Cleanup, and the door closed behind it

WordPress Malware Removal and Blacklist Clearance

Clean malware out of WordPress and close the route in, so the same infection does not return in a fortnight. Files, database, scheduled tasks and administrator accounts, in that order. 150+ removals and 500+ recovered sites, same-day on most infections, with blacklist clearance chased with Google and your host until the warning clears.

Worldwide service, remote. No long-term contracts.

Get a free site audit See what it costs

30-day money-back guarantee · No setup fee · Cancel anytime

Get a free written site audit

Send the address and we return a written report inside one working day: patch backlog, exposure, load timings, restore status.

Written report within one working day · No obligation · We never sell your details

  • Same-day cleanup on most infections, and an active infection is answered at any hour
  • The entry route is found and closed — cleanup without it is a reinfection
  • Database scanned too, not just files: injected content and rogue admin users
  • Blacklist and Safe Browsing review requests chased until the warning clears
infection trace report and blacklist clearance record
The path this interrupts: files replaced then the entry route stays open then persistence survives then reinfected in a fortnight.

What this covers

  • Full snapshot taken before anything is changed, for evidence
  • Core, plugin and theme files compared against known-good copies
  • Injected and orphaned PHP files removed
  • Database scanned for injected content, spam posts and rogue admin users
  • Cron jobs and must-use plugins checked — a common persistence route
  • Entry route identified and closed
  • All credentials rotated: admin, database, FTP, hosting
  • Blacklist and Safe Browsing clearance requested and chased
  • Written incident report
1,000+ WordPress sites built
500+ hacked sites recovered
150+ malware removals
100+ sites under management
50+ popular plugins mastered
10+ years on one platform

Why cleaned sites get reinfected

The single most common thing we are called about is a site that was cleaned two weeks ago and is infected again. It is nearly always the same story: the files were cleaned and the way in was left open.

Malware on WordPress persists in more places than the file system:

  • The database — injected scripts in post content, options rows, or widget data.
  • Admin users you did not create, often with innocuous names.
  • Scheduled tasks that re-download the payload on a timer.
  • Must-use plugins, which do not appear in the normal plugin list.
  • The original vulnerability — usually the unpatched plugin that let them in the first time, still unpatched.

Closing all five is the job. Keeping them closed is hardening and daily scanning, which runs monthly inside WordPress maintenance rather than being re-bought after each incident — cleanup is included from Professional on maintenance plans and pricing. Whether that work is better held by one person or a team is the question in a freelancer versus an agency, and a compromise is where the difference shows.

How the work runs

  1. Snapshot firstThe infected state is the evidence. Deleting it before we have read it is how the entry route gets lost and the site gets reinfected.
  2. Service restoredUsually from a clean backup, so the site is back while cleanup runs in parallel rather than after it.
  3. Files cleanedCore, plugins and themes diffed against known-good copies. Anything that does not belong is removed, not quarantined and forgotten.
  4. Database cleanedInjected scripts, cloaked spam, and admin users you did not create. File-only cleanups miss all three.
  5. The route is closedThe vulnerable plugin, the reused password, the exposed endpoint. Then every credential is rotated.
  6. Blacklist clearanceReview requests submitted and chased until the browser warning is gone, which is usually the part clients feel most.

Plans that include this

  • Starter$39/monthor $390 a year — two months freeBlogs, portfolios and brochure sites
    • UpdatesMonthly
    • BackupsWeekly, 30-day retention
    • Uptime5-minute checks
    • Malware removalNot included
    See what is includedKept current and backed up.
  • Business$149/monthor $1490 a year — two months freeStores, membership sites, anywhere downtime costs money
    • UpdatesWeekly, tested on staging first
    • BackupsDaily, 90-day, multi-location
    • Uptime1-minute + 2-hour restore
    • Malware removalIncluded
    See what is includedEverything, including unlimited hack recovery.

The service that covers this

freelancer vs agency wordpress maintenance

Decide between one freelancer and a team for WordPress upkeep on coverage rather than price. A single person is cheaper and answers faster, right up until…

Related pages

Questions people ask before calling

How quickly can you clean an infected site?

Most are done the same day. Long-running infections and already-blacklisted sites take two to three days including the review.

Is there cover outside office hours?

An active infection is answered at any hour, nights and weekends included, on every plan — malware serving to your visitors is an emergency and is treated as one. Routine questions and planned work run in business hours inside your plan's window.

Will it come back?

Not if the entry route is closed, which is why finding it is part of the job rather than an extra. Reinfection after our cleanup is handled free.

My host cleaned it and it came back. Why?

Almost always a file-only cleanup. A backdoor in the database, a rogue admin account or a malicious cron job survives that and reinstalls everything.

Do I need to take the site offline?

Usually not. If it is actively serving malware to visitors we will put up a maintenance page while we work.

Is this included in a plan?

Yes on Professional and Business. As a one-off it is quoted after we have seen the site — no fixed emergency fee before we know the scope.