Included in a typical proposal
- Investigation labour on the access you grant.
- Cleanup or restore work in the proposal.
- A note of findings and credentials rotated during the job.
WEB DESIGN & DEVELOPMENT
Investigate a compromised website, contain the issue and plan a controlled recovery. The work depends on the affected platform, available access and the condition of backups.
WHAT THIS SERVICE IS
Website malware investigation and cleanup is a controlled response when a site is defaced, sending spam, redirecting visitors, or flagged by a browser. The work is to contain access, find what changed, remove or restore, and close the obvious holes that let it happen. It is not a public incident-response agency, and it is not a promise that attackers will never return.
Success depends on logs, hosting access, and backups taken before the compromise. If the only copy is the infected one, cleanup is slower and less certain. If you have already paid a random “security company” to overwrite files, say so; we need to know what is original.
Legal notification, customer emails and insurer forms are your responsibility. We can describe technically what we found at a level suitable for a handover note.
A CLEAR PICTURE
Copies before more edits.
Keys, users, hosting panel.
Whichever the backup quality allows.
Then decide if a wider review is a new job.
WHO IT IS FOR
Owners who received a hosting abuse notice, teams whose Google listing shows a warning, and businesses that found strange admin users in WordPress.
TYPICAL SCOPE
Symptoms, timestamps, visible file changes, and whether the host has already suspended the account. We record what evidence exists before anyone “cleans” by deleting logs.
Passwords, extra admin users, FTP, and whether to serve a holding page. Taking mail or checkout offline is your call with the trade-offs named.
Remove identified malicious code or restore from a backup that predates the incident. Mixed approaches are common: restore then re-apply legitimate changes that came later.
Update the CMS, remove unused plugins, and rotate credentials. A full security programme is the cybersecurity or maintenance page. Here we close what this incident showed.
INCLUDED AND QUOTED SEPARATELY
AFTER HANDOVER
New passwords are yours to store. Any web shells we found are listed. If the attacker had the same password you use on mail, say so to your mail admin; that rotation is not automatic.
Search warnings can lag. Clearing a host flag is not the same hour as every browser cache. We will not invent a time when Google will drop a warning.
PRACTICAL NOTES
Shared hosting means a neighbour or an old account on the same panel can be part of the story. We will look at what we can see. The host’s abuse team may still need to act. If they have already taken the site offline, restoration timing is theirs as well as ours.
Once you are clean, changing every password that could have been in wp-config or in a plugin is tedious and necessary — mail, registrar, payment, analytics. We can provide a checklist. Walking into each vendor is yours unless you book that time. Reusing the old password is how the same backdoor returns.
PLANNING THE WORK
We can look at the public symptoms. We cannot clean what we cannot log into. Host lockouts need the hosting company’s process.
A first look might be. A compromise is usually a project because the labour is unknown at the start. We cap or time-box rather than write a blank cheque.
That is your decision with advice you trust. This page is recovery of a website from backups and cleanup, not a negotiation service.
CONNECTED SERVICES
LET’S BUILD WHAT’S NEXT
Tell us what you want to improve, build or simplify. We’ll help you define a practical way forward.
Discuss your project