Redirects, spam pages, a Google warning or suspended by your host? We remove the malicious code, close the entry point and bring your site cleanly back online — checked by hand by the founder, not by a bot.
Attackers on your-domain.com might try to install malicious software or steal your data.
WordPress hacked? Take the site offline or into maintenance mode immediately, change every password (WordPress, hosting, FTP, database) and don't blindly restore an old backup — it often gets reinfected. Forge12 removes the malicious code by hand at a fixed price from €390, the initial analysis is free.
A single one of these symptoms is enough. Many attacks run unnoticed for weeks — until the host suspends you or Google warns. The earlier we can step in, the smaller the damage.
Visitors land on pharma, gambling or phishing sites — often only via Google or on mobile.
“This site may be hacked” or a red warning screen in Chrome instead of your homepage.
Email from the provider: account disabled for malware or spam. Site offline.
Google suddenly indexes hundreds of foreign sub-pages on your domain (Japanese characters, pill shops).
Visibility and visitors collapse within a few days — Google penalises compromised sites.
New backend users, a changed theme, or you can’t get into the WordPress dashboard at all.
Stay calm. A few correct steps limit the damage before we take over. The wrong ones destroy traces we need to find the cause.
You briefly describe the problem, we inspect the installation. Honest assessment + fixed price — free and with no obligation.
A deleted symptom is no solution. We clean completely, find the way in and close it — so the same attack doesn’t hit you again in two weeks.
The initial analysis is always free — you get an honest assessment and a binding fixed price before we start. No timesheets, no hidden costs.
Full cleanup in the standard case.
Highest priority — handled the same day or over the weekend.
Without follow-up protection, re-infection is likely — over 90% of hacks run automatically through known vulnerabilities. We strongly recommend a security setup plus an ongoing Care plan so the closed gap stays closed.
Work beyond the agreed fixed price (e.g. data recovery, rebuild) is agreed in advance — never a surprise invoice. External costs (hosting, licenses) are borne by the client.
Over 90 % of all WordPress hacks run automatically through known gaps in outdated plugins. The best insurance against the next incident is ongoing maintenance: updates, monitoring, tested backups.
Not hacked yet? How to secure WordPress — the hardening checklist →
Not every hack looks the same. These are the attack types we see most. The cleanup differs by type — the rule stays the same: find the backdoor first, then clean.
Visitors are silently redirected to third-party sites — often only via Google clicks or on mobile, so you don’t notice it in your own browser.
Hundreds of hidden spam pages (pills, gambling, fake shops) are injected into your domain to hijack its ranking. Google penalises you for it.
The homepage is visibly overwritten — with the attacker’s message. The loudest but often most harmless case, because it’s spotted instantly.
Fake login pages (banks, PayPal) are hosted in a hidden subdirectory. Your server sends the spam — your reputation and IP suffer.
Your server is abused for someone else’s crypto mining or attacks on others. Symptoms: high server load, slow site, suspension by the host.
Hidden code gives the attacker permanent access and injects malware into your files. The real root cause — miss it, and the hack comes back.
So you can follow along in an emergency — the terms that keep coming up with a WordPress hack.
Hidden code that gives the attacker permanent access — independent of the visible infection. Miss it, and the site is reinfected within days.
Umbrella term for malicious software of any kind: injected code that steals data, sends spam, redirects or abuses your server.
The targeted abuse of a security gap — usually in an outdated plugin, theme or the WordPress core.
The actual malicious code an exploit drops and runs after breaking in — e.g. a backdoor or a spam injector.
Random values in wp-config.php that secure login cookies. After a hack they must be regenerated, otherwise attacker sessions stay valid.
Your domain being listed in Google Safe Browsing or spam lists. Result: warning screen, ranking loss and blocked emails until the site is clean.
The standard cleanup is from €390 as a fixed price (plus VAT), usually within 24–48 h. Express with same-day handling from €690. The initial analysis with a binding fixed price is always free.
We respond to your request in under 2 hours. A standard cleanup is usually done in 24–48 hours. Exactly how long depends on the depth of the attack — a plain backup restore is faster than a full code cleanup.
Don’t panic and don’t delete anything hastily. Usually FTP access still works, and that’s enough for our initial analysis. We have experience with suspended accounts at all common hosts and work directly with the provider.
Yes, that’s actually the normal case. Most emergencies come from sites built by other agencies or by the owner and then no longer maintained. We just need FTP/SSH and ideally database access.
Yes. After the full cleanup we request a re-review in the Google Search Console. Google usually lifts the warning within a few days — provided the malicious code is fully removed and the gap closed.
Possible, but risky. Plugins often remove only the visible problem and miss hidden backdoors — then the site is reinfected within days. We clean by hand and also find the backdoors automated tools skip.
There’s no blanket guarantee — every case is different. Even in the worst case we can usually rescue the content (texts, images, products, database) and move it safely into a fresh installation. We tell you honestly what’s possible before any order.
Over 90 % of hacks run through outdated plugins. After the cleanup we recommend ongoing maintenance: manually checked updates, security monitoring and tested backups. On request we handle that directly in the WordPress maintenance package.
Typical signs: unexpected redirects to unknown sites, spam or pharma pages appearing out of nowhere, a Google warning “This site may be hacked”, browser or host warnings, unexplained slow load times, unknown admin users in the backend, or a sudden spike in server traffic. Often you notice it first because the site looks different in Google search than in your own backend.
The ones we see most: (1) redirect hacks that send visitors to third-party sites, (2) SEO spam or pharma hacks that inject hundreds of hidden spam pages into your domain, (3) defacements that overwrite the homepage, (4) phishing pages hidden in a subdirectory, and (5) crypto miners or botnet code that abuses your server. Almost all share one thing: a planted backdoor so the attacker can return any time.
Yes — but in the right order, and only after the site is cleaned. Change passwords too early, while the backdoor is still active, and the attacker simply captures them again. As part of the cleanup we rotate all relevant credentials: WordPress admins, database, FTP/SSH, hosting panel and the security keys (salts) in wp-config.php.
A backdoor is hidden code that gives the attacker permanent access — independent of the actual infection. If you remove only the visible malware but not the backdoor, the site is usually reinfected within days. That’s exactly why we clean by hand and scan the whole installation for backdoors that automated plugins miss.
It depends on the attack. If personal data (e.g. customer or order data from a shop) was accessed, a notification duty under GDPR Art. 33 may apply — usually within 72 hours to the data-protection authority. During the cleanup we document what was affected so you have a solid basis for that decision. The legal assessment should be made by a data-protection officer or lawyer.
Yes. If several sites sit in the same hosting account, malware often spreads across all of them (known as cross-site contamination). That’s why our cleanup checks not just the affected site but the entire account — otherwise one overlooked site reinfects the freshly cleaned one.
Hardening, login protection, firewall & backup strategy — so the emergency never happens in the first place.
Checked updates, monitoring and tested backups in one package — the best protection against the next hack.
Thorough, manual cleanup as a service — including sites we didn’t build.