An illustrative consultation on cleaning up a hacked WordPress site or server — what access is needed, whether the site stays online, how long it takes, and what happens if the infection comes back.
Our site is showing weird redirects and it's on a blacklist. What do you actually need from us to start cleaning it up?
To begin, I need the website URL, WordPress admin login, hosting panel access (hPanel, cPanel, or similar), SSH access if it's available, and FTP/SFTP as a fallback — plus a description of what you're seeing: redirects, errors, blacklist warnings, or strange files. If you don't have SSH access, message me first so I can confirm what level of cleanup is realistic.
Is SSH actually necessary? We only have FTP access right now.
SSH is strongly preferred — it's what lets me find malware hidden in system files, check server-level cron jobs, identify the actual persistence mechanism, and remove backdoors at the root level. FTP-only cleanup is still possible using FTP and WordPress admin, but some persistent malware may be impossible to fully remove without shell access. If FTP is all you have, tell me before ordering so I can set expectations.
We can't afford downtime. Will the site go offline while you're working on it?
No — the site stays online for the entire process. I always take a full backup before touching anything, so if an issue comes up mid-cleanup, I restore immediately. In most cases your visitors won't notice a thing.
How long is this going to take?
For a single site, usually 24 hours. For three sites, around 48 hours. For up to ten sites, about 3 days. If the server itself is heavily infected it can take longer, but I'll give you a clear timeline before starting any work.
What if the malware just comes back a few weeks later? That's happened to us before.
That's usually because the persistence mechanism — the thing that lets the malware recreate itself — was never actually removed, only the visible files were. I offer a 30-day guarantee: if malware returns within 30 days of my cleanup, I clean it again completely free, no questions asked. Finding and destroying the root cause is what makes that guarantee possible.
Will we lose any content, orders, or user accounts during this?
No. A full backup of the site and database is taken before any cleanup begins. Posts, pages, products, users, and settings are all preserved — only malicious files and code are removed. If a file is borderline, I back it up and review it before taking any action.
Once the malware is gone, do you make sure the site actually still works properly?
Yes. After removal I verify the site loads correctly, check every page and feature, fix anything that broke during cleanup, clear all caches, and test speed and performance before calling it done.
What do you do to stop this from happening again?
I apply security hardening as part of the cleanup: correct file and folder permissions, Wordfence installed and configured, 2FA recommendations, removal of unused plugins and themes, updates to WordPress core and everything installed, automatic backups set up, and a recommendation to rotate passwords across all accounts.
What do we actually get handed back at the end of this?
A full delivery package: a clean, working WordPress site, a report of every piece of malware found and removed, a database cleanup report, a list of verified active plugins and themes, a root cause explanation, a security hardening report, a 24-hour verification result, and confirmation of the 30-day guarantee. Everything is documented so you know exactly what was done and why.
Malware types this covers, based on direct experience — if what you're seeing isn't listed, ask and it can be confirmed quickly.
If malware returns within 30 days of cleanup, it gets cleaned again — completely free, no questions asked. This is possible because the work targets the persistence mechanism itself, not just the visible files.
Website URL, WordPress admin login, hosting panel access, SSH access (preferred) or FTP/SFTP, and a description of the symptoms you're seeing.
It's strongly preferred for finding hidden malware, checking cron jobs, and removing backdoors at the root level. FTP-only cleanup is possible but more limited.
No — the site stays online the whole time. A full backup is taken first, so any issue can be reversed immediately.
About 24 hours for one site, 48 hours for three, and 3 days for up to ten, depending on infection severity.
A 30-day guarantee covers a free re-clean, since the persistence mechanism — the actual root cause — is removed, not just the files.
No — content, posts, products, users, and settings are all preserved. Only malicious code is removed, after a full backup.
Yes — every page and feature is checked, caches are cleared, and performance is tested before delivery.
Yes — permissions, Wordfence, 2FA recommendations, plugin/theme cleanup, updates, and automatic backups are all part of the process.
A clean working site, a full malware and database report, root cause explanation, security hardening report, 24-hour verification, and the 30-day guarantee confirmation.
Message Naveed Ali Qureshi directly on WhatsApp with your site's symptoms for a scoped answer.
Send us a message directly — no signup needed.