Website security services

Website security: a proper review before it happens, and recovery when it has.

A security audit that tells you how exposed your site is, in plain English, ranked by risk. And if your website has already been hacked, a recovery that removes the malware, shuts the way in, clears the warnings and keeps watch afterwards. WordPress included.

What a compromise costs

A hacked website does not look hacked to you. It does to everyone else.

The owner usually finds out last. Google flags the site in search results, browsers show a red warning, rankings slide, and email from the domain starts landing in spam. Customers see all of it before you do. The site itself often looks perfectly normal from the office.

What customers and Google see
"This site may be hacked" Warning line under your listing in Google
Red browser warning "Deceptive site ahead". Most visitors leave.
Pages you never wrote Spam pages indexed under your domain, rankings falling
Email in spam Domain reputation drops with the site
After recovery
Malware removed Every injected file and database entry found and cleared
The way in shut Entry point identified, closed, access hardened
Warnings cleared Google review requested and confirmed clean
Monitored for 30 days If anything reappears, we see it first
How we work

Fix the cause, not just the symptom.

1 way in, always

Every compromise has an entry point: an outdated plugin, a weak password, an old admin account. Removing malware without finding it means it comes back.

30 days of monitoring after every recovery

Reinfection usually happens in the first weeks. We watch the site so that if anything reappears, we catch it, not your customers.

180+ pages rebuilt from a hacked site in 2026

A travel company's compromised WordPress site, rebuilt page for page with rankings protected. Recovery and rebuild are both on the table; we tell you which.

0 admin logins, plugins or public database on a Qyliq build

Sites we build are coded without the parts that get attacked. There is nothing for the usual exploits to get into.

What website security includes

Two services. One straight answer.

A security review is for a site that is working and you want to know how exposed it is. Recovery is for a site that has already been compromised. Both end the same way: with a written, plain-English account of what we found, what we did, and what you should do next.

Platform versionCurrent
Plugins4 outdated
Admin accounts7, 3 unknown
BackupsNever tested
security review
01 · Security review · from £1,000

Website security audit

Hosting, platform, plugins and themes, user access, backups, SSL and DNS, forms and uploads, known vulnerabilities. Findings ranked by risk with a fix list. Credited in full against a recovery or a rebuild.

Injected filesremoved
Database entriescleaned
Entry pointclosed
Google warningcleared
hacked website recovery
02 · Recovery · from £2,500

Fix a hacked website

Malware and injected code found and removed, WordPress or otherwise. The way in identified and shut. Credentials, access and hosting hardened. Search-engine and browser warnings cleared.

30 days monitored after clean-up
harden and monitor
03 · Included in recovery

Harden and monitor

Access tightened, unused accounts removed, software brought current, backups tested. Then 30 days of monitoring so reinfection is caught in hours, not months.

Patch and keepSound platform, one bad plugin
RebuildNulled software, repeat infections, no maintainer
the straight answer
04 · Included in both

Patch or rebuild: a straight call

Some sites are worth keeping. Some are a liability that will be hacked again. We tell you which, with the reasons, and what a rebuild on a platform with nothing to attack would cost.

WordPress

WordPress malware removal, and why it keeps coming back

Most of the hacked sites we see run WordPress, and almost none were hacked through WordPress itself. The way in is nearly always an outdated or abandoned plugin, a "nulled" premium theme downloaded for free with a back door built in, or an admin account left behind by a previous developer.

That is why a WordPress malware removal that only deletes the visible files fails. We remove the malware, then find and close the route it used, remove the accounts and software that should not be there, and put monitoring in place. If the site is running nulled software, replacing it is a condition of the work, not an option.

Where a site has been hacked more than once or nobody has maintained it for years, we will say so plainly: a rebuild on a platform with no admin login, no plugins and no public database usually costs less over two years than the next two clean-ups.

Questions

What people ask
about website security

Straightforward answers. If yours is not here, ask us directly.

Has my website been hacked? What are the signs?
The usual signs are a red warning in the browser or a "this site may be hacked" line under your listing in Google, pages or links appearing that you did not create (often pharmacy, gambling or foreign-language pages), your site redirecting visitors somewhere else, a sudden drop in rankings or traffic, your emails landing in spam, or your hosting company suspending the account. Some compromises show none of this and only surface in Search Console. If you suspect it, do not wait: the longer malicious code sits on a site, the more damage it does to your search standing.
What does a website security audit cover?
We review the whole surface, not just the code: hosting configuration, the platform and its version, every plugin and theme (including anything nulled, abandoned or no longer maintained), user accounts and access, backups and whether they actually restore, SSL and DNS, forms and file uploads, and any known vulnerabilities in what you are running. You get written findings in plain English, ranked by risk, and a fix list you can act on yourself or hand to us. The audit fee is credited in full if you go on to a recovery or a rebuild.
Can I remove malware from my website myself?
Sometimes, if you are technical and the compromise is simple. The problem is that most clean-ups that fail do so for the same reason: the visible malware is removed but the way in is left open, so the site is reinfected within days. A proper recovery finds the entry point (usually an outdated plugin, a weak password or a leftover admin account), closes it, hardens the site and then monitors it. If you have already tried once and it came back, that is the pattern.
How much does website security cost?
A security review starts at £1,000 and is credited in full against a recovery or a rebuild. Recovery of a hacked site starts at £2,500 and includes malware removal, closing the entry point, hardening, clearing search-engine and browser warnings, and 30 days of monitoring afterwards. Every published price is a floor; the fixed quote is set before work starts. Ongoing patching and monitoring for sites we run is part of the Growth and Performance retainers.
How long does hacked website recovery take?
Most sites are clean and hardened within a few working days of access being granted. Clearing a Google warning takes a review request after the clean-up, which Google typically processes within days rather than weeks. Rankings that dropped during the compromise recover over the following weeks once Google recrawls a clean site. We monitor for 30 days after the clean-up so that if anything reappears, we catch it, not your customers.
Do you work on WordPress sites?
Yes. Most of the hacked sites we see are WordPress, and almost always the way in is an outdated or abandoned plugin, a nulled theme, or an old admin account, not WordPress itself. We remove the malware, close the route, harden the installation and tell you straight whether the site is worth keeping on WordPress or should be rebuilt on a platform with no admin login, plugins or public database for anyone to attack.
Will Google penalise my site for being hacked?
Google does not issue a manual penalty for being a victim, but it does warn users away from a compromised site, flag it in Search Console, and stop ranking pages it considers unsafe. In practice that is a traffic collapse until the site is clean and the warning is lifted. Recovery includes requesting that review and confirming the flag has cleared.
Next step

Find out how exposed your site is

A security review from £1,000, credited in full against a recovery or a rebuild. Already hacked? Say so and we will start with that.

Book a security review