You have been passed between four parties and none of them have touched the problem. This page is the honest breakdown of what your hosting company, the person who built your website, your security plugin and a security engineer each do and refuse to do. Read it before you pay anybody, including us.
Clean or your money back. Written. Flat $249, no hourly meter.
You do not need to know what your website is built with. We will tell you in the first 10 minutes.
Last updated · Reviewed by Ali Yasin Jatoi
If you ticked even one of these, send us the address of your website and we will look at it for free within the hour.
Your host is responsible for the machine: the hardware, the network, the server software and the backups they promise in your plan. They are not responsible for the website software you run on it, and every mainstream hosting agreement says so. In practice your host will scan, warn you, suspend the account to protect other customers, and sell you a cleanup add on or refer you to a partner. What they will not do on a normal plan is go in, find the hidden way back in, and tell you how it happened.
A web designer builds. That is a project with a start and an end, and unless you signed a maintenance agreement afterwards, security was never in scope. Most small business websites were built three to seven years ago by somebody who has since changed job, gone in house, or simply stopped answering. They are not being rude. They genuinely do not do this work, and quite often they cannot. Being able to build a beautiful website and being able to run a malware cleanup are different trades.
A plugin is excellent at detection and at blocking obvious attacks, and everyone should have one. It is much weaker at removal, for a simple reason: the parts that matter hide in places a plugin does not or cannot look, including the database, scheduled tasks, and files that hide themselves from the plugin list. Worse, using a scanner to delete files is how many blank white websites happen, because the flagged file was a real part of the website that had been modified rather than added.
Takes a full copy first. Reads the server logs to find the entry point rather than guessing. Removes the infection from files and database together, so it cannot reinstall itself. Closes every way back in, including accounts and scheduled tasks. Produces the written evidence your host needs to switch you back on. Requests the Google review. And tells you plainly how it happened so you can decide whether to prevent the next one. That is the job nobody else in the chain is doing.
Nobody's, in the sense you mean. It is almost never a targeted attack on your business and it is rarely carelessness. It is a website built well, handed over, and then left alone for years while the software underneath it kept needing updates that nobody was paid to apply. The responsibility, legally and practically, sits with the website owner. That is an uncomfortable answer, and it is the true one.
Four questions. Will you give me a fixed price before you start? Will you tell me how they got in? Will you give me a written list of what you removed? And what happens if it comes back next week? Anybody who answers those four clearly is worth talking to. Anybody who wants access before quoting, or who cannot explain the entry point afterwards, has probably deleted the visible mess and left the door open.
Ask your host for their scan report and download a full backup. Both are free, both work during a suspension, and both make every later step faster.
Host add on, freelancer, or a security engineer. Ask the four questions above. If the answers are vague, keep looking.
Files and database together, entry point closed, accounts and scheduled tasks cleared, written report produced.
Either you or somebody you pay has to apply updates and hold backups from now on. If it is not going to be you, put it on a retainer.
No quotes, no discovery calls, no hourly meter. You know the number before we touch anything.
One website, one price. Median clean time about 4 hours from the moment we have access. Written report at the end.
Everything above, plus locked down logins, file monitoring, and 60 days of reinfection cover.
Updates on staging, daily backups, monitoring, and a real engineer on call so this never repeats.
Clean or your money back. Written.
No, on a standard shared or managed plan. The host secures the server, you are responsible for the software running in your account. Their hosting agreement will say this in the acceptable use section. They will scan and warn you, and many will sell a cleanup as a separate paid service, but it is not included in the rent.
All four will scan and all four sell or refer a paid cleanup. None of them include full malware removal in a standard plan. If you buy their add on, ask whether it includes finding the entry point and a written report, because the cheaper products often only remove the flagged files.
Assume they are gone and stop waiting, because every day costs you. What you actually need from them is access, and you can get that yourself from your hosting control panel and your domain registrar in most cases. If the developer holds the domain or the hosting in their own name, tell whoever you hire immediately, because that changes the recovery plan.
The paid tiers offer a cleaning service and the free scanner will find plenty. What a scanner cannot reliably do alone is spot a modified core file versus an added one, or find code stored in the database, which is where the parts that bring the infection back usually live. Use a plugin to detect and block. Use a human to remove.
The market runs from about $99 for an automated tool pass to $500 and beyond for agency work, with annual security subscriptions at a few hundred a year. We charge a flat $249 for a standard single website with the report, the Google review request and 30 days of cover included. Be careful with anything much below $99, because at that price nobody is reading logs.
Only if nobody in your business is going to apply updates, hold backups off the server, and watch for problems. If somebody will, do it yourself and keep the money. If nobody will, and that is the usual honest answer, a plan is cheaper than the second cleanup.
Yes, and we publish the actual steps rather than a sales page. The checklists and problem pages on this site are the same process we follow. If you get partway and hit something that needs a log or a database, that is the point to hand it over.
What the host needs before they will switch you back on.
The twelve signs and what each one means.
Our actual process, published, so you can follow it yourself.
If the honest answer is that nobody in your business will do the updates.