Skip to content
Oh My Web

Site down or defaced right now?

Email us nowOr send the details in 30 seconds

Emergencies jump the queue, day or night.

WordPress malware removal service — we clean it, then we keep it clean.

We remove the malware, find and close the route it came in by, rotate every credential, and file the request that gets you off Google’s blocklist — for a fixed ₹9,999 / $149, usually within 24 hours for a standard site. If it comes back inside 30 days we clean it again at no charge.

Symptoms

Six signs the site is infected

In roughly the order people notice them, which is unfortunately not the order they happen in.

  • “This site may be hacked” under your search result

    Google has found injected content it believes was not put there by you. It usually appears days before anything is visible on the site itself.

  • A full-page red warning in the browser

    The blocklist. At this point most visitors never reach your site at all, and it is the single most expensive symptom on this list.

  • Visitors redirected somewhere else

    Often only on mobile, often only from search, and often not when you visit directly — which is why owners are told by customers rather than noticing.

  • Admin users you do not recognise

    A backdoor that has already been used. Deleting the user does not remove the way back in.

  • Pages you never wrote, in a site: search

    Spam pages injected to use your domain's reputation. Search your own site and count.

  • An email from your host

    Suspension, or a notice about outbound spam or resource abuse. Hosts are usually right about this.

The cleanup

What ₹9,999 / $149 actually buys

Eight things, and the fourth and fifth are the ones cheap cleanups skip — which is why cheap cleanups get re-done.

A full scan and a file diff
Every file compared against a clean copy of the same core and plugin versions, so modified files are found by comparison rather than by pattern matching.
A database scan
Injected content in posts, options and users — the half that file scanners miss entirely.
Removal, then a backdoor sweep
Removing the visible payload is the easy part. The sweep is what stops it coming back on Thursday.
Credential rotation
Admin passwords, database credentials, salts and any API keys stored in the site. Assume everything on the box was read.
A plugin and theme audit
What is out of date, what is abandoned, and what came in from outside the official directories.
Hardening and firewall rules
File permissions, disabled file editing, and rules covering the route it came in by.
Blocklist and Search Console
A security-issue review request filed, plus the blocklist removal request. We handle the paperwork; Google controls the clock.
Thirty days of monitoring
Because reinfection, when it happens, almost always happens in the first fortnight.

Timeline: an assessment as soon as we have access, and a standard site clean within 24 hours. Blocklist removal then takes Google somewhere between one and three days — that clock is theirs, not ours, and anyone promising you a time on it is guessing.

Before you pay anyone

Can you do this yourself?

Often, yes. Here is where the free route works and where it stops.

Try this first

Wordfence and Sucuri both publish free scanners that find most common infections. Check Search Console for a security issue, search your own domain for pages you did not write, and look at your admin users. If the infection is a single injected file and you have a clean backup from before it, restoring and updating everything is a genuinely reasonable afternoon.

Stop and call someone when

It comes back within days — that is a backdoor you did not find, and finding it is the actual skill. Or the site is blocklisted, or your host has suspended you, or there are orders and customer data involved, or you have no backup from before the infection. At that point the free route is costing you more in downtime than the fixed fee.

The price

₹9,999 / $149, fixed, for a standard WordPress site. Fixed means fixed — it does not move because the clean took longer than we expected.

Quoted separately: multisite installations, large stores with years of order data, and sites on a server we have to secure as well. We tell you that before starting, not afterwards. It is free if you are already on Care Pro or Growth.

Stopping it happening again

A clean site with nobody patching it is a site waiting for the next public exploit. That is the honest recommendation and it is also the upsell, so judge it accordingly: a care plan from ₹4,999 / $79 a month covers updates tested on staging, daily off-site backups, monitoring, and cleanup if it ever happens again.

The 30-day guarantee continues for as long as you are on one.

Questions

Hacked-site questions, answered

How do you remove malware from a WordPress site?

Take a forensic copy first, then compare every file against a clean copy of the same versions rather than scanning for signatures. Clean the database separately. Find the entry route — usually an outdated plugin — and close it. Rotate every credential. Then harden, request the blocklist review, and watch it for a month. Skipping the entry route is why most cleanups fail.

How do I check a WordPress site for malware?

Start free: run Sucuri's public scanner and check Google Search Console for a security issue. Then search site:yourdomain.com and look for pages you did not write, and check your admin users list for accounts you do not recognise. Those four take about ten minutes and catch most infections.

Is my site hacked?

If any of the six signs above is true, treat it as yes until proven otherwise. The two people usually least likely to notice are the owner, because the browser caches and the redirect often only fires for search traffic on mobile, and the host, until the outbound spam starts.

Will I lose my content?

No. We clean rather than restore wherever we can, precisely so you keep the posts, products and orders added since the infection. If a restore is the only safe option we say so first and we carry the newer content across by hand.

Do you work with my host?

Yes, and with whoever they are. We need admin and file access — SFTP or a control panel is fine. If your host has suspended the account we will talk to them and get it lifted; that conversation goes faster when someone can describe what was actually found.

What if it comes back?

We clean it again at no charge for 30 days. That guarantee is real and it is also why we insist on finding the entry route rather than just the payload. It does continue past 30 days on a care plan, because we cannot guarantee a site that nobody is patching — that is not a sales condition, it is arithmetic.

How often do WordPress sites get hacked?

Often enough that it is a maintenance question rather than bad luck. Almost every compromise we see comes through a known vulnerability in an outdated plugin, with a public exploit and an automated scanner behind it. The site was not targeted; it was found.

Send us the site

The address and when you first noticed is enough to start. You do not need to know what is wrong — that is the part we are for.

Faster still: hello@ohmyweb.in

Optional. Only if you would rather we called.

Emergencies jump the queue. If nothing has reached you quickly, email us directly rather than waiting — the address is above and a person reads it.