My WordPress site was hacked – what now?
Stay calm, don’t pay a ransom, and don’t try to clean the files manually – that usually makes it worse. Change your passwords, and bring in someone who has done this before. ShowSpring removes malware from hacked WordPress sites, usually within 24 hours.
Signs your site is infected
- Google flags it – “This site may be hacked” or a blacklist warning
- Redirects, popups or spam pages you never created
- Admin accounts you don’t recognize
- Sudden crashes, slow loading, or emails sent from your domain that you didn’t send
What malware removal includes
- Full scan and removal of malware, backdoors and injected code
- Finding how the attacker got in – and patching that vulnerability
- Hardening: logins, file permissions, security plugins, two-factor auth
- Google Search Console and blacklist delisting
- A post-cleanup report, plus monitoring on the care plan so it doesn’t happen twice
How long does it take? How much?
Cleanups are quoted as a fixed price after a quick look at the site, and most are done within 24 hours. If a cleanup would cost more than a rebuild, we’ll tell you honestly.
Why ShowSpring?
Cleaning the files is the easy part – stopping the next attack is the job. We harden after we clean and keep monitoring after we leave.