Google warnings, unexpected pharmacy or loan redirects, new admin users, and SEO spam pages are an incident — not something to click through and hope will pass.
Google shows “This site may be hacked” or unexpected pharmacy/loan redirects
New admin users appear, SEO spam pages show up in Search Console, or outbound email is blacklisted
A plugin or theme vulnerability was disclosed and traffic looks “off” in analytics
Strip malicious code and users, update vulnerable components, rotate keys, and apply the hardening that makes the same entry point unlikely to work again.
Strip malicious code and users, update vulnerable components, and remove unused entry points
Admin passwords, salts, API keys, FTP/SFTP, and hosting panel access reviewed and rotated
Every cleanup ends with a written report: what happened, how they got in, what was removed, and what we filed with Google. If the same hole is used again within 30 days, we clean it again at no charge.
Google Search Console security review and blacklist reconsideration requests once the site is verifiably clean
A written after-action report you can keep — not “it’s fixed, trust me”
If the site is reinfected through the same entry point within 30 days of cleanup, we clean it again at no charge. A brand-new vulnerability in an unpatched plugin is a different incident, and we will say so plainly rather than quietly billing it as the same one.
What we cannot promise: that Google clears a warning instantly. No honest vendor can
What we do instead: fix the root cause, file the reconsideration request, and monitor until warnings clear
If the install is too far gone to clean safely, we say that on day one instead of billing hours into it
What you get
How WordPress malware removal and hacked site cleanup actually works
Concrete deliverables — no vague SaaS jargon. Each engagement is sized to your business and reviewed monthly.
Containment
Isolate the site where it helps, preserve logs when useful, and stop the bleeding before cosmetic fixes.
Database & files
Scan uploads, themes, and mu-plugins; audit the database for injected scripts, rogue admins, and scheduled junk.
Clean restore path
Rebuild from a verified backup when that is faster than hand-cleaning thousands of infected files.
Search Console & blacklist reconsideration
Once the site is verifiably clean we file the Google Search Console security review, submit reconsideration requests to blacklists flagging you, recheck Safe Browsing and your sitemap, then monitor until the warnings drop.
Keys rotated
Admin passwords, salts, API keys, FTP/SFTP, and hosting panel access reviewed and rotated with a simple handoff list.
After-action report
A written summary of what happened, how they got in, what was removed, and what to watch next — no fear-mongering, just facts.
From our team’s years of agency support work, the first message is rarely “we have malware.” It is a search warning, a redirect, or an article that changed itself.
Search warnings and injected addresses
Google or another engine flags the site, or search results show URLs you never published.
Unauthorized content changes
Published articles or pages rewritten without an editor login you recognize.
Redirects on the search-result link only
Typing the domain works; the result in Google still bounces. Direct access and the indexed URL are different tests.
Cleanup that reinfects
Files removed during a deploy come back because the entry point was never closed.
Tools that will not run
The application or PHP version is too old for the scanner you wanted to use. That is a finding, not a reason to skip the cleanup.
Updates as remediation
Patching is part of the job. It is not a guarantee the site will stay clean.
From experience
Situations our team has handled
Anonymized examples from recent support work (2025–2026). Incomplete outcomes stay incomplete — we do not invent a clean ending.
2026
Cleanup during a deploy, then reinfection
What they saw
A compromised website needed cleanup in the middle of a deployment.
What we found
The host had flagged affected files. Later review found suspicious scripts and redirect rules. The entry point was never established.
What we did
An initial cleanup allowed the site to launch.
What stayed open
Later comments documented reinfection and a further escalation. A durable cleanup was not established — this is why we treat incomplete cleanups as a risk, not a finished incident.
2025
Site too old for the intended scanner
What they saw
A suspected compromise needed review, but the application was too old for the security plugin we wanted to run.
What we found
The application version blocked the intended tool. The intrusion path was not established.
What we did
We prepared a cleaned copy for review.
What stayed open
Deployment approval was not recorded.
2025
Search results still redirected after direct access worked
What they saw
Search results redirected visitors after a reported compromise.
What we found
Outdated application and runtime versions blocked the intended malware tool. The entry point was not established.
What we did
Direct access to the site was working again.
What stayed open
The search-result link still needed a later check.
2025
Published articles changed without authorization
What they saw
Published articles were altered without authorization.
What we found
A known core-application vulnerability was suspected. The attack path was not conclusively proven.
What we did
The incident was closed as resolved.
What stayed open
Recovery of the original article text was not documented.
Rewritten from internal notes. No client names. Dated in the current 2025–2026 window.
After a cleanup
Post-hack hardening checklist
A cleanup that skips these steps is how reinfection starts. Use this after the site is verifiably clean.
Print this page to keep a paper copy beside the work.
1Keep the pre-cleanup snapshot. You may need it for forensics even if you never restore it.
2Remove malicious files and altered published content, then update the components that let them in.
3Rotate every secret that could have leaked: CMS admins, salts, hosting panel, SFTP/SSH, FTP, API keys, and leftover contractor accounts.
4Compare core, themes, and plugins against known-good copies. Delete unused themes and abandoned plugins.
5File the Search Console security review and any blacklist reconsideration only after the site is clean — not before.
6Put a WAF or CDN rule in front of wp-login and xmlrpc if the stack is WordPress.
7Turn on daily off-site backups and a restore test. A backup you have never restored is a rumour.
8Write the after-action: entry point if known, what was removed, what was rotated, what was filed, what only the owner can decide next.
We cannot promise Google will clear a warning on a timetable. We can promise the request is filed after the site is actually clean.
Verified Metro Vancouver IT work
Related case studies
Named clients, with consent, from work we delivered as Metro Vancouver IT.
A hacked website recovered and stabilized with ongoing WordPress hosting and uptime support — in a case where no backup was available.
Recovery
Restored from scraped content
Hardening
WAF + admin lockdown
Backups going forward
Daily off-site, tested
What you are left holding
What your after-action report covers
Every cleanup ends with a written report, because “it’s fixed, trust me” is worthless the next time something looks odd. The report states when the compromise started as far as the logs show, the entry point we believe was used, the malicious files and database rows removed, the accounts and keys rotated, the components patched, and the hardening applied. Where a fact is uncertain, it says so instead of dressing a guess up as forensics.
It also lists what we filed on your behalf — the Google Search Console security review, any blacklist reconsideration requests — and what we could not do, which usually means the two or three things only you can decide: retiring an abandoned plugin, dropping an old admin account someone still uses, or budgeting for a rebuild the cleanup postponed rather than solved.
You can read an illustrative version before you hire us: see a sample after-action report. It is a redacted example written to show the format and depth — not a real client’s incident.
Who it is for
A strong fit when
Google shows “This site may be hacked” or unexpected pharmacy/loan redirects
New admin users appear, SEO spam pages show up in Search Console, or outbound email is blacklisted
A plugin or theme vulnerability was disclosed and traffic looks “off” in analytics
You need someone local who will explain options without upselling a full rebuild on day one
Our process
How cleanup usually runs
1
Triage
Confirm symptoms (redirects, spam, admin lockout), check hosting status, and decide whether to take a fresh backup before cleanup.
2
Snapshot
Point-in-time backup even if the site is compromised — useful for forensics and rollback if a cleanup pass misses something.
3
Scan & integrity
Malware scan plus core, plugin, and theme integrity checks against known-good copies.
4
Remove & patch
Strip malicious code and users, update vulnerable components, and remove unused entry points.
5
Harden
WAF/CDN rules, least-privilege admin accounts, file permissions sanity check, and basic rate limits where they help.
6
Validate
Forms, checkout, logins, cron, and Search Console — then a reinfection prevention checklist you can actually follow.
Who does the work
One technician, start to finish
Metro Vancouver IT is a small Burnaby-based shop. The person who triages the compromise removes the malware, rotates your keys, and writes your after-action report — so nothing gets lost in a handoff halfway through an incident.
Plain-English updates while the cleanup runs, not a silent ticket
We work on your existing host — no forced migration attached to the cleanup
Rebuild is recommended only when cleaning is genuinely the wrong call
Same-day triage is often possible for active Vancouver-area clients. Exact timing depends on hosting access and how badly the site is degraded.
How much does WordPress malware removal cost?
Cleanup is billed at $90 CAD/hour, and a typical cleanup runs two to three hours — about $180–$270. A heavily infected site, thousands of injected files, or an install nobody has updated in years takes longer. We begin with triage and access review, give you an estimate for the safest recovery path, and ask for approval before continuing if new damage changes the scope.
Will you need hosting and WordPress access?
Yes — hosting panel, SFTP/SSH if available, and an admin account. If credentials are compromised, we reset through the host before continuing.
Do you guarantee Google will clear warnings instantly?
No honest vendor can. We fix the root cause, request reviews where applicable, and monitor until warnings clear — usually improves within days once the site is clean.
Is a rebuild always required?
Not usually. If the core is intact and backups are trustworthy, cleanup plus hardening is enough. When the install is ancient or heavily modified, we will say so plainly.
What happens after cleanup?
We recommend WordPress care or hosting with WAF and monitored backups. Ongoing work is optional and scoped to what you actually need.
Do you handle the Google Search Console and blacklist reconsideration requests?
Yes, and it is a named part of the job rather than something you chase afterwards. Once the site is verifiably clean we file the security review in Google Search Console, submit reconsideration requests to any blacklist flagging your domain or mail, recheck Safe Browsing and your sitemap, and monitor until the warnings drop. We cannot control how long a review queue takes, so we tell you what was filed and when.
What if the site gets reinfected?
If it is reinfected through the same entry point within 30 days of cleanup, we clean it again at no charge. A new vulnerability in a different component is a separate incident — we will explain which one we are looking at and why, rather than billing a fresh cleanup as if it were the old one.
Do I get anything in writing?
Yes. Every cleanup ends with a written after-action report covering the entry point, what was removed, which accounts and keys were rotated, what was patched, and what we filed with Google. You can read a redacted sample at /services/hacked-wordpress-website-cleanup/sample-report before hiring us.
Google says my site may be hacked. Do you start in Search Console?
We start by proving whether the live site is still compromised. Search Console and blacklist requests are filed after the site is clean, not instead of the cleanup.
Search results redirect but typing the domain works. Are we done?
No. Direct access and the indexed URL are different tests. We treat the search-result link as still dirty until it is rechecked.
Can you clean a site that is too old for the security plugin you wanted to run?
Yes. An outdated application is a finding. It is not a reason to skip containment, file review, and a cleaned copy. It may be a reason to talk about a rebuild after the bleeding stops.
If the site is hacked, start here
Tell us what you are seeing — redirects, warnings, or admin lockout — and we will propose the fastest safe path. Typical cleanup totals $180–$270 (2–3 hours at $90 CAD/hour); heavier infections are quoted before we continue.
Include the website URL, warnings or redirects you see, and whether you still have hosting access. Active incidents are triaged the same business day when received during Pacific Time business hours.