Initial assessment without passwords Quote before intervention One accountable specialist from start to finish
Initial assessment available

SPECIALIST WORDPRESS SUPPORT

Compromised Form and Notification Recovery

Specialist assessment within WordPress form, SMTP and email delivery repair. Clear scope and quote before access, the smallest supported change, testing and a documented close-out.

15+
years with
WordPress
01
specialist from
start to finish
documented
intervention

A hacked WordPress site is an incident of access, persistence and business impact — not just a pile of suspicious files. A site can look completely normal to you while it sends spam, redirects only search visitors, or keeps hidden administrators. Recovery works in a deliberate order.

Step 1 — Regain control and contain

Confirm you legitimately hold the hosting account, the domain and the recovery email. If the site is actively harming visitors, you can take it offline behind a maintenance page while you work — but preserve a backup of the compromised state first, because that is your evidence.

Step 2 — Establish the timeline

Server access logs and file modification dates are the most useful evidence you have. Sort /wp-content by modification time to see what changed recently, and match it against the access log around that moment. This is what turns “we were hacked” into “this file was written at this time from this request”.

Is your website affected right now?

Send the URL and the symptom you can see. Jordi Ensenyat reviews the case personally and defines the scope and quote before anything is changed. This form never asks for passwords.

Step 3 — Eradicate every foothold

  • Reinstall WordPress core and reinstall plugins and themes from clean sources; delete anything inactive or unrecognised.
  • Search for backdoors — eval(, base64_decode(, obfuscated blobs — including inside /wp-content/uploads and mu-plugins.
  • Audit the database: unexpected administrators, injected options, spam posts, and the cron array for tasks that restore the payload.
  • Review wp-config.php and server config for injected includes.

Step 4 — Rotate everything and close the hole

Change all WordPress, database, SFTP/FTP and hosting passwords, and invalidate sessions so stolen cookies die. Then update or replace the vulnerable component that allowed entry — reinstalling without patching the hole just invites the same attack again.

Step 5 — Recover reputation

If the compromise reached search results — spam pages, a “this site may be hacked” label, or a Search Console security issue — the cleanup has a second half: remove the spam URLs, confirm the site is genuinely clean, and only then request a review. Requesting it too early usually makes the warning stick longer.

When to escalate

Reinstalling WordPress is not enough on its own, and a compromise that touches customer data, payments or many sites deserves specialist handling. Send the URL, the symptoms and any hosting warnings and the incident can be assessed before access is requested.

EVIDENCE-LED WORDPRESS RECOVERY

Recover a hacked WordPress site without hiding the cause

In WordPress form, SMTP and email delivery repair, the visible symptom may be far from the cause. The objective is to trace the full route from browser submission to mailbox and restore verifiable delivery. A compromised site is an incident involving access, persistence and business impact—not just a collection of suspicious files. Recovery prioritises control of the website, preservation of useful evidence, removal of malicious changes and closure of the entry point where it can be established.

What we verify

  • The complete journey, not only the screen where the error appears
  • External dependencies, logs and evidence before configuration changes
  • Authorised control of hosting, domain, WordPress and recovery email
  • Malware, backdoors, rogue users, scheduled tasks and modified server rules
  • Exposed credentials, vulnerable components and unauthorised integrations
  • Clean public behaviour, administrator access and monitoring after recovery

What a verified outcome means

Close-out documents the cause found, the change applied and the tests performed. The result must be observable and repeatable—not a feeling that it “seems to work”.

BEFORE THE ASSESSMENT

Common questions about this WordPress incident

How do you verify that the problem is genuinely resolved?+

The affected journey is reproduced, its dependencies are checked and post-change evidence is recorded.

What is the first priority after discovering a hacked WordPress site?+

Regain authorised control, limit further damage and preserve evidence before making broad changes that could hide the entry point.

Is reinstalling WordPress enough?+

No. Compromise may remain in uploads, plugins, themes, the database, server configuration, users or stolen credentials.

When can the website be considered recovered?+

When malicious behaviour and persistence are removed, access is controlled, affected journeys are tested and remaining risks are documented.

Assess my incident