Hacked Website Repair

Site hacked? Cleanup, hardening, blacklist recovery.

Malware removed, entry points patched, Google Search Console reconsideration submitted, 30-day monitoring. Fixed-price cleanup regardless of care plan status. Typical resolution 24 to 72 hours.

WhatsApp us right now

What "hacked" actually means for your website

Website hacks come in a few common flavours and one uncommon one. The common cases: attackers exploit an outdated plugin to inject spam pages, redirects, or backdoors into your site. The site itself often still works from your perspective. What has changed is that Google is now indexing spam URLs on your domain, visitors from Google may be redirected to gambling or pharma sites, and Search Console may be showing warnings about malware or deceptive content. The uncommon case: a full server-level compromise where the entire hosting account has been taken over. Both are handled by our hacked website repair service in the UK. This page covers the process, what it costs, and how to prevent recurrence.

Common signs your site has been hacked

  • Google Search Console showing warnings about deceptive content, hacked content, or malware
  • Browser warnings (Chrome, Safari, Firefox) when visitors try to load the site
  • Hosting provider has suspended the account for security or terms-of-service violation
  • Spam pages appearing in Google search results for your domain (viagra, gambling, casino, foreign-language pharma)
  • Unexpected redirects from Google search results to unrelated sites
  • New admin users you did not create appearing in WordPress
  • Sudden ranking drops or de-indexing with no other explanation
  • Unfamiliar files or folders on the server (WP-admin, wp-content/uploads/*.php, root-level unfamiliar PHP)

Our hacked website cleanup process

The cleanup follows a specific order because each step depends on the previous one. Skipping steps or doing them out of order almost guarantees the infection returns.

  1. Contain the infection Site is taken behind a maintenance page immediately so no more visitors are exposed. If hosting has already suspended, we work through their support to get read-only access for cleanup.
  2. Identify all malicious files Compare current site files against a clean install of the same CMS version. Anything that should not be there gets flagged: injected PHP files, modified core files, backdoor scripts, obfuscated code hidden in plugin folders, uploaded shells masquerading as images.
  3. Remove the malicious code Malicious files deleted, modified core files restored from clean copies, database entries cleaned of injected content. Every change is logged so you have a record of what was removed.
  4. Identify and patch the entry point This is the step most cheap cleanup services skip. The infection got in somewhere. Usually an outdated plugin with a known exploit, occasionally a weak admin password brute-forced, sometimes compromised FTP or hosting credentials. If we do not find and close the entry, the same infection returns within days.
  5. Rotate all credentials All WordPress admin passwords force-reset. FTP and SSH credentials rotated. Database password rotated. Hosting control panel password rotated. Any API keys the site had rotated. Nothing that could have been leaked stays valid.
  6. Submit Google Search Console reconsideration If Google blacklisted the site, we file a reconsideration request through Search Console with a full write-up of what was found, what was removed, and how the entry point was closed. Reconsideration reviews typically take 24 to 72 hours.
  7. 30-day monitoring Site is checked daily for 30 days after cleanup for reinfection attempts. Reinfections within this window are handled at no additional charge as part of the standard engagement.

Malware removal specifics

The malware side of the cleanup depends on infection type:

  • SEO spam injections (pharmacy pages, casino pages, foreign-language spam). Cleaned by removing injected files and database entries, restoring clean core files, and submitting sitemap re-crawl requests to Google to force reindexing of the correct content.
  • Malicious redirects (visitors from Google get sent to unrelated sites). Cleaned by finding the redirect code (usually in .htaccess, wp-config.php, or an injected mu-plugin), removing it, and verifying redirects no longer trigger on any user agent.
  • Backdoor shells (PHP files that allow attacker access even after other malware is removed). Found by scanning file uploads directory and core CMS folders for unexpected PHP files, unusual base64-encoded content, or eval() calls in files that should not have them.
  • Cryptomining scripts (JavaScript injected to mine cryptocurrency on visitors' devices). Cleaned by removing the injection point from theme files or database entries.
  • Phishing pages (fake login pages hosted on your domain to steal credentials). Removed and the directory structure that hosted them locked down.

Google blacklist recovery

Google flags hacked sites in Search Console under "Security Issues" and browsers (Chrome primarily) display large red warning pages instead of loading the site. This can crater traffic overnight. The blacklist recovery process:

  1. Complete the technical cleanup first. Reconsideration requests submitted before the site is actually clean get rejected and add delay.
  2. Verify Search Console access is intact (attackers sometimes add themselves as verified owners; those need removing first).
  3. Submit reconsideration through Search Console with a written summary: what infection was found, what was removed, when it started, when it ended, and what has been done to prevent recurrence.
  4. Google typically responds within 24 to 72 hours. If reconsideration is granted, browser warnings stop appearing within hours and the "Security Issues" panel in Search Console clears.
  5. If reconsideration is rejected (rare but possible), it usually means residual malware was missed. Second cleanup pass, then resubmit.

Hardening after: preventing the next hack

The same conditions that let attackers in the first time will let them in again if nothing changes. Standard post-cleanup hardening includes:

  • Password rotation for every admin account, with strong unique passwords enforced via a password manager
  • Two-factor authentication enabled on all WordPress admin logins (or CMS equivalent)
  • Abandoned admin accounts removed (ex-employees, former contractors, unused test accounts)
  • Unused plugins deactivated and deleted (dormant plugins with known vulnerabilities are a common entry vector)
  • Everything patched to latest stable versions (core, plugins, themes, PHP version)
  • File permissions locked down (no world-writable directories, config files with restrictive permissions)
  • WordPress version disclosure disabled so attackers cannot easily fingerprint your specific version
  • Login rate limiting enabled to prevent brute-force attacks
  • Security monitoring plugin installed (Wordfence or equivalent) with alerts routed to us or you
Most clients who arrive after a hack stay on a care plan. A one-off cleanup gets the site back. Care Plus at £109/mo or Care Pro at £199/mo means someone is checking weekly for reinfection attempts, patching plugins before exploits become public knowledge, and rotating credentials on schedule. See our care plans for detail, or the WordPress maintenance page if you are on WP specifically.

What it costs

Hacked website cleanup is quoted flat once we have diagnosed the infection. Typical ranges:

  • Simple infection (single injected file, obvious entry point, no blacklist): £250 to £400
  • Standard cleanup (multiple injection points, blacklist recovery, 30-day monitoring): £500 to £800
  • Complex compromise (multiple backdoors, unclear entry vector, extensive spam indexing, full server rebuild required): £800 to £1,500

Fixed price agreed before work begins. No hourly meter. If the initial diagnosis reveals worse damage than we quoted for, we revise the quote before continuing rather than surprising you with a bigger invoice at the end. For Care Pro clients, hacked cleanup is included in the monthly fee. For Care Plus, the response is faster and simpler cleanups are covered. Full detail on the pricing page.

How this fits with our other services

Hacked website repair is one part of our emergency response toolkit. Related pages worth knowing about:

  • Emergency website support for site outages, broken checkouts, and other urgent issues that are not hacks
  • Website care plans for ongoing monthly protection, backups, and updates that prevent hacks in the first place
  • WordPress maintenance services specifically for WP sites, including the staging-tested update process that catches vulnerable plugin versions before attackers do

Common questions

How do I know if my website has been hacked?

Search Console warnings, browser warnings, hosting suspension, spam pages appearing in Google for your domain, unexpected redirects, unauthorised admin users, sudden ranking drops. Any of these means treat it as an emergency.

How long does hacked website cleanup take?

24 to 72 hours from access to fully resolved. Simple infections in a few hours. Complex ones 2 to 3 days. Blacklist reconsideration adds a further 24 to 72 hours for Google.

Do you work on any CMS or just WordPress?

Any. WordPress makes up most of what we clean because it is most-attacked, but also Magento, Shopify (rare), Drupal, custom PHP, and static sites where hosting was compromised.

Will my search rankings recover after cleanup?

Usually yes. Blacklist recovery takes 2 to 6 weeks. Light spam takes 2 weeks to normalise. Severe long-term infections take 2 to 3 months. We monitor for 30 days after cleanup.

How do I stop this from happening again?

Rotate all passwords, enable 2FA, remove abandoned admin accounts, disable unused plugins, keep everything patched, and ideally move to a Care Plus or Care Pro plan for ongoing protection.

Site hacked right now? Message us.

WhatsApp is the fastest way to reach us. We diagnose within the hour during UK business hours and quote a fixed cleanup price.