Emergency help · WordPress

WordPress hacked?
We get your site back.

Redirects, spam pages, a Google warning or suspended by your host? We remove the malicious code, close the entry point and bring your site cleanly back online — checked by hand by the founder, not by a bot.

< 2 hFirst response
from €390Fixed-price cleanup
0 €Initial analysis
100 %Manual, no plugin
In short

WordPress hacked? Take the site offline or into maintenance mode immediately, change every password (WordPress, hosting, FTP, database) and don't blindly restore an old backup — it often gets reinfected. Forge12 removes the malicious code by hand at a fixed price from €390, the initial analysis is free.

01 · Am I affected?

Typical signs of a hack.

A single one of these symptoms is enough. Many attacks run unnoticed for weeks — until the host suspends you or Google warns. The earlier we can step in, the smaller the damage.

Unknown redirects

Visitors land on pharma, gambling or phishing sites — often only via Google or on mobile.

Google warning

“This site may be hacked” or a red warning screen in Chrome instead of your homepage.

Host has suspended you

Email from the provider: account disabled for malware or spam. Site offline.

Unknown spam pages

Google suddenly indexes hundreds of foreign sub-pages on your domain (Japanese characters, pill shops).

Sudden ranking loss

Visibility and visitors collapse within a few days — Google penalises compromised sites.

Unknown admin accounts

New backend users, a changed theme, or you can’t get into the WordPress dashboard at all.

02 · The first 15 minutes

What you should do now — and what not.

Stay calm. A few correct steps limit the damage before we take over. The wrong ones destroy traces we need to find the cause.

Do immediately
  • Stay calm — rushed deletions usually make it worse.
  • Put the site into maintenance mode or take it offline via the host to protect visitors.
  • Save a copy of the current (infected) state — files and database.
  • Change all passwords: WordPress, hosting, FTP/SSH, database, email.
  • Document anomalies (screenshots) and inform your host.
  • Note what happened last: plugin/theme update, new user, last login — it narrows down the cause.
  • Check other sites in the same hosting account — malware often spreads across them (cross-site contamination).
Never do
  • Delete files at random — you destroy evidence of the entry point.
  • Restore an old backup before the cause is known (it gets reinfected immediately).
  • Only remove the visible problem — backdoors stay hidden in the code.
  • Sit it out — daily damage to ranking, reputation and revenue.
  • Pay ransom or install dubious “1-click repair” plugins.
  • Rush to rebuild the whole account — without root-cause analysis you invite the same gap back.
  • Send credentials or backups unencrypted by email.
03 · Our process

Cleanly back online in four steps.

01

Initial analysis

You briefly describe the problem, we inspect the installation. Honest assessment + fixed price — free and with no obligation.

Proof

From infected to clean — drag the slider.

🔒 your-domain.com
Clean & back online
Malware removed · gap closed · hardened
All secure
0 findings
Firewall active
Monitoring
Clean
your-domain.com
This website has been hacked
Redirects to spam pages · foreign content
▸ shady link
Malware
Spam links
Backdoor
Infected
04 · Included in the fixed price

Not just clean. Secure.

A deleted symptom is no solution. We clean completely, find the way in and close it — so the same attack doesn’t hit you again in two weeks.

Deep scan
Core, themes, plugins, uploads & database checked for malicious code.
Malware removal
Injected code, spam links, web shells & crypto miners gone.
Close backdoors
Track down hidden backdoors — the part plugins miss.
Find the cause
Log analysis: how did the attacker get in? The gap gets closed.
Updates & reset
WordPress, extensions updated, all access reset.
Security hardening
Firewall, login protection, file permissions, 2FA recommendation.
Google clearance
Remove blacklist & Safe Browsing warnings via Search Console.
Plain-text report
What it was, what we did, what we recommend — in writing.
05 · Price

Fixed price. No surprises.

The initial analysis is always free — you get an honest assessment and a binding fixed price before we start. No timesheets, no hidden costs.

Standard
from €39024–48 h

Full cleanup in the standard case.

Included
  • Full malware cleanup
  • Core & files set up clean again
  • Hidden admins / backdoors removed
  • Basic hardening
  • Plain-language report: what it was, what we did
  • Free initial analysis with a fixed price up front
Not included
  • Content restore without an available backup
  • Rebuild after total loss
  • Larger development / new features
  • Ongoing protection afterwards (→ Security setup + Care plan)
Cleaning alone isn't enough.

Without follow-up protection, re-infection is likely — over 90% of hacks run automatically through known vulnerabilities. We strongly recommend a security setup plus an ongoing Care plan so the closed gap stays closed.

Work beyond the agreed fixed price (e.g. data recovery, rebuild) is agreed in advance — never a surprise invoice. External costs (hosting, licenses) are borne by the client.

Request emergency helpAll prices net, plus VAT · Free initial analysis
A hack is stressful, but not the end of the world. With me your emergency doesn’t disappear into a ticket forest — I look into it myself, tell you honestly what’s possible, and bring the site back clean. By hand, not at the push of a plugin button.
Marc Wagner
Founder · Forge12 Interactive
06 · Afterwards

Hacked once is enough. Never again.

Over 90 % of all WordPress hacks run automatically through known gaps in outdated plugins. The best insurance against the next incident is ongoing maintenance: updates, monitoring, tested backups.

  • Security updates checked by hand, critical gaps patched in < 24 h
  • Weekly security scan & uptime monitoring
  • Daily off-site backups with a real restore test

Not hacked yet? How to secure WordPress — the hardening checklist

Knowledge · Types of hacks

The most common WordPress hacks — and what they do.

Not every hack looks the same. These are the attack types we see most. The cleanup differs by type — the rule stays the same: find the backdoor first, then clean.

Redirect hack

Visitors are silently redirected to third-party sites — often only via Google clicks or on mobile, so you don’t notice it in your own browser.

SEO spam / pharma hack

Hundreds of hidden spam pages (pills, gambling, fake shops) are injected into your domain to hijack its ranking. Google penalises you for it.

Defacement

The homepage is visibly overwritten — with the attacker’s message. The loudest but often most harmless case, because it’s spotted instantly.

Phishing pages

Fake login pages (banks, PayPal) are hosted in a hidden subdirectory. Your server sends the spam — your reputation and IP suffer.

Crypto miner & botnet

Your server is abused for someone else’s crypto mining or attacks on others. Symptoms: high server load, slow site, suspension by the host.

Backdoor / malware injection

Hidden code gives the attacker permanent access and injects malware into your files. The real root cause — miss it, and the hack comes back.

Knowledge · Glossary

In brief: the most important terms.

So you can follow along in an emergency — the terms that keep coming up with a WordPress hack.

Backdoor

Hidden code that gives the attacker permanent access — independent of the visible infection. Miss it, and the site is reinfected within days.

Malware

Umbrella term for malicious software of any kind: injected code that steals data, sends spam, redirects or abuses your server.

Exploit

The targeted abuse of a security gap — usually in an outdated plugin, theme or the WordPress core.

Payload

The actual malicious code an exploit drops and runs after breaking in — e.g. a backdoor or a spam injector.

Salts / security keys

Random values in wp-config.php that secure login cookies. After a hack they must be regenerated, otherwise attacker sessions stay valid.

Blacklisting

Your domain being listed in Google Safe Browsing or spam lists. Result: warning screen, ranking loss and blocked emails until the site is clean.

07 · FAQ

Frequently asked questions.

01What does it cost to clean a hacked WordPress site?

The standard cleanup is from €390 as a fixed price (plus VAT), usually within 24–48 h. Express with same-day handling from €690. The initial analysis with a binding fixed price is always free.

02How fast is my site back online?

We respond to your request in under 2 hours. A standard cleanup is usually done in 24–48 hours. Exactly how long depends on the depth of the attack — a plain backup restore is faster than a full code cleanup.

03My host has suspended the site — what now?

Don’t panic and don’t delete anything hastily. Usually FTP access still works, and that’s enough for our initial analysis. We have experience with suspended accounts at all common hosts and work directly with the provider.

04Can you also rescue sites you didn’t build?

Yes, that’s actually the normal case. Most emergencies come from sites built by other agencies or by the owner and then no longer maintained. We just need FTP/SSH and ideally database access.

05Will I get the Google warning removed?

Yes. After the full cleanup we request a re-review in the Google Search Console. Google usually lifts the warning within a few days — provided the malicious code is fully removed and the gap closed.

06Can’t I just fix it myself with a plugin?

Possible, but risky. Plugins often remove only the visible problem and miss hidden backdoors — then the site is reinfected within days. We clean by hand and also find the backdoors automated tools skip.

07What if the site can’t be saved at all?

There’s no blanket guarantee — every case is different. Even in the worst case we can usually rescue the content (texts, images, products, database) and move it safely into a fresh installation. We tell you honestly what’s possible before any order.

08How do I prevent it from happening again?

Over 90 % of hacks run through outdated plugins. After the cleanup we recommend ongoing maintenance: manually checked updates, security monitoring and tested backups. On request we handle that directly in the WordPress maintenance package.

09How do I know my WordPress site has been hacked?

Typical signs: unexpected redirects to unknown sites, spam or pharma pages appearing out of nowhere, a Google warning “This site may be hacked”, browser or host warnings, unexplained slow load times, unknown admin users in the backend, or a sudden spike in server traffic. Often you notice it first because the site looks different in Google search than in your own backend.

10What are the most common types of WordPress hacks?

The ones we see most: (1) redirect hacks that send visitors to third-party sites, (2) SEO spam or pharma hacks that inject hundreds of hidden spam pages into your domain, (3) defacements that overwrite the homepage, (4) phishing pages hidden in a subdirectory, and (5) crypto miners or botnet code that abuses your server. Almost all share one thing: a planted backdoor so the attacker can return any time.

11Do I need to change all passwords after a hack?

Yes — but in the right order, and only after the site is cleaned. Change passwords too early, while the backdoor is still active, and the attacker simply captures them again. As part of the cleanup we rotate all relevant credentials: WordPress admins, database, FTP/SSH, hosting panel and the security keys (salts) in wp-config.php.

12What is a backdoor — and why isn’t deleting the malicious code enough?

A backdoor is hidden code that gives the attacker permanent access — independent of the actual infection. If you remove only the visible malware but not the backdoor, the site is usually reinfected within days. That’s exactly why we clean by hand and scan the whole installation for backdoors that automated plugins miss.

13Are customer data affected in a hack — do I have to report it?

It depends on the attack. If personal data (e.g. customer or order data from a shop) was accessed, a notification duty under GDPR Art. 33 may apply — usually within 72 hours to the data-protection authority. During the cleanup we document what was affected so you have a solid basis for that decision. The legal assessment should be made by a data-protection officer or lawyer.

14Can a hack infect other websites on the same server?

Yes. If several sites sit in the same hosting account, malware often spreads across all of them (known as cross-site contamination). That’s why our cleanup checks not just the affected site but the entire account — otherwise one overlooked site reinfects the freshly cleaned one.

Acute emergency?Report emergency
EVERY HOUR COUNTS

Get your site back.

Request emergency helpSee price