Cleanup, and the door closed behind it
WordPress Malware Removal and Blacklist Clearance
Clean malware out of WordPress and close the route in, so the same infection does not return in a fortnight. Files, database, scheduled tasks and administrator accounts, in that order. 150+ removals and 500+ recovered sites, same-day on most infections, with blacklist clearance chased with Google and your host until the warning clears.
Get a free written site audit
Send the address and we return a written report inside one working day: patch backlog, exposure, load timings, restore status.
- Same-day cleanup on most infections, and an active infection is answered at any hour
- The entry route is found and closed — cleanup without it is a reinfection
- Database scanned too, not just files: injected content and rogue admin users
- Blacklist and Safe Browsing review requests chased until the warning clears

What this covers
- Full snapshot taken before anything is changed, for evidence
- Core, plugin and theme files compared against known-good copies
- Injected and orphaned PHP files removed
- Database scanned for injected content, spam posts and rogue admin users
- Cron jobs and must-use plugins checked — a common persistence route
- Entry route identified and closed
- All credentials rotated: admin, database, FTP, hosting
- Blacklist and Safe Browsing clearance requested and chased
- Written incident report
Why cleaned sites get reinfected
The single most common thing we are called about is a site that was cleaned two weeks ago and is infected again. It is nearly always the same story: the files were cleaned and the way in was left open.
Malware on WordPress persists in more places than the file system:
- The database — injected scripts in post content, options rows, or widget data.
- Admin users you did not create, often with innocuous names.
- Scheduled tasks that re-download the payload on a timer.
- Must-use plugins, which do not appear in the normal plugin list.
- The original vulnerability — usually the unpatched plugin that let them in the first time, still unpatched.
Closing all five is the job. Keeping them closed is hardening and daily scanning, which runs monthly inside WordPress maintenance rather than being re-bought after each incident — cleanup is included from Professional on maintenance plans and pricing. Whether that work is better held by one person or a team is the question in a freelancer versus an agency, and a compromise is where the difference shows.
How the work runs
- Snapshot firstThe infected state is the evidence. Deleting it before we have read it is how the entry route gets lost and the site gets reinfected.
- Service restoredUsually from a clean backup, so the site is back while cleanup runs in parallel rather than after it.
- Files cleanedCore, plugins and themes diffed against known-good copies. Anything that does not belong is removed, not quarantined and forgotten.
- Database cleanedInjected scripts, cloaked spam, and admin users you did not create. File-only cleanups miss all three.
- The route is closedThe vulnerable plugin, the reused password, the exposed endpoint. Then every credential is rotated.
- Blacklist clearanceReview requests submitted and chased until the browser warning is gone, which is usually the part clients feel most.
Plans that include this
- Starter$39/monthor $390 a year — two months freeBlogs, portfolios and brochure sites
- UpdatesMonthly
- BackupsWeekly, 30-day retention
- Uptime5-minute checks
- Malware removalNot included
- Most chosenProfessional$79/monthor $790 a year — two months freeSmall businesses and lead-generation sites
- UpdatesWeekly + PHP version management
- BackupsDaily, 60-day retention
- Uptime1-minute checks
- Malware removalIncluded
- Business$149/monthor $1490 a year — two months freeStores, membership sites, anywhere downtime costs money
- UpdatesWeekly, tested on staging first
- BackupsDaily, 90-day, multi-location
- Uptime1-minute + 2-hour restore
- Malware removalIncluded
What clients say
They found malware two of our previous agencies had missed, cleaned it in an afternoon, and told us exactly how it got in.
Operations Director, professional services, 4 sitesThe staging step is the whole point. Three years and not one update has taken our booking form down.
Practice Manager, healthcareWe resell it to 31 clients under our own brand. The reports go out with our logo and our clients have never heard their name.
Agency Founder, digital agency
The service that covers this
freelancer vs agency wordpress maintenanceDecide between one freelancer and a team for WordPress upkeep on coverage rather than price. A single person is cheaper and answers faster, right up until…
Related pages
Questions people ask before calling
How quickly can you clean an infected site?
Most are done the same day. Long-running infections and already-blacklisted sites take two to three days including the review.
Is there cover outside office hours?
An active infection is answered at any hour, nights and weekends included, on every plan — malware serving to your visitors is an emergency and is treated as one. Routine questions and planned work run in business hours inside your plan's window.
Will it come back?
Not if the entry route is closed, which is why finding it is part of the job rather than an extra. Reinfection after our cleanup is handled free.
My host cleaned it and it came back. Why?
Almost always a file-only cleanup. A backdoor in the database, a rogue admin account or a malicious cron job survives that and reinstalls everything.
Do I need to take the site offline?
Usually not. If it is actively serving malware to visitors we will put up a maintenance page while we work.
Is this included in a plan?
Yes on Professional and Business. As a one-off it is quoted after we have seen the site — no fixed emergency fee before we know the scope.