Unexpected redirects
Visitors are sent to casino, pharmacy, fake support or adult pages, sometimes only from Google or mobile devices.
WordPress security cleanup
I clean infected WordPress websites, databases and hosting accounts, remove redirects, spam pages and backdoors, then identify how the infection entered. A typical single-site cleanup starts at EUR 190. Diagnostics and the estimate come first.
Direct answer
For one ordinary WordPress website, emergency malware cleanup starts at EUR 190 and usually takes several hours. A full cleanup with updates, credential rotation and hardening starts at EUR 320. I confirm the fixed price after a free diagnosis, before changing the website.
| Service | Best for | Typical time | Price |
|---|---|---|---|
| Emergency cleanup | Redirects, injected pages, malicious files or an urgent hosting block. | From a few hours | from EUR 190 |
| Google warning removal | Deceptive-site warning, hacked-result label or spam pages in Google. | Usually 24-48h after cleanup | from EUR 240 |
| Full recovery and protection | Cleanup, root-cause repair, updates, new credentials, hardening and report. | 1-5 days | from EUR 320 |
An infection is not always a visible red screen. WordPress malware often behaves differently for the owner, Googlebot and first-time visitors.
Visitors are sent to casino, pharmacy, fake support or adult pages, sometimes only from Google or mobile devices.
Japanese keywords, Viagra pages or unknown titles appear in search even though the WordPress dashboard looks normal.
The provider reports malicious PHP, outgoing spam, phishing or excessive CPU usage and takes the account offline.
New admin users, plugins, scheduled tasks or modified theme files appear without an authorised change.
A scanner deletes files, but the infection comes back because a backdoor, cron task or vulnerable plugin remains.
Chrome, Search Console or an antivirus marks the domain as dangerous, deceptive or compromised.
Deleting one suspicious file is not a cleanup. I inspect the complete execution path and verify the result from both the server and the public website.
I review WordPress core, plugins, themes, uploads, configuration, database content and scheduled tasks for injected code.
Web shells, rogue admins, hidden PHP, cron persistence and malicious database records are removed without deleting legitimate content.
Compromised core files are replaced from official packages. Required plugins and themes are checked against trusted copies.
I identify the vulnerable plugin, leaked credential, unsafe upload path or neighbouring infected site that allowed the compromise.
Credentials are rotated, risky accounts removed, updates applied and PHP execution restricted where it is not needed.
I test pages, admin and forms, run a second scan and provide a concise report of what was found, removed and changed.
Send the URL and any warning from Google or the host. I confirm symptoms, scope, price and access needed.
I preserve the current files, database and useful logs before removing anything, so there is a rollback point.
I remove malicious code across files and the database, then close the route used to infect the site.
I verify the public site and admin area, help request Google or hosting review if needed, and send the report.
Security plugins are useful detectors, but a list of changed files is not the same as an incident investigation. If the original vulnerability, stolen password or infected neighbouring site remains, WordPress can be compromised again minutes after a clean scan.
Redirects and spam can live in posts, options, widgets or serialized plugin data that file scanners do not repair safely.
Another infected website under the same account can write malware back into a cleaned WordPress installation.
Old FTP, hosting, database and administrator credentials let an attacker return even after all malicious files are gone.
Yes. A clean backup is helpful but not required. I compare the installation with official WordPress, plugin and theme packages, inspect the database and preserve the current state before repairs.
Yes. The goal is to remove malicious code without deleting legitimate pages, products, orders or theme customisation. If an infected component must be replaced, I explain the impact first.
Yes. After the website is clean and the entry point is closed, I prepare and submit the appropriate review request in Google Search Console. Google controls the review time.
Usually hosting or SSH/FTP access, the WordPress administrator and database access. Temporary credentials are recommended and should be changed again after the work.
Yes. Orders, customer data, checkout and payment integrations are handled carefully, with a backup and post-cleanup functional checks.
If the same infection returns through the same entry point within 90 days, I clean it again free. No service can guarantee against a new vulnerability or newly stolen credential.
Free diagnosis
The form goes directly to my Telegram. A URL, the visible symptom and any message from Google or the host are enough to start.