NIKOLA

Your store is hacked and the orders have stopped

Most cleanup services are priced for a blog. A compromised shop is a different problem — checkout has to work, payments have to be safe to take, and every hour is money you are not making. The first job is not a perfect site. It is a working one you can trade on today.

YOU ARE PROBABLY HERE BECAUSE

  • customers cannot check out and orders have stopped
  • Google is showing a warning on your site
  • pages you never created are indexed under your domain

What I can do for you

The first two are for when something has already happened. The last two are considerably cheaper than either.

HOURLY · FIRST LOOK FREE

Emergency recovery

Same-day work to get a compromised shop trading again: payload removed, entry vector closed, database cleaned as well as files, payment path verified, credentials rotated, and a written account of what happened.

FIXED · 1–2 DAYS

Scan and written finding

You suspect something but nothing is obviously broken. Files, database and payment path examined, with a written answer either way. Plenty of people buy this and get told they are clean, which is a reasonable thing to pay for.

FIXED · 1–2 WEEKS

Hardening

Two-factor, login limiting, file permissions, PHP execution blocked in uploads, update policy, bot and AI crawler control, and backups you have actually tested restoring. Available with nothing having gone wrong first.

MONTHLY RETAINER

Monitoring and maintenance

File integrity checks, database scanning, alerts on new admin users and modified core files, and someone who answers when they fire.

Book a consultation

Forty-five minutes, no charge.
I will tell you which of these you need, including when it is the cheapest one.

How this shows up on a shop

They need different responses, and the third is the one that costs the most because nobody notices it for months.

HOURS MATTER

Checkout is broken and orders have stopped

Trading has stopped. Orders are not being taken, or they are being taken and not fulfilled. Every hour is money.

  • White screen or fatal error
  • Checkout failing at payment
  • Card skimmer injected into the payment step
  • Orders taken but never reaching fulfilment
  • Host has suspended the account
VISIBLE TO CUSTOMERS

Customers are being redirected or warned away

Visitors land somewhere else, or Chrome shows a red interstitial before your homepage. The damage is reputational and it compounds daily.

  • Redirects that only fire on mobile
  • Deceptive site ahead warning
  • Defaced pages or injected popups
  • Unknown admin users
SLOW BURN, BIGGEST COST

Spam pages are indexed under your domain

Nothing looks wrong. Your site serves normal pages to you and injected pharmacy or gambling links to Google. By the time rankings drop it has usually been running for months.

  • Pages in Search Console you never made
  • Japanese keyword hack or pharmacy spam indexed
  • Fake products or coupons appearing in the catalogue
  • Cloaked content shown only to crawlers
  • Traffic falling with no obvious cause

Why a compromised shop is not the same job

You can buy a WordPress cleanup for eighty dollars, and for a brochure site that is a reasonable price. For a store taking orders it is the wrong service entirely — and the difference is not thoroughness, it is what has to be checked.

WHAT A CHEAP CLEANUP MISSES

The payment path

Skimmers live in checkout, not in wp-content. Anything touching the payment form, the gateway callback or the order confirmation has to be verified line by line, and the gateway logs read for charges that never became orders.

  • Injected scripts on the checkout page
  • Modified gateway callback handlers
  • Charges at the gateway with no order here
AND THIS

Order and customer data

A compromise that reached the database reached your customers. Which records were read, what was exposed, and what you are obliged to tell people are questions a malware scanner cannot answer.

  • Customer records accessed or exported
  • Prices, coupons or stock altered
  • Notification obligations under GDPR
AND THIS

Trading again, not merely clean

Clean is not the same as selling. Payments have to reconcile, stock has to be trustworthy, the processor has to stay willing to process, and orders placed during the incident have to be resolved rather than guessed at.

  • Payment account still in good standing
  • Stock reconciled against the warehouse
  • Orders during the outage worked out

Where it actually hides

Most cleanups fail because they only look at files. Half of what I find lives in the database or in the media library, where a file scanner never looks.

FILES DATABASE wp-admin / wp-includes core — verifiable by checksum wp-content/themes functions.php, header, footer wp-content/plugins 42 of them, all diffable now wp-content/uploads valid GIF header, PHP payload appended after the image data .htaccess / wp-config.php auto_prepend, injected include Scheduled tasks cron re-writing the payload back wp_options serialised payloads, injected scripts in widget and theme mods wp_posts / wp_postmeta spam links inside real content, hidden pages never in the menu wp_users / wp_usermeta ghost administrators, and application passwords that wp_users continued bypass the login page entirely THE LOADER One small file that reads the disguised payload, executes it, and puts it back the way it was. missed by file-only scanners caught by checksum comparison
Checksum comparison against the official WordPress and plugin releases finds modified core, theme and plugin files in seconds — the job that used to mean diffing forty-two plugins by hand. What it does not find is a payload disguised as an image, a row injected into the options table, or a ghost administrator. Those need looking for separately, and they are why sites get reinfected a week after a cleanup.

How the emergency job runs

The order matters. Removing the payload before you have found the way in just means doing it again on Thursday.

  1. Snapshot everything before touching it

    Full copy of files and database, kept aside. This is your evidence and your undo. If your host has suspended the account, this is also what proves what happened.

    First 15 minutes
  2. Find what changed, and when

    Checksum every core, theme and plugin file against its official release. Cluster modification timestamps to find the intrusion window. Scan uploads for files that claim to be images and are not. Read the database for injected rows and unfamiliar administrators.

    First hour
  3. Find the way in before removing anything

    Access logs around the intrusion window, the vulnerable plugin version, the reused password, the leftover install script. Without this step the cleanup is temporary and we both know it.

    First hour
  4. Get it trading

    Replace compromised files with clean copies from source, clean the injected database rows, remove ghost accounts, rotate every credential — hosting, database, admin users, API keys, application passwords. Close the entry vector.

    Same day
  5. Clear the warnings

    Google Search Console review request, blocklist removal, and reindexing where the spam got that far. This is the part most cleanups skip, and it is the part that actually restores your traffic.

    Day two onward, Google sets the pace
  6. Write down what happened

    What got in, when, through what, what it did, what was changed, and what is now closed. One document. You may need it for your insurer, your payment provider, or your customers.

    Within the week

What I will not promise you

Nobody can honestly guarantee a compromised site is completely clean. You can prove you found things; you cannot prove there is nothing left. Anyone selling you a hundred percent guarantee is selling you a feeling.

What I will promise: your site trading again, the entry vector closed, the database cleaned as well as the files, and a written account of what happened. If you are reinfected through the same route I found and closed, I fix it at no charge.

The genuinely clean version is a rebuild on current software with content migrated across. That is a planned piece of work, priced separately, and it is the right thing to do after the shop is open again — not instead of opening it.

Hardening, so there is no second time

Most compromises are not clever. They are an unpatched plugin, a reused password, or a file permission nobody checked. Available on its own, without anything having gone wrong first.

Login and access

The front door accounts for more compromises than every clever exploit combined.

  • Two-factor for every administrator
  • Login rate limiting and lockout
  • Audit of existing users and roles
  • Application password review
  • XML-RPC closed at the server
  • Admin URL moved off the default

Files and permissions

Correct ownership and the right restrictions in the right directories, so a single upload cannot become code execution.

  • PHP execution blocked in uploads
  • Correct 644 / 755 ownership
  • wp-config moved and locked down
  • File editing disabled in admin
  • Directory listing turned off
  • Security headers at the web server

Updates and vulnerability watch

Not blind auto-updates. A policy that patches security releases quickly and tests the rest.

  • Inventory of every plugin and version
  • Monitoring against known CVEs
  • Abandoned plugins identified and replaced
  • Staging environment for major updates
  • Automatic security-only patching

Scanning and alerting

Detection is worth more than prevention alone, because the goal is finding it in hours rather than months.

  • Scheduled file integrity checks
  • Database scanning, not just files
  • Alerts on new admin users
  • Alerts on modified core files
  • Search Console monitoring

Bot and crawler control

Bad bots cost you money in server load and credential stuffing. Good crawlers you may be blocking without realising it.

  • Scraper and spam bot filtering
  • Credential stuffing protection
  • Comment and form spam at the edge
  • AI crawler policy, decided deliberately
  • Verifying your site is reachable at all
  • robots.txt that matches the edge rules

Backups you have actually tested

An untested backup is a hope. The restore is the thing that matters, and almost nobody has tried theirs.

  • Off-server, versioned, not just on the host
  • Database and files, both
  • Restore rehearsed on staging
  • Retention long enough to predate an infection
  • Documented recovery procedure

Questions I get asked

How fast can you get us trading again?

Usually the same day for the common infections. The tooling for finding modified files is far better than it used to be — what once meant comparing dozens of plugins by hand is now a single verification pass. What varies is how deeply it is embedded and whether your host has suspended the account.

Do we have to rebuild the site?

Eventually, yes, and I will tell you that honestly. But not today and not instead of opening the shop. Emergency work gets you trading; the rebuild is planned properly afterwards, usually alongside the update backlog that let this happen in the first place.

Will this happen again?

Not through the same route, because closing it is part of the job. Through a new route, only if something else goes unpatched — which is what the hardening and monitoring work is for.

Google is showing a warning on our site. How long to clear it?

Once the site is genuinely clean, the review request typically clears within a few days, though Google sets the timetable and not me. Reindexing after SEO spam takes longer, and I will be straight with you about what has been lost rather than promising a full recovery.

Someone will do this for eighty dollars. Why would we pay more?

For a blog, use them — I mean that. The cheap services scan files, remove what matches a signature and submit a blacklist removal, which is genuinely the right service for a site with no orders in it. A shop needs the payment path verified, the order and customer data checked for what was reached, and the processor relationship protected. Different job, different amount of time.

Our payment provider has flagged the account. Can you help?

Yes, and it is the most urgent version of this. A processor that suspects a skimmer will hold funds or close the account, which hurts far more than the malware did. Getting the payment path demonstrably clean and documented is what resolves that conversation.

Can you just tell us if we are infected?

Yes. A scan and a written finding is a small fixed piece of work on its own, and plenty of people buy that first. If it comes back clean you have paid for peace of mind, which is a reasonable thing to buy.

Do you work with agencies on this?

Regularly. White-label, your process, your client relationship. I do not appear in front of your client, and I will not tell them their previous developer left the door open.

If it is happening now, do not fill in a form

Call or message. Bring the site URL and what you are seeing — I will look before we talk about money.

Get help now