Website cleanup
Files compared against the official versions, webshells and backdoors removed, including those hidden in images or in the core.
Security · Incident response
If your site redirects to strange places, Google flags it as dangerous or your host has suspended your account, deleting a couple of files is not enough. It needs containing, cleaning thoroughly, closing the door they came in through and checking nothing is left.
Some are obvious; others go unnoticed for months.
It is not just WordPress: PrestaShop, Joomla, Laravel, custom PHP or the Linux server itself.
Files compared against the official versions, webshells and backdoors removed, including those hidden in images or in the core.
Injected content, fake admin users and malicious scheduled tasks.
Cryptocurrency miners, rootkits, persistence processes and services, unknown SSH keys and access that should not exist.
If the server has sent spam: stop the sending, clean the queue and get off the blocklists.
Order matters: cleaning without understanding what happened usually ends in a second infection.
A copy of the current state as evidence, cutting off access and stopping active damage.
How they got in: a vulnerable plugin, a leaked password, another site on the same server…
Malware out, everything updated, permissions fixed, new passwords and a firewall.
What happened, what was done and what is pending, in writing and in plain language.
It depends on the size and how long the attacker has been inside. Containment comes first; I estimate the rest once I see the case.
The aim is to lose nothing: a full copy is taken before touching anything, and everything removed is kept in quarantine in case it needs to be recovered.
If only the malware is deleted, very likely. That is why the way in is found and closed, everything is updated and measures are left in place to detect changes.
After the cleanup, a review is requested in Google Search Console. Once Google confirms the site is clean, it removes the warning.
If customers’ personal data may have been exposed, under the GDPR you may have to notify your data protection authority (in Spain, the AEPD) within 72 hours. In the report I set out what data was exposed so you can assess it.
Got an idea to build, a platform that has fallen short or a network that keeps scaring you? Tell me. I will tell you how I would do it, how long it would take and what it would cost, with no commitment.
Or email me directly: