services / wordpress / site rescue

WordPress gone wrong? We fix that.

Hacked, white-screened, half-updated, or abandoned by whoever built it — we take WordPress sites in a bad state and get them stable, clean and back under someone's responsible care. Calmly, and with a written record of what we found.

situations

The states we rescue sites from

Hacked or infected

Spam pages in Google, redirects to dodgy pharmacies, browser warnings, blacklisted email. We find the infection, clean it, close the hole it came through, and handle Google's review process.

Broken by an update

The classic: someone clicked "update all", now it's a white screen or a fatal error. We diagnose from logs, not guesswork, and get you back up — then set up staging so it can't happen again.

Abandoned by the builder

The freelancer's gone quiet, the agency's folded, and nobody has the passwords. We recover access, document everything, and become the team that answers the phone.

Years out of date

PHP 5-era sites running plugins last updated in 2019. We update in careful stages on a copy of the site — never by clicking update on production and hoping.

Held hostage

A developer who owns "your" domain, hosting or admin account and won't hand it over gracefully. We've untangled this more than once; there's usually a clean path out.

Just plain flaky

Random errors, intermittent downtime, forms that sometimes send. Intermittent faults have causes too — we find them in the logs and fix them properly.

the process

How a rescue runs

  1. Stabilise

    Full backup of everything as-is (evidence matters), then stop the bleeding: take the site offline behind a holding page if needed, rotate credentials, block active attacks.

  2. Diagnose

    Logs, file integrity scans, database inspection. You get a plain-English write-up of what happened and how — useful for insurers and, where personal data is involved, ICO decisions.

  3. Repair

    Malware removed or the fault fixed, core and plugins brought current on staging, then a clean deploy. Fixed price agreed before we start the repair phase.

  4. Harden & hand over

    Security hardening, monitoring, off-site backups — and every credential documented and handed to you. Most rescues roll onto a care plan so this never happens again, but that's your call.

hour 0–24 stabilise: backup, lock down fast day 1–3 diagnose from logs, written findings (£350) day 3–10 repair on a fixed quote, staged then deployed ongoing hardened, monitored, documented, yours
// a typical rescue: stabilised same-day, diagnosed within days, repaired on a fixed price
how sites get hacked

How WordPress sites actually get compromised

Knowing the attack routes makes the fixes make sense. The overwhelming majority of WordPress compromises come through four doors. Outdated plugins lead by a distance: a vulnerability is disclosed, automated scanners find every unpatched site running it within days, and exploitation is a script, not a hacker taking personal interest in you. Credential attacks come second — reused passwords from breached services, or brute force against an admin login nobody rate-limited. Nulled themes and plugins (pirated premium software) frequently ship with backdoors pre-installed — the "bargain" that costs a cleanup. And hosting-level weaknesses: ancient PHP, other compromised sites on the same loose shared server, FTP credentials from 2015 still active.

This is also why cheap "malware removal" services disappoint: deleting infected files without closing the entry route means reinfection within weeks — often within days, because compromised sites get listed and re-targeted. Our repair phase always pairs removal with route-closing: everything updated, credentials rotated, unused accounts and plugins removed, file permissions corrected, and the specific vulnerability that let them in identified from the logs wherever the evidence allows. Then hardening makes the next attempt expensive: two-factor authentication, login rate-limiting, file-integrity monitoring, and a firewall tuned to WordPress attack patterns.

The uncomfortable truth we'll give you straight: a hacked site is almost never personal, and almost always preventable. The same automation that attacks unpatched sites ignores patched ones — which is why every rescue ends with a conversation about maintenance, and why rescued clients who take it up virtually never call us in an emergency again.

faq

Common questions

How fast can you start?

For active infections and down sites, usually same day — email us with the URL and "urgent" and a developer replies quickly. Stabilisation comes first; paperwork can follow.

What does a rescue cost?

Diagnosis is a fixed £350, credited against the repair. Repairs are quoted fixed-price once we know what we're dealing with — most fall between £500 and £2,500.

We don't have any passwords. Is that a problem?

Usually solvable. If you control the domain or the hosting billing, there's almost always a legitimate recovery path. We'll walk you through it.

Could the hack happen again?

Cleaning without hardening is how sites get reinfected within weeks. We close the entry route, harden the configuration, and recommend monitoring — reinfection on a hardened, maintained site is rare.

Google flagged our site as dangerous. How long until that clears?

Once the site is verifiably clean we request a review through Search Console; Google typically clears the warning within a day or two of a successful review. Email blacklists (if the server was sending spam) are chased separately per list. Both are part of the repair phase, not extras.

Do we need to tell anyone the site was hacked?

If personal data may have been accessed — customer accounts, form submissions, order details — UK GDPR may require reporting to the ICO within 72 hours of becoming aware. Our diagnosis write-up documents what the evidence shows was and wasn't touched, which is exactly what you need to make that call with your advisers. We're engineers, not lawyers, but we make sure you're deciding with facts.

// get in touch

The sooner we look, the smaller the damage

Send the URL and what you're seeing. A developer will tell you what it looks like and what stabilising it involves — usually the same day.

Get help now