Marketing lead or owner
“Google is warning visitors that our site is dangerous”
Does this sound familiar?
- Browsers show a red interstitial warning before your site loads
- Search results display spam keywords — pharmacy, casino, counterfeit goods
- The site redirects to somewhere else, but only for some visitors
- Admin accounts exist that nobody created
- Your host suspended the account for sending spam
What it costs to ignore
Traffic collapses immediately when Google blocklists a domain, and recovery takes days to weeks after cleanup. Meanwhile the compromise is usually being used to attack your visitors or send spam in your name. Cleaning the payload without finding the entry point means reinfection within weeks — which is why sites get 'cleaned' three or four times before someone does it properly.
How the engagement runs
- 1
Preserve before changing
Snapshot the compromised state first. You cannot investigate what you have already overwritten, and the evidence determines whether data was exposed.
- 2
Find the entry point
File integrity comparison, log analysis, user and plugin audit. This is the step most cleanup services skip — and the reason sites get reinfected.
- 3
Clean properly
Remove malware, backdoors, injected content and unauthorised accounts. Core and plugin files are replaced from known-good sources rather than disinfected in place.
- 4
Close the vector
Patch or remove the vulnerable component, rotate every credential including hosting and database, and fix the permissions or configuration that allowed it.
- 5
Recover reputation
Blocklist removal, Search Console reconsideration, and cleanup of spam pages that were indexed under your domain.
Cleanup without root cause is a subscription
The most common thing we hear is that the site has been cleaned before. Sometimes two or three times.
That happens because removing the payload is easy and finding the entry point is work. If the vulnerable plugin is still installed, or the stolen administrator password still works, the site is reinfected within weeks — and everyone concludes that “WordPress is just insecure.”
It usually is not. The compromise is nearly always an out-of-date third-party component or a reused credential.
What the engagement covers
We preserve the evidence, establish how they got in, clean thoroughly, close the vector, rotate everything, and then handle the reputation recovery — blocklist removal and Search Console reconsideration — because a clean site that Google still flags is not actually fixed from your perspective.
You get a written explanation of what happened. Not a reassurance that it is gone.
The honest recommendation afterwards
If your site is a brochure — services, articles, a contact form, no logins — the most secure version of it has no CMS at all. A statically generated site has no database to breach and no plugins to leave unpatched.
This site is built that way. If that fits, we will tell you, even though it is a smaller engagement than a maintenance retainer.
What you get
- A clean site with malware and backdoors removed
- A written root-cause report explaining how they got in
- Every credential in the blast radius rotated
- Blocklist and Search Console recovery
- Hardening plus a maintenance plan so it does not recur
Frequently asked questions
How did they get in?
In the large majority of cases we investigate: an out-of-date plugin or theme with a publicly known vulnerability, a reused or weak administrator password, or a compromised hosting account. Rarely anything exotic. Attacks are automated and opportunistic — scanners find the vulnerable version and exploit it without a human ever choosing you.
Can we just restore from a backup?
Only if you know precisely when the compromise happened, and usually you do not. Attackers commonly sit quietly for weeks before doing anything visible, so the backup you restore may already contain their backdoor. Restoring also does nothing about the vulnerability that let them in. We use backups as part of recovery, never as the whole of it.
How long until Google removes the warning?
Once the site is genuinely clean, a reconsideration request typically clears within a few days. The critical word is genuinely: a failed review because remnants remain puts you at the back of the queue and costs more time than doing the cleanup properly.
Was our customer data stolen?
That is exactly what the scoping step establishes, and it matters legally under Quebec's Law 25 if personal information was involved. Many web compromises are opportunistic spam or SEO injection with no interest in your database, but that must be determined from evidence rather than assumed.
How do we stop it happening again?
Updates applied on a schedule rather than after an incident, removal of abandoned plugins, strong unique credentials with multi-factor authentication, and backups kept somewhere the web server cannot reach. Given how these compromises actually happen, ongoing maintenance is usually worth more than the cleanup itself.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreWordPress Development
Custom builds, hardening, and cleanup for sites that have been hacked or abandoned.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.