If your WordPress site was hacked, the first thing you should do is not restore an old backup: the backdoor will come back with it. We run a diagnostic within 24 hours and have the site cleaned up and back online within 48, with the backdoors closed and a review request submitted to Google. Starting at 300,000 in Chile.
Before calling anyone
What to Do in the
First Few Hours.
It makes no difference whether you hire us or not. What you do in the next few hours will determine whether recovery takes two days or two weeks.
- Don't restore an old backup just yet
If the backdoor already existed when that backup was made, reinfection is only a matter of hours. First, you need to figure out how they got in.
- Back up the current state before making any changes
Files and databases, just as they are now. That raw backup is the evidence that makes it possible to reconstruct how the attack occurred.
- Change your passwords from another device
Hosting, FTP or SFTP, WordPress, and the database. From another computer, in case yours is part of the problem.
- Check the administrator users
The attacker almost always leaves a user account behind so they can log back in, even if you clean up the rest of the site.
- Take the site offline if it is displaying injected content
Put it into maintenance mode. You'll protect your visitors and prevent Google from continuing to index the spam that was posted on your site.
- Don't request a review from Google just yet
This is the mistake that takes the most time: if you submit the request while the site is still infected, you'll waste that attempt, and the next review will take longer.
Why Is It Happening Again?
Cleaning isn't the same as closing the door.
An infected backup was restored
The number one cause of the second infection. The backup was created after the backdoor was already in place, so it brings it back.
The plugin that opened the door was left behind
The site is cleaned up, but the vulnerable extension is left in place. The next time the bot scans for it, the site goes down again.
The keys were never all changed
It only takes one: the hosting account, the FTP account, or a database user. With that, they can log in again without having to break in.
No one is viewing the site
Without monitoring, the next infection isn't discovered until a customer reports it or Google has already issued a warning. It's always too late.
How do we get it back?
Diagnosis within 24 hours; back on your feet within 48.
-
Hour 0: Containment
We secure the site, document the current state as evidence, and block the attacker's access.
-
After 24 hours: diagnosis
We'll tell you where they broke in, what they went through, and what they took. That way, you'll know what you're up against without having to wait until it's all over.
-
In 48 hours: clean and up and running
The site is now free of malware and backdoors, has new passwords, up-to-date plugins, and has been republished.
-
Next: Google review
We've requested that the warning in Search Console be lifted and have provided you with a report on what happened.
No fine print
What's Included
in the Recovery.
- Removing malware and any backdoors they left behind
- File-by-file and database review, not just an automatic scan
- Update WordPress, the theme, and the plugins, starting with the one that opened the door
- Reset all credentials: hosting, FTP, WordPress, and database
- Removing Administrator Users You Don't Recognize
- Hardening the site so that the same hole cannot be used again
- Request a review in Google Search Console to remove the warning
- Report on what happened, where they entered, and what was locked
Measured, not promised
That's how vulnerable
these sites are.
These are the security headers for the sites we rebuilt, showing the before and after results, as measured by Security Headers. These aren't sites that have been attacked, this is the state in which normal sites arrive, and 2 of the 4 started with an "F." You can repeat the measurement yourself at securityheaders.com.
- Viña del Mar Fire Department bomberosvinadelmar.clB A+
- IGNEO igneobomberos.clF A+
- Dr. David Oschilewski dr-oschilewski.clF A+
- Profugas profugas.clC A+
What people who have been through Rocket have to say
Verified reviews from
satisfied customers.
"The best we could do. Highly recommended, A+++"
They perfectly captured the web design style we were looking for. The project progressed quickly and was delivered on time. The sales and technical support were efficient and prompt, even during the holidays.
"Professionalism, commitment, and quality"
Their team was always eager to help, offering personalized and effective solutions. We are very pleased with the results achieved on our website. We definitely recommend them.
"It's been over two years, and it has never let me down."
Joaquín is always available to answer my questions, since technology sometimes gets the better of me. I put my trust in Rocket Media, and I recommend them 100%. Thank you, Rocket Media!
"Their after-sales and technical service is very good."
I have two websites with them, I built the first one 4 years ago and the other one 2 years ago. They've worked perfectly! I go back to them every so often for help with updates. They fixed the issues quickly.
"Security from Start to Finish"
Our project manager was thoroughly professional and always went out of his way to meet our needs. I would like to highlight the smooth communication, which led to a final result that was exactly what we had hoped for.
"They met all expectations"
Excellent company. We started the web development project from Australia, and they met all our expectations. 100% recommended!
Recovery starting at $300,000.
Free diagnosis within 24 hours. We'll give you a fixed price before we do anything.
To Make Sure It Doesn't Happen Again
Recovering it is the beginning,
not the end.
We’ll provide you with the assessment within the first 24 hours and have the site cleaned up and back online within 48 hours. That’s the timeline we commit to for a corporate website. If the attack compromised the entire server, not just WordPress, we’ll let you know right in that assessment instead of quietly extending the timeline.
Starting at $300,000, depending on the size of the site and how far inside they got. There’s no charge for the initial assessment: we take a look first, and only then do we give you a fixed price. In an emergency, the last thing you need is a surprise halfway through.
Almost never. Before we clean up, we back up the entire current state, so there’s always a way to revert. What does sometimes get lost are files that the attacker deleted, and that’s where your hosting provider’s previous backup serves as a safety net. That’s why we request access to your hosting right from the start.
Yes, but you should only request it once. Once the site is truly clean, we request a review in Search Console, and Google lifts the warning. If you request it too soon, while traces of the infection are still present, it gets rejected, and the next review takes longer. This is the most common mistake people make when they try to fix it on their own.
A security plugin doesn’t fix a vulnerability that already exists in another outdated plugin. Most attacks on WordPress don’t involve guessing your password, they exploit a known vulnerability in a plugin that wasn’t updated in time. That’s why cleaning up without updating is of little use.
Two options. The cheaper one is to leave the site as-is and have someone monitor it every month. The permanent solution is to move away from WordPress: a site built from scratch has no plugins to update and no public admin panel to attack. We’ll show you both, and you can decide.
Your next step
How's your website today?
You already know what your business needs to grow. Now, in just 1 minute, analyze your current website and discover all the mistakes that are holding you back.