Redirects to spam, Japanese or pharma keywords in Google, a "Deceptive site ahead" warning, a host suspension notice, or a checkout that suddenly asks for card details twice. We've seen all of it, and it's fixable.
€350 fixed for cleanup + hardening · €500 for WooCommerce shops (includes payment-flow integrity check).
Take it offline or put a maintenance page up if you can — it protects visitors and your reputation.
Change your WordPress, hosting, FTP/SFTP and database passwords.
Logs and file timestamps tell us how they got in, and that's what stops it recurring.
Send us the hosting login and a description of what you're seeing.
We start within hours on working days, and we'll tell you honestly if it's a quick job or a rebuild.
.htaccess and wp-config.php inspected for backdoorsMost breaches come from one of: an outdated plugin with a public exploit, a weak or reused admin password, a nulled ("free premium") theme or plugin, or a compromised neighbour on shared hosting.
What was infected, how they got in, what we removed, what we changed, and what you should do next. Plain language, one page — the kind of document you can send to a client, an insurer or your own management.
Shops get a different kind of attack: JavaScript that copies card details at checkout, or a modified payment plugin that changes the account money goes to. We check the checkout flow end to end, verify the payment plugin's integrity, review Mollie/Stripe webhook endpoints, and confirm no orders were redirected. If customer data may have been exposed, we help you assess your GDPR notification duties — with your legal adviser for the formal decision.
| Scope | Fixed price |
|---|---|
| Cleanup, root cause, hardening, blacklist removal, report | €350 |
| WooCommerce cleanup with payment-integrity check | €500 |
| Multiple sites on one account (cross-contamination) | €250 per additional site |
| Rebuild when the site is beyond cleaning | from €1,200 |
| Ongoing care afterwards (recommended) | from €50 / month |
Nothing to pay until we've confirmed it's clean.
Security plugins detect; they don't patch. Most hacks come through an outdated plugin with a known exploit, which no scanner prevents. Updates on a schedule are the fix.
Only if you know when the breach happened and have a backup from before it — and even then the vulnerability is still there. We restore when it helps, and still fix the entry point.
Yes. Once it's clean and we request a review with evidence, the warning is typically lifted within 1–3 days. Rankings usually recover within a few weeks.
If personal data may have been accessed, GDPR may require notifying your data protection authority within 72 hours. We'll give you the facts; a lawyer gives you the decision.
Same day on working days for sites that are actively harming visitors.
Send us the hosting login and what you're seeing. We start within hours on working days — and there's nothing to pay until it's confirmed clean.
Get a fixed-price quote →