services · wordpress security
Hacked site? We find the door.
Not just the malware. Cleaning a hacked WordPress site without understanding how the attacker got in means watching them come back two days later. We investigate, clean up, harden, and leave you a report your team or your host can apply.
symptoms
You are probably in the right place if…
Stripe, PayPal or your bank reports an API key used from an unknown address. This is often the first sign: many plugins store keys in plain text.
You already cleaned up, changed the passwords, and the site was compromised again a few days later. A door was left open: a hidden loader, an import key, an inconspicuous account.
Administrators nobody created, plugins nobody installed, PHP files sitting in the uploads folder.
A "dangerous site" warning in search results, an email from your host, spam sent from your domain, redirects to shady sites.
method
Investigate first, clean up second
A proven timeline
Server logs, file fingerprints, first-seen dates: we reconstruct the intrusion and date every step. Evidence preserved, no payload ever executed.
Every door closed
Loaders and backdoors removed, secrets rotated (database, salts, API keys), rogue accounts and plugins purged, WordPress core verified file by file.
So it does not come back
Automatic updates genuinely active, PHP execution blocked in uploads, web application firewall in blocking mode, tested off-site backups, daily monitoring.
A deliverable, not an email
Timeline, root cause, impact (data, payments, GDPR obligations), fixes done, fixes still to do and by whom. Readable by management, actionable by your tech team.
real case · 2026
Two intrusions in ten days, a single cause
The website of a Brussels association was compromised for the first time in mid-August: Stripe payment key stolen, rogue administrator accounts, a file manager plugin that appeared out of nowhere. The site was cleaned, the passwords changed. Two days later, it happened again.
Our investigation showed there were not two attacks but one: a loader planted a month earlier in a rarely watched folder, reinstalled through an import plugin whose key had never been revoked. We dated every step, proved that the member database had not been exfiltrated, and identified why the August WordPress security patch had never been applied: a plugin was silently switching off automatic updates.
Delivered in six days: a report with 34 exhibits, a defence chain tailored to their server, and daily monitoring until handover. The site has been quiet ever since.
preventive
Security audit before the incident
Sites that take payments, store member or patient data, or cost real money when they go down. Associations, e-commerce, professional practices.
Versions and updates, risky plugins, secrets and API keys, account permissions, server configuration, backups (do they exist, are they tested, are they off-site).
A prioritised report: what is urgent, what is important, what can wait, with who does what, and how, for every item. Then, if you want it, maintenance that keeps it that way.
frequently asked questions
WordPress security FAQ
My host already cleaned the site. Why run an audit?
A cleanup removes what is visible. The audit establishes how the attacker got in and verifies that entry point is closed. Without it, you clean the symptom and keep the cause.
How long does it take?
An emergency response starts within 1 business day. Investigation and cleanup usually take between two and six days depending on the size of the site and access to logs. The report follows straight after.
Do I have to notify the data protection authority or the people affected?
It depends on what leaked: the report documents it precisely (data accessed or not, evidence). That factual basis is what you need to decide with your counsel, within the 72 hours set by the GDPR.
Do you work with my IT person or my host?
Yes, and it is often the best setup: we investigate and recommend, your technician applies what belongs to the server. We work read-only unless writing is necessary.
How much does it cost?
An audit on a standard WordPress site is a fixed fee, agreed before we start, not a running meter. Describe the situation and you get the figure within 2 business days.