About
An Australian WordPress recovery service
We clean infected WordPress sites and put back what the attack broke. That is the whole business.
This site has been answering the same question since 2012: my site got hacked, what do I do? The guides in the archive were written across those years, and most of them still hold up, because the way WordPress sites get compromised has not changed much — an abandoned plugin, an out-of-date core, a password reused somewhere it should not have been.
What has changed is the clean-up. Automated scanning got better at finding payloads and no better at finding the persistence mechanism sitting next to them. Which is why so many people arrive here having already "cleaned" the site once.
So the work is deliberately manual. Someone reads the file tree and the database, finds the entry point, and writes down what they found. It is slower than running a scanner, and it is the reason the site stays clean.
What we think
A clean-up that skips the cause is not a clean-up
The reinfection rate on scanner-only jobs is high, and the reason is simple: the payload gets removed and the way in does not. Every job we do ends with an answer to "how did this happen".
Nobody can quote a turnaround before looking
A guaranteed fix time sounds reassuring and means nothing — infections vary enormously. We give you a timeline after we have assessed the site, and we tell you immediately if it moves.
You should understand what happened to your own site
A scanner log is not an explanation. You get a written summary in plain English, so you can make a sensible decision about what to change.
Nothing destructive without a backup you keep
A full copy of your files and database is taken before anything is touched, and it is yours. If we cannot save something, you hear about it before it goes.
What we will not claim
There is a lot of theatre in website security marketing. Some things you will not find on this site:
- A guaranteed turnaround time quoted before anyone has looked at the site.
- A client count, a "sites cleaned" counter, or a wall of testimonials.
- A promise that your site can never be compromised again. Nobody can offer that.
A timeline before we start
Every infection is different, so we will not quote a turnaround before we have looked. You get a clear timeline once the site has been assessed, and we hold to it.
A fixed price, agreed up front
You approve the price before any work begins. If the assessment shows the job is bigger than the plan you picked, we tell you and you decide.
You find out how it happened
A clean-up that does not identify the way in is a clean-up you will be paying for again. Every job ends with a written explanation of the entry point.
We work on a copy first
Nothing destructive happens to a live site. We take a full backup before touching anything, and you keep it.
Think your site is infected?
Send us the URL and what you are seeing. We will tell you what we find, what it will cost, and how long it will take — before anything is touched.