Your store is hacked and the orders have stopped
Most cleanup services are priced for a blog. A compromised shop is a different problem — checkout has to work, payments have to be safe to take, and every hour is money you are not making. The first job is not a perfect site. It is a working one you can trade on today.
YOU ARE PROBABLY HERE BECAUSE
- customers cannot check out and orders have stopped
- Google is showing a warning on your site
- pages you never created are indexed under your domain
What I can do for you
The first two are for when something has already happened. The last two are considerably cheaper than either.
Emergency recovery
Same-day work to get a compromised shop trading again: payload removed, entry vector closed, database cleaned as well as files, payment path verified, credentials rotated, and a written account of what happened.
Scan and written finding
You suspect something but nothing is obviously broken. Files, database and payment path examined, with a written answer either way. Plenty of people buy this and get told they are clean, which is a reasonable thing to pay for.
Hardening
Two-factor, login limiting, file permissions, PHP execution blocked in uploads, update policy, bot and AI crawler control, and backups you have actually tested restoring. Available with nothing having gone wrong first.
Monitoring and maintenance
File integrity checks, database scanning, alerts on new admin users and modified core files, and someone who answers when they fire.
Forty-five minutes, no charge.
I will tell you which of these you need, including when it is the cheapest one.
How this shows up on a shop
They need different responses, and the third is the one that costs the most because nobody notices it for months.
Checkout is broken and orders have stopped
Trading has stopped. Orders are not being taken, or they are being taken and not fulfilled. Every hour is money.
- White screen or fatal error
- Checkout failing at payment
- Card skimmer injected into the payment step
- Orders taken but never reaching fulfilment
- Host has suspended the account
Customers are being redirected or warned away
Visitors land somewhere else, or Chrome shows a red interstitial before your homepage. The damage is reputational and it compounds daily.
- Redirects that only fire on mobile
- Deceptive site ahead warning
- Defaced pages or injected popups
- Unknown admin users
Spam pages are indexed under your domain
Nothing looks wrong. Your site serves normal pages to you and injected pharmacy or gambling links to Google. By the time rankings drop it has usually been running for months.
- Pages in Search Console you never made
- Japanese keyword hack or pharmacy spam indexed
- Fake products or coupons appearing in the catalogue
- Cloaked content shown only to crawlers
- Traffic falling with no obvious cause
Why a compromised shop is not the same job
You can buy a WordPress cleanup for eighty dollars, and for a brochure site that is a reasonable price. For a store taking orders it is the wrong service entirely — and the difference is not thoroughness, it is what has to be checked.
The payment path
Skimmers live in checkout, not in wp-content. Anything touching the payment form, the gateway callback or the order confirmation has to be verified line by line, and the gateway logs read for charges that never became orders.
- Injected scripts on the checkout page
- Modified gateway callback handlers
- Charges at the gateway with no order here
Order and customer data
A compromise that reached the database reached your customers. Which records were read, what was exposed, and what you are obliged to tell people are questions a malware scanner cannot answer.
- Customer records accessed or exported
- Prices, coupons or stock altered
- Notification obligations under GDPR
Trading again, not merely clean
Clean is not the same as selling. Payments have to reconcile, stock has to be trustworthy, the processor has to stay willing to process, and orders placed during the incident have to be resolved rather than guessed at.
- Payment account still in good standing
- Stock reconciled against the warehouse
- Orders during the outage worked out
Where it actually hides
Most cleanups fail because they only look at files. Half of what I find lives in the database or in the media library, where a file scanner never looks.
How the emergency job runs
The order matters. Removing the payload before you have found the way in just means doing it again on Thursday.
Snapshot everything before touching it
Full copy of files and database, kept aside. This is your evidence and your undo. If your host has suspended the account, this is also what proves what happened.
First 15 minutesFind what changed, and when
Checksum every core, theme and plugin file against its official release. Cluster modification timestamps to find the intrusion window. Scan uploads for files that claim to be images and are not. Read the database for injected rows and unfamiliar administrators.
First hourFind the way in before removing anything
Access logs around the intrusion window, the vulnerable plugin version, the reused password, the leftover install script. Without this step the cleanup is temporary and we both know it.
First hourGet it trading
Replace compromised files with clean copies from source, clean the injected database rows, remove ghost accounts, rotate every credential — hosting, database, admin users, API keys, application passwords. Close the entry vector.
Same dayClear the warnings
Google Search Console review request, blocklist removal, and reindexing where the spam got that far. This is the part most cleanups skip, and it is the part that actually restores your traffic.
Day two onward, Google sets the paceWrite down what happened
What got in, when, through what, what it did, what was changed, and what is now closed. One document. You may need it for your insurer, your payment provider, or your customers.
Within the week
What I will not promise you
Nobody can honestly guarantee a compromised site is completely clean. You can prove you found things; you cannot prove there is nothing left. Anyone selling you a hundred percent guarantee is selling you a feeling.
What I will promise: your site trading again, the entry vector closed, the database cleaned as well as the files, and a written account of what happened. If you are reinfected through the same route I found and closed, I fix it at no charge.
The genuinely clean version is a rebuild on current software with content migrated across. That is a planned piece of work, priced separately, and it is the right thing to do after the shop is open again — not instead of opening it.
Hardening, so there is no second time
Most compromises are not clever. They are an unpatched plugin, a reused password, or a file permission nobody checked. Available on its own, without anything having gone wrong first.
Login and access
The front door accounts for more compromises than every clever exploit combined.
- Two-factor for every administrator
- Login rate limiting and lockout
- Audit of existing users and roles
- Application password review
- XML-RPC closed at the server
- Admin URL moved off the default
Files and permissions
Correct ownership and the right restrictions in the right directories, so a single upload cannot become code execution.
- PHP execution blocked in uploads
- Correct 644 / 755 ownership
- wp-config moved and locked down
- File editing disabled in admin
- Directory listing turned off
- Security headers at the web server
Updates and vulnerability watch
Not blind auto-updates. A policy that patches security releases quickly and tests the rest.
- Inventory of every plugin and version
- Monitoring against known CVEs
- Abandoned plugins identified and replaced
- Staging environment for major updates
- Automatic security-only patching
Scanning and alerting
Detection is worth more than prevention alone, because the goal is finding it in hours rather than months.
- Scheduled file integrity checks
- Database scanning, not just files
- Alerts on new admin users
- Alerts on modified core files
- Search Console monitoring
Bot and crawler control
Bad bots cost you money in server load and credential stuffing. Good crawlers you may be blocking without realising it.
- Scraper and spam bot filtering
- Credential stuffing protection
- Comment and form spam at the edge
- AI crawler policy, decided deliberately
- Verifying your site is reachable at all
- robots.txt that matches the edge rules
Backups you have actually tested
An untested backup is a hope. The restore is the thing that matters, and almost nobody has tried theirs.
- Off-server, versioned, not just on the host
- Database and files, both
- Restore rehearsed on staging
- Retention long enough to predate an infection
- Documented recovery procedure
Questions I get asked
How fast can you get us trading again?
Usually the same day for the common infections. The tooling for finding modified files is far better than it used to be — what once meant comparing dozens of plugins by hand is now a single verification pass. What varies is how deeply it is embedded and whether your host has suspended the account.
Do we have to rebuild the site?
Eventually, yes, and I will tell you that honestly. But not today and not instead of opening the shop. Emergency work gets you trading; the rebuild is planned properly afterwards, usually alongside the update backlog that let this happen in the first place.
Will this happen again?
Not through the same route, because closing it is part of the job. Through a new route, only if something else goes unpatched — which is what the hardening and monitoring work is for.
Google is showing a warning on our site. How long to clear it?
Once the site is genuinely clean, the review request typically clears within a few days, though Google sets the timetable and not me. Reindexing after SEO spam takes longer, and I will be straight with you about what has been lost rather than promising a full recovery.
Someone will do this for eighty dollars. Why would we pay more?
For a blog, use them — I mean that. The cheap services scan files, remove what matches a signature and submit a blacklist removal, which is genuinely the right service for a site with no orders in it. A shop needs the payment path verified, the order and customer data checked for what was reached, and the processor relationship protected. Different job, different amount of time.
Our payment provider has flagged the account. Can you help?
Yes, and it is the most urgent version of this. A processor that suspects a skimmer will hold funds or close the account, which hurts far more than the malware did. Getting the payment path demonstrably clean and documented is what resolves that conversation.
Can you just tell us if we are infected?
Yes. A scan and a written finding is a small fixed piece of work on its own, and plenty of people buy that first. If it comes back clean you have paid for peace of mind, which is a reasonable thing to buy.
Do you work with agencies on this?
Regularly. White-label, your process, your client relationship. I do not appear in front of your client, and I will not tell them their previous developer left the door open.
If it is happening now, do not fill in a form
Call or message. Bring the site URL and what you are seeing — I will look before we talk about money.