i.
Change the passwords you can
WordPress admin, hosting panel, SFTP, and the email account tied to the admin user. Different passwords, not variations of the old one.
don't: reuse the old one with a "2"Services / Hacked site cleanup & malware removal
Same-day WordPress malware removal by a senior engineer: the infection out, the way in found and closed, Google's warning lifted, and the site hardened so you never read this page again. One fixed price. No lecture.
In one paragraph: RoundBorders cleans hacked WordPress and WooCommerce sites the same day for a fixed price, usually between $149 and $599. The cleanup removes malware from files and the database, identifies and closes the entry point, removes rogue admin users, rotates keys, hardens the site, requests the Google Safe Browsing review and host reinstatement, and monitors the site for 30 days. If the infection returns within those 30 days, the re-clean is free.
how pricing works →Signs your WordPress site is hacked
A hacked WordPress site rarely looks hacked to its owner. It announces itself sideways: through Google, through a customer's phone, through your host. These are the six ways it usually shows up. Any one of them is enough to start; most sites arrive with two or three.
What to do first when your site is hacked
Free, honest, and safe, whether you hire us or not. Do these before anyone touches the site. Each comes with the thing most people do instead, and shouldn't.
i.
WordPress admin, hosting panel, SFTP, and the email account tied to the admin user. Different passwords, not variations of the old one.
don't: reuse the old one with a "2"ii.
Don't delete "suspicious" files or restore a random backup yet. The infection is evidence: it tells us how they got in, which is the only thing that stops it happening again.
don't: restore a backup blindlyiii.
Screenshots of the redirect, the Google warning, the host email. Timestamps shorten the investigation and the bill.
don't: pay the "we'll clean it" DMHow we clean a hacked WordPress site
Times from a real cleanup, a WooCommerce store with a mobile-only redirect. Yours will differ in the details, never in the order: nothing is deleted before it's copied, and nothing is called clean before the door is closed.
Before a single file changes, we take a full copy of files and database and keep it for 30 days. The site goes behind a maintenance screen for visitors while we work, so the redirect stops immediately even though the cleanup hasn't started. Evidence stays intact.
Core, plugin, and theme files are compared against their official checksums; the database is searched for injected content, options, and users; access logs are read backwards from the first symptom. Most "malware removal" skips this step. It's the step that matters. Here: an abandoned slider plugin, unpatched since 2023.
WordPress core, plugins, and the theme are reinstalled from clean official sources, not patched by hand; injected code, backdoors, rogue cron jobs, and the mailer script in uploads are removed; the database is cleaned of spam pages, injected options, and the rogue administrator. Then it's scanned again, by a second tool.
The entry point is patched or replaced. Salts and keys are rotated so every stolen session dies, file permissions are corrected, PHP execution is blocked in uploads, login is rate-limited and a firewall is put in front. You get a written report naming what happened, how, and what changed.
We request the Google Safe Browsing review from Search Console and send the host the cleanup report with checksums so a suspended account is reinstated. Then the site is monitored for 30 days. If anything comes back in that window, we come back, free.
How much it costs to fix a hacked WordPress site
Diagnosis is free and needs no credentials. You get a fixed price in writing, usually within the hour, and the price you approve is the price you pay. Same-day work carries no rush fee.
$149 – $599 fixed, same day
Larger multisite or WooCommerce cleanups are quoted individually, still fixed, still before we start. Never hourly.
Every cleanup ends with 30 days of monitoring. If the infection returns inside that window, the re-clean is on us. It almost never does, because we close the door instead of sweeping the floor. Want it watched after that? Maintenance plans from $149/month.
Client Reviews
Real reviews from owners whose sites were down, hacked, or throwing errors.
You, Sir, are a genius. Thank you so much for helping us out. Myself and our hosting provider weren't able to find the error, Bishoy found it in less than 24 hours. Thank you so much!
Bishoy is so awesome. I would gladly hire him again for a project. He is super fast and an expert at his craft. He helped me to clean up and optimize a 29GB database file down to less than 1% of that size. My website is running so smoothly now. Thank you, Bishoy!
Kylie A. thebrilliant.com I was really happy with the speed at which Bishoy completed this work. A real lifesaver!
Hacked WordPress site FAQ
What people ask before handing over a hacked site, and what we tell them.
Most cleanups finish the same working day you approve the quote. The redirect or spam stops within minutes of us starting, because the site goes behind a maintenance screen while we work.
Almost never. WordPress core, plugins, and the theme are reinstalled from clean official sources and your content, orders, and settings stay. A rebuild is only worth discussing if the site was already at the end of its life.
Yes, once the site is actually clean. We request the Safe Browsing review from Search Console after the cleanup, and Google usually lifts the flag within one to three days.
That is the point of the diagnosis step. Your written report names the entry point (a plugin, theme, credential, or the host) and what we changed so it cannot be used again.
No. A full snapshot of files and database is taken before anything changes and kept for 30 days. Cleaning is done on the live database with the site in maintenance mode, not by rolling back to an old backup.
Yes. Hosts normally grant SFTP access or a temporary window for cleanup. Afterwards we send them the cleanup report with file checksums, which is what gets a suspended account reinstated.
Inside the 30-day monitoring window, we re-clean for free. Beyond it, a maintenance plan keeps updates tested, backups daily, and a developer watching, which is how sites stop needing this page.
No. Describe what you are seeing, or tick the symptoms on the page, and you will get a fixed price. Access is only needed after you approve the quote.
Tell us what you see. A senior engineer looks immediately and a fixed price is usually in your inbox within the hour.
Hacked site?
Start the cleanup