A real engineer picks up in about 11 minutes, day or night.

Who is actually responsible for fixing this?

You have been passed between four parties and none of them have touched the problem. This page is the honest breakdown of what your hosting company, the person who built your website, your security plugin and a security engineer each do and refuse to do. Read it before you pay anybody, including us.

Clean or your money back. Written. Flat $249, no hourly meter.

You do not need to know what your website is built with. We will tell you in the first 10 minutes.

Last updated · Reviewed by Ali Yasin Jatoi

Tell us what your site needs

One form for every service. Maintenance, emergencies, development, migrations, speed, security and SEO. A senior engineer reads it, not a bot.

A WordPress engineer replies within 1 business hour. 150+ WordPress sites managed by founder at Pearl Lemon No card, no contract

Free. No sales pitch. If we are not the right fit, we will tell you who is.

Secure and private 30 day money back No lock in contract

Is this you?

  • Your host said malware removal is not covered by your plan
  • Your host offered a paid cleanup add on and you are not sure it is worth it
  • The person who built your website has stopped replying
  • The developer replied to say they do not do maintenance
  • Your security plugin found dozens of issues and asked for an upgrade
  • You have been quoted wildly different prices by three different people
  • Nobody has told you how the attacker got in

If you ticked even one of these, send us the address of your website and we will look at it for free within the hour.

What your hosting company does

Your host is responsible for the machine: the hardware, the network, the server software and the backups they promise in your plan. They are not responsible for the website software you run on it, and every mainstream hosting agreement says so. In practice your host will scan, warn you, suspend the account to protect other customers, and sell you a cleanup add on or refer you to a partner. What they will not do on a normal plan is go in, find the hidden way back in, and tell you how it happened.

What the person who built your website does

A web designer builds. That is a project with a start and an end, and unless you signed a maintenance agreement afterwards, security was never in scope. Most small business websites were built three to seven years ago by somebody who has since changed job, gone in house, or simply stopped answering. They are not being rude. They genuinely do not do this work, and quite often they cannot. Being able to build a beautiful website and being able to run a malware cleanup are different trades.

What your security plugin does

A plugin is excellent at detection and at blocking obvious attacks, and everyone should have one. It is much weaker at removal, for a simple reason: the parts that matter hide in places a plugin does not or cannot look, including the database, scheduled tasks, and files that hide themselves from the plugin list. Worse, using a scanner to delete files is how many blank white websites happen, because the flagged file was a real part of the website that had been modified rather than added.

What a security engineer does

Takes a full copy first. Reads the server logs to find the entry point rather than guessing. Removes the infection from files and database together, so it cannot reinstall itself. Closes every way back in, including accounts and scheduled tasks. Produces the written evidence your host needs to switch you back on. Requests the Google review. And tells you plainly how it happened so you can decide whether to prevent the next one. That is the job nobody else in the chain is doing.

So whose fault is it, honestly?

Nobody's, in the sense you mean. It is almost never a targeted attack on your business and it is rarely carelessness. It is a website built well, handed over, and then left alone for years while the software underneath it kept needing updates that nobody was paid to apply. The responsibility, legally and practically, sits with the website owner. That is an uncomfortable answer, and it is the true one.

How to judge whoever you hire, including us

Four questions. Will you give me a fixed price before you start? Will you tell me how they got in? Will you give me a written list of what you removed? And what happens if it comes back next week? Anybody who answers those four clearly is worth talking to. Anybody who wants access before quoting, or who cannot explain the entry point afterwards, has probably deleted the visible mess and left the door open.

What happens once you say go

  1. Step 1

    Get the evidence

    Ask your host for their scan report and download a full backup. Both are free, both work during a suspension, and both make every later step faster.

  2. Step 2

    Decide the route

    Host add on, freelancer, or a security engineer. Ask the four questions above. If the answers are vague, keep looking.

  3. Step 3

    Clean once, properly

    Files and database together, entry point closed, accounts and scheduled tasks cleared, written report produced.

  4. Step 4

    Decide about next time

    Either you or somebody you pay has to apply updates and hold backups from now on. If it is not going to be you, put it on a retainer.

What it costs

No quotes, no discovery calls, no hourly meter. You know the number before we touch anything.

  • Emergency cleanup
    $249 flat

    One website, one price. Median clean time about 4 hours from the moment we have access. Written report at the end.

  • Cleanup plus hardening
    $449 flat

    Everything above, plus locked down logins, file monitoring, and 60 days of reinfection cover.

  • Care plan after the fix
    $99 a month

    Updates on staging, daily backups, monitoring, and a real engineer on call so this never repeats.

Clean or your money back. Written.

Questions people ask us at this exact moment

Is my web host responsible for malware on my website?+

No, on a standard shared or managed plan. The host secures the server, you are responsible for the software running in your account. Their hosting agreement will say this in the acceptable use section. They will scan and warn you, and many will sell a cleanup as a separate paid service, but it is not included in the rent.

Will Bluehost, HostGator, SiteGround or GoDaddy fix my hacked site?+

All four will scan and all four sell or refer a paid cleanup. None of them include full malware removal in a standard plan. If you buy their add on, ask whether it includes finding the entry point and a written report, because the cheaper products often only remove the flagged files.

My web developer is not responding. What now?+

Assume they are gone and stop waiting, because every day costs you. What you actually need from them is access, and you can get that yourself from your hosting control panel and your domain registrar in most cases. If the developer holds the domain or the hosting in their own name, tell whoever you hire immediately, because that changes the recovery plan.

Does Wordfence or a similar plugin remove malware?+

The paid tiers offer a cleaning service and the free scanner will find plenty. What a scanner cannot reliably do alone is spot a modified core file versus an added one, or find code stored in the database, which is where the parts that bring the infection back usually live. Use a plugin to detect and block. Use a human to remove.

How much should a hacked website cleanup cost?+

The market runs from about $99 for an automated tool pass to $500 and beyond for agency work, with annual security subscriptions at a few hundred a year. We charge a flat $249 for a standard single website with the report, the Google review request and 30 days of cover included. Be careful with anything much below $99, because at that price nobody is reading logs.

Do I need a maintenance plan afterwards?+

Only if nobody in your business is going to apply updates, hold backups off the server, and watch for problems. If somebody will, do it yourself and keep the money. If nobody will, and that is the usual honest answer, a plan is cheaper than the second cleanup.

Can you just tell me what to do so I can fix it myself?+

Yes, and we publish the actual steps rather than a sales page. The checklists and problem pages on this site are the same process we follow. If you get partway and hit something that needs a log or a database, that is the point to hand it over.

Related pages

Emergency Book a call