Active WordPress incident? Initial assessment within 4 hours. (Mon–Fri 8am–8pm, Sat 9am–2pm (CET/CEST))

Active security incident

Hacked WordPress site? What to do now

If your WordPress site is redirecting visitors, showing unfamiliar content, or has administrator accounts you don't recognize, treat it as a possible security incident. We assess the symptoms for free, respond personally within four hours, and clean confirmed fixed-price cases for €699. The cleanup covers malware, persistence, accounts, database, data-exfiltration indicators, baseline hardening, and a final report.

What does a possible incident look like?

These symptoms show up often in WordPress hacks. Any single one isn't proof on its own — several at once is a clear warning sign.

Acute

Visitors get redirected to unfamiliar sites

These redirects can be caused by injected malicious code. They often appear only on mobile devices or when a visitor arrives from a search engine.

Suspected

Google shows spam pages or a security warning

After cleanup, Google still needs to review or recrawl the site. Warnings and spam results may therefore remain visible for some time.

Acute

Your host suspended the site over malware

Acute

Unknown administrator accounts have appeared

Impact

The site is blank, slow, or throwing errors

Suspected

Files or plugins reappear after being deleted

Suspected

Forms or emails are behaving strangely

Impact

Ads were rejected because of a compromised site

What's safe to do right now

In the first few minutes, the priority is preserving evidence and avoiding hasty changes that could make a later cleanup harder.

Safe and useful

  • Save screenshots of warnings, redirects, or spam search results
  • Leave existing backups and logs untouched
  • Note down anomalies with date and time
  • Request a free initial assessment
  • Notify the relevant internal contacts if payment or customer data may be at risk

Please avoid

  • Don't delete suspicious files hastily
  • Don't install additional "cleaner" plugins
  • Don't send passwords via WhatsApp or plain email
  • Don't overwrite backups or let logs rotate out
  • Don't start manually "tidying up" the file system before evidence is preserved

Finding, indicator, or limit — how we frame statements

Our final report clearly separates what was actually established, what's merely an indicator, and where the available data reaches its limits. Examples from a typical initial assessment:

Befund / Finding
An unknown file containing executable PHP code was found in the uploads directory.
Indiz / Indicator
Outbound connections to an unfamiliar domain suggest a possible data exfiltration, but are not proof on their own.
Grenze / Limit
Without complete access logs, it isn't possible to conclusively determine whether — or which — data was actually read out.

Read more about our indicator-based review on the data breach assessment page.

Site affected? We assess it for free.

The following pages explain scope, data breach assessment, pricing, and process.

Frequently asked questions about active incidents

How do I know if my WordPress site has been hacked?

Common signs include redirects to unfamiliar sites, spam content appearing in Google search results, unknown administrator accounts, warnings from Google or your host, and unexplained changes to files or plugins. When in doubt, a free assessment gives you clarity quickly.

What should I do right now?

Don't delete anything hastily, don't overwrite backups or logs, don't send passwords over WhatsApp or plain email, and request a free assessment. That preserves evidence and keeps the cleanup straightforward.

How quickly will a real person respond?

We review your information within four hours during our service hours and reply through your chosen contact channel. The four-hour window applies to the initial assessment, not the completed cleanup.

How much does the cleanup cost?

Cleanup of one confirmed WordPress installation and one clearly defined incident costs €699 including VAT. If further work is required, we send you a separate quote.

Can you tell whether data was exfiltrated?

We review available files, database, user changes, logs, and outbound connections for credible indicators. A negative result means no credible indicators were found in the available data — not that data exfiltration is technically ruled out.