Logo JR Agency JR Agencyweb & ia FR / EN / PT

services · wordpress security

Hacked site? We find the door.

Not just the malware. Cleaning a hacked WordPress site without understanding how the attacker got in means watching them come back two days later. We investigate, clean up, harden, and leave you a report your team or your host can apply.

symptoms

You are probably in the right place if…

payment alert

Stripe, PayPal or your bank reports an API key used from an unknown address. This is often the first sign: many plugins store keys in plain text.

it keeps coming back

You already cleaned up, changed the passwords, and the site was compromised again a few days later. A door was left open: a hidden loader, an import key, an inconspicuous account.

unknown accounts

Administrators nobody created, plugins nobody installed, PHP files sitting in the uploads folder.

google or your host

A "dangerous site" warning in search results, an email from your host, spam sent from your domain, redirects to shady sites.

first-seen · sha-256 hash · nginx logs · timeline

method

Investigate first, clean up second

01 · forensics

A proven timeline

Server logs, file fingerprints, first-seen dates: we reconstruct the intrusion and date every step. Evidence preserved, no payload ever executed.

02 · cleanup

Every door closed

Loaders and backdoors removed, secrets rotated (database, salts, API keys), rogue accounts and plugins purged, WordPress core verified file by file.

03 · hardening

So it does not come back

Automatic updates genuinely active, PHP execution blocked in uploads, web application firewall in blocking mode, tested off-site backups, daily monitoring.

04 · report

A deliverable, not an email

Timeline, root cause, impact (data, payments, GDPR obligations), fixes done, fixes still to do and by whom. Readable by management, actionable by your tech team.

real case · 2026

Two intrusions in ten days, a single cause

The website of a Brussels association was compromised for the first time in mid-August: Stripe payment key stolen, rogue administrator accounts, a file manager plugin that appeared out of nowhere. The site was cleaned, the passwords changed. Two days later, it happened again.

Our investigation showed there were not two attacks but one: a loader planted a month earlier in a rarely watched folder, reinstalled through an import plugin whose key had never been revoked. We dated every step, proved that the member database had not been exfiltrated, and identified why the August WordPress security patch had never been applied: a plugin was silently switching off automatic updates.

Delivered in six days: a report with 34 exhibits, a defence chain tailored to their server, and daily monitoring until handover. The site has been quiet ever since.

See the case in our work

cron 9am · surveillance.log · 10 "ok" before closing

preventive

Security audit before the incident

who it is for

Sites that take payments, store member or patient data, or cost real money when they go down. Associations, e-commerce, professional practices.

what we look at

Versions and updates, risky plugins, secrets and API keys, account permissions, server configuration, backups (do they exist, are they tested, are they off-site).

what you get

A prioritised report: what is urgent, what is important, what can wait, with who does what, and how, for every item. Then, if you want it, maintenance that keeps it that way.

frequently asked questions

WordPress security FAQ

My host already cleaned the site. Why run an audit?

A cleanup removes what is visible. The audit establishes how the attacker got in and verifies that entry point is closed. Without it, you clean the symptom and keep the cause.

How long does it take?

An emergency response starts within 1 business day. Investigation and cleanup usually take between two and six days depending on the size of the site and access to logs. The report follows straight after.

Do I have to notify the data protection authority or the people affected?

It depends on what leaked: the report documents it precisely (data accessed or not, evidence). That factual basis is what you need to decide with your counsel, within the 72 hours set by the GDPR.

Do you work with my IT person or my host?

Yes, and it is often the best setup: we investigate and recommend, your technician applies what belongs to the server. We work read-only unless writing is necessary.

How much does it cost?

An audit on a standard WordPress site is a fixed fee, agreed before we start, not a running meter. Describe the situation and you get the figure within 2 business days.

Describe the situation