These are the signs that bring most owners to us, usually after a customer or Google notices first.
The first hour
What to do right now
if your WordPress site is hacked.
Whether or not you hire anyone, these four steps make WordPress malware removal faster and stop the damage spreading. What not to do matters as much.
Don't delete everything
Wiping files or restoring blindly destroys the evidence of how they got in, so it happens again.
Keep a copy as it is
Download the files and database in their infected state, or ask your host for a snapshot.
Change key passwords
Hosting control panel, WordPress admins, database and FTP/SFTP. From a clean device.
Report it once
Send the site address and what you've seen. One clear message beats five partial ones.
Report a hacked site →How the cleanup works
How we remove malware
from a WordPress site.
Most reinfections happen because the malware was cleaned but the way in was left open. Our WordPress malware removal services are built around finding and closing that entry point.
Why sites get reinfected
A quick clean-up vs
a proper one.
| Quick clean-up | How we clean a hacked WordPress site | |
|---|---|---|
| Infected files | Deleted where a scanner flags them. | Core, plugins and themes replaced from clean sources. |
| Backdoors | Often missed, so the attacker walks back in. | Searched for manually in files, database and scheduled tasks. |
| Entry point | Rarely identified. | Found and fixed, and named in the report. |
| Passwords & keys | Left as they were. | Changed, security keys rotated, sessions logged out. |
| Google & host warnings | Left for you to sort out. | Review requested once the site is clean. |
| What you get | "It's clean now." | A written report you can keep. |
Plugin or service?
When a malware plugin is enough,
and when it isn't.
Security plugins are good at detecting known malware. Removing it safely, and closing the way in, is what WordPress malware removal services are for.
After the cleanup
Keeping it clean
once it's fixed.
Who you're dealing with
Who cleans
your site.
You're handing someone the keys to your website. You should know who they are.
Naveen Kumar
Founder & lead engineer · Based in Chennai, India, working with clients across the US, UK, Europe and Australia
I built and ran WordPress, WooCommerce and custom-coded sites for clients directly for years before starting PixelGravitas — writing the code, managing the servers, staying on call when something broke. If your site goes down, you're talking to the person who fixes it, not a support queue. More about how I work →
Questions, answered
WordPress malware removal:
common questions.
How much does WordPress malware removal cost?
Without a plan, our WordPress malware removal services are quoted as a fixed fee before any work starts, based on the size of the site and how deep the infection goes. You know the price before you say yes. Malware monitoring and emergency response are part of the Care + Secure plan.
How fast can you respond to a hacked site?
On Care + Secure, a hacked site is an emergency with a response target of 2 hours in business hours and 4 hours outside them, including nights and weekends. Without a plan, you get a fixed quote first and work starts once you approve it.
How do I know if my WordPress site is hacked?
Common signs are redirects to spam sites, a Google warning in search results or the browser, spam pages under your domain, unknown admin users, a host suspension, or your email suddenly landing in spam.
Can I remove WordPress malware myself?
Sometimes. If a security plugin flags a single file early and you have a known clean backup, you may be able to. If Google or your host has flagged the site, it keeps coming back, or customer data may be involved, a proper cleanup that closes the way in is safer.
Why does malware keep coming back after a cleanup?
Usually because a backdoor was missed or the entry point, such as a vulnerable plugin or a leaked password, was never fixed. Finding and closing that entry point is the main part of the job.
Will you remove the Google 'This site may be hacked' warning?
Once the site is clean, a review is requested through Google Search Console. Google decides how quickly the warning is lifted; it is usually faster when the request shows what was fixed.
Do I need to restore from a backup?
Not always, and not blindly. A backup may already be infected. Restoring can be part of the fix once we know when the infection started and which copy is clean.
Will I lose content, orders or form entries?
The aim is to keep everything legitimate. Core, plugins and themes are replaced, while your content and database are cleaned rather than rolled back, so recent orders and entries are preserved where possible.
Do you clean sites that aren't WordPress?
Yes. WooCommerce stores and custom PHP sites are cleaned the same way. For WooCommerce, checkout and payments are tested before the site reopens.
What do I get at the end?
A written report: what was found, how the attacker got in, what was changed, and what to do to stop it happening again.