Skip to main content

Web Development

Website Security & Malware Removal

If your site is currently compromised, call rather than reading further. Every hour a warning shows in search results costs traffic and trust.

Malware removal cleans an infected site, closes the vulnerability that allowed it, and gets the Google warning lifted. The Nexclick works from backups and file comparison rather than guesswork, and treats finding the entry point as the job — a cleaned site with the hole still open reinfects.

Book a 20-minute callFixed-price project · Web Development from £4,500

Is this you?

What usually prompts the call

  • Google shows "This site may be hacked" or a red warning before your site loads.
  • Your site redirects visitors somewhere else, but only from search results.
  • Your host has suspended the account for sending spam.
  • Pages you did not create are appearing in search results under your domain.

What we do

The actual deliverables

Things that appear on an invoice, not adjectives.

Contain first
Take the site offline or into maintenance mode if it is actively serving malware. Stopping harm to visitors comes before diagnosis.
Identify the infection
File comparison against clean core and plugin releases, database scanning for injected content, and log analysis to establish when it started.
Find the entry point
Vulnerable plugin, weak password, compromised host account or an old backdoor from a previous infection. This is the actual job — cleaning without it guarantees reinfection.
Clean thoroughly
Malicious files removed, injected database content cleaned, and backdoors hunted specifically. Attackers routinely leave several, in places that look legitimate.
Close the vulnerability
Patch or remove what allowed it, rotate every credential, and review user accounts for ones that should not exist.
Request review and clear warnings
Google Search Console security issue review, host reinstatement, and blocklist removal requests where the domain has been listed.
Harden against recurrence
File permissions, login protection, update discipline and monitoring, so the same route is not available again in six months.

Checklist

What to do in the first hour of a hack

If your site is compromised right now, work through this. It is the sequence we follow, and doing the first four before calling anyone makes the remediation faster and cheaper.

  1. 01Put the site into maintenance mode or take it offline — stop harming visitors first.
  2. 02Do not delete anything yet. You need the evidence to find the entry point.
  3. 03Take a full copy of files and database as they are, and store it separately.
  4. 04Change the hosting control panel password and enable two-factor authentication.
  5. 05Change database, FTP and SFTP credentials.
  6. 06Change every CMS administrator password, and check for admin accounts nobody created.
  7. 07Check Google Search Console for a security issue notice and read what it says.
  8. 08Check whether your domain appears on any blocklist.
  9. 09Tell your host — they may already have detected it and can help.
  10. 10Check whether your backups predate the infection, and whether they are also infected.
  11. 11Check email — compromised sites are frequently used to send spam, which affects deliverability.
  12. 12Do not simply restore a backup and consider it resolved — the entry point is still open.
  13. 13Note when you first noticed the problem; it helps narrow the log search considerably.
  14. 14Warn your team not to log in from the affected site until it is clean.

How it works

Step by step, with timeframes

Timeframes are typical rather than guaranteed, and they assume we get account access and approvals when we ask.

  1. 01Hours 1–4

    Contain and assess

    Stop active harm, take a forensic copy, and establish the scale. Speed matters here more than anywhere else in this service list.

  2. 02Day 1–3

    Clean and close

    Infection removed, entry point identified and closed, credentials rotated. Cleaning without closing is the most common failed remediation.

  3. 03Day 2–5

    Request review

    Search Console review submitted. Google typically responds within one to three days if the site is genuinely clean.

  4. 04Week 1–2

    Harden and monitor

    Hardening applied and monitoring configured, with a follow-up scan at fourteen days to confirm nothing has returned.

What you get

Reporting and ownership

  • A written incident report: what happened, how they got in, what was cleaned and what was changed.
  • A forensic copy retained, in case anything needs revisiting.
  • Search Console review submitted and warnings tracked until cleared.
  • Every credential rotated, with a record of what was changed.
  • A follow-up scan at fourteen days included, because reinfection shows up in the first fortnight.

Tools and platforms

  • File integrity comparison against clean releases
  • Server and access log analysis
  • Google Search Console (security issues)
  • Malware scanners as a cross-check, not a diagnosis
  • Blocklist status checks
  • WP-CLI and database tooling

Timeline

How long this actually takes

Containment within hours of being called. Cleaning and closing the entry point takes one to three days for a typical compromise, longer where the infection is old and has spread through backups. Google’s security review takes one to three days once submitted. Blocklist removals vary and some take a week. Two honest points. Search rankings usually recover within weeks of the warning clearing, but not always fully. And if backups are also infected — common where an infection went unnoticed for months — restoration is not an option and the cleaning is substantially more work.

Pricing model

Fixed-price project

Fixed price for a standard compromise, quoted after a short assessment. Where the infection is extensive or backups are also affected, the additional work is quoted before it starts rather than added afterwards.

Full pricing

Questions

Website Security & Malware Removal questions

Can we just restore a backup?

Only if you know the backup predates the infection and you have closed the entry point. Restoring alone reinstates the same vulnerability, and reinfection typically follows within days. Where an infection went unnoticed for months, the backups are usually infected too.

How long until the Google warning disappears?

Usually one to three days after submitting a security review, provided the site is genuinely clean. A review submitted on a site that still has a backdoor gets rejected, which wastes days — which is why we clean thoroughly before submitting rather than the other way round.

Will our rankings recover?

Mostly, and usually within weeks of the warning clearing. Recovery is faster where the compromise was caught quickly. Where a site spent months serving spam pages, some loss can persist, because the damage is to accumulated trust rather than just to the current index state.

How did they get in?

Most commonly an out-of-date plugin or theme with a known vulnerability. After that: weak or reused passwords, a compromised hosting account, and backdoors left from an earlier infection nobody fully cleaned. Establishing which is the core of the job, not an optional extra.

Was our site specifically targeted?

Almost never. The overwhelming majority of compromises are automated scans looking for known vulnerabilities across the whole web. It is not personal, which is worth knowing — it also means it will happen again if the vulnerability stays open.

How do we stop it happening again?

Update discipline, removing abandoned plugins, strong unique credentials with two-factor authentication, and monitoring that alerts on file changes. Nearly every site we clean had no monitoring and months of skipped updates. Maintenance is the preventative version of this service and costs a fraction of it.

Tell us what you are trying to fix

A 20-minute call, no pitch deck. The Nexclick will tell you what we would do, roughly what it costs, and whether we are the right people for it.