Security
Hacked WordPress site cleaned and secured
Visitors were greeted with a defaced homepage and Google began showing security warnings. BugShield removed the malware, rebuilt trust signals, and locked down admin access.
Industry
Digital agency
Service
Emergency malware cleanup
Confirmed price
£99.99
Time to resolve
12 Hours
The challenge
The agency's marketing site was injecting spam links into footers and briefly showing a hijacked homepage overnight. Clients started forwarding screenshots of Google's security warning that the site may be hacked. Business correspondence suddenly gave the impression of a compromised brand.
Admin users had reused passwords across tools, and an outdated plugin left a known entry point. Restoring last week’s backup alone would have brought the same malware back if the injection point stayed open. The team also could not tell whether client project URLs on shared hosting were involved.
They needed emergency cleanup with a clear price, proof the site was clean enough to request a Safe Browsing review, and hardening so the same plugin hole did not reopen the following night.
What visitors and Google were seeing
-
Homepage briefly showed unrelated phishing-style content overnight.
-
Footer spam links appeared on inner pages even when the homepage looked normal.
-
Google Search Console and browser warnings indicated a possible hack.
-
Unknown admin users and scheduled tasks appeared in wp-admin.
-
PHP files with obfuscated code sat under uploads and an abandoned plugin folder.
-
Password resets had been emailed from WordPress without staff requesting them.
How BugShield approached it
BugShield treated this as an emergency cleanup with a confirmed quote. The Vault held hosting, WordPress, and DNS credentials so the developer could work without passwords living in email threads or Slack.
Cleanup covered malware scanning, removing injected files and database spam, rotating compromised credentials, closing the outdated plugin hole, checking core file integrity, and preparing evidence for a Google Safe Browsing review once the public site was clean.
The developer also walked the agency through which client sites on the same host should be scanned next. Scope stayed on the marketing site they registered, with a clear recommendation rather than silent access to unrelated projects.
Timeline
Emergency intake
The agency sent screenshots of Google's security warning and the defaced homepage. They received a confirmed quote and a developer was assigned within an hour.
Containment
Admin passwords were changed, unknown users were removed, and the suspected plugin was disabled while we checked the site files.
Cleanup
Injected PHP, spam database rows, and .htaccess redirects removed. Core and theme files compared against clean copies.
Handoff
Clean scan summary delivered with Safe Browsing review guidance. Shield Pro recommended for ongoing malware checks.
Technical findings
-
An abandoned contact-form add-on with a known CVE was the likely initial entry point.
-
The attackers hid their code by uploading PHP dropper files and modifying an mu-plugin to insert malicious content into the footer.
-
Two unused administrator accounts still had administrator capability from past freelancers.
-
wp-config salts looked unchanged after the incident, so credential rotation alone was not enough without fresh keys.
-
A partial backup restore earlier that week had reintroduced one of the droppers because the backup was taken after infection started.
The result
-
Defacement and spam injections were removed from the live site.
-
Admin passwords and keys were rotated, and unused accounts were disabled.
-
A clean scan report was available for the Safe Browsing review submission.
-
Shield Pro monitoring was recommended so reinfection would alert them early.
-
The agency had a short checklist for every WordPress property they manage for clients.
The homepage returned to the agency’s brand within the cleanup window, and referral traffic started recovering after Google processed the review. The team kept daily malware scans on a Shield Pro plan and stopped relying on ‘restore last backup’ as their only security playbook.
What this prevented next time
Backups without knowing the infection date can restore malware. Cleanup first, then take a clean restore point.
Reused agency passwords across client tools turn one breach into many. The Vault and rotation policy reduced that blast radius for future work.
Why hacked WordPress sites bounce back
Malware often leaves persistence in places a homepage restore never touches: mu-plugins, uploads PHP, cron events, and database options. If the original plugin hole stays open, reinfection can happen overnight even after a cosmetic cleanup.
Emergency WordPress hacked site cleanup has to pair removal with hardening: update or replace the vulnerable plugin, rotate every privileged credential, and verify core integrity before you ask Google to clear a warning.
-
File and database payloads, not just the homepage HTML
-
Unused administrator accounts from past freelancers
-
Outdated plugins with known public CVEs
-
Backups taken after infection began
-
Shared passwords across hosting and SaaS tools
Cleaning the site and clearing Google warnings
BugShield's job was to remove the hack, close the entry point, and get the site back to normal. Clearing Google's warning is a separate step that happens after the site is clean.
Once cleanup was done, the agency submitted a review request in Google Search Console. Google checks the site on their own schedule, so the warning can stay visible for a while even after the site looks fine to visitors.
FAQs
Could they have just restored a backup?
A backup only helps if it was taken before the infection and after the entry point is closed. Their earlier restore had already reintroduced malware. BugShield cleaned the live site and then hardened access.
Did BugShield remove the Google warning?
No. BugShield cleaned the site and explained what the agency needed to submit in Google Search Console. Google reviews that request separately, and the warning can take time to clear.
Was the price confirmed upfront?
Yes. Malware cleanup was quoted at a fixed emergency price before any work started.
Were client project sites cleaned too?
This engagement covered the agency marketing site they registered. We recommended scanning other WordPress properties on the same host and offered separate quotes rather than touching them without scope.
How fast was a developer assigned?
Within one hour of payment.
What stopped reinfection?
Removing the vulnerable plugin path, rotating credentials, clearing persistence files, and moving onto Shield Pro scans so new payloads would alert early.
More case studies
WooCommerce
WooCommerce checkout restored the same day
A mid-size UK fashion shop had card payments fail after a payment plugin update. Within hours, orders were flowing again.
Read case studyError fix
WordPress critical error after update, fixed the same day
A UK charity’s donation site white-screened after weekend updates. BugShield diagnosed a plugin conflict, restored access, and verified forms before donors returned on Monday.
Read case studyEmergency
WordPress site down: emergency recovery the same afternoon
A consultancy’s WordPress site returned DNS errors and SSL warnings in the middle of client meetings. BugShield restored availability before the end of the day.
Read case studyFacing something similar?
Get a confirmed price, a BugShield developer, and direct chat from payment onwards.
Request a Fix