Security and hacked site cleanup
A hacked site is almost never limited to a single modified page. Cleanup starts with understanding how access was obtained, otherwise the problem comes back within days, sometimes more discreetly than the first time.
What points to a hack
- The site redirects to another domain, intermittently or only on mobile.
- Google or your host shows a warning about dangerous or deceptive content.
- Unknown pages appear in search results, with content you never published.
- An admin account exists that you didn't create, or a password changed without you doing it.
- The site is unusually slow, with high server activity and no obvious explanation.
How the cleanup runs
-
Containment
Putting immediate measures in place to limit the damage during investigation, without necessarily cutting access to the site if it's not needed.
-
Identifying the flaw
Finding the real source of the intrusion: an outdated module, a compromised password, a flaw in a theme or extension.
-
Cleaning the code and data
Removing injected code, fraudulently created accounts and files added without authorisation.
-
Closing the flaw
Updating or fixing the identified entry point, to prevent immediate reinfection through the same path.
-
Verification and review request
Checking the cleaned site, then requesting removal of any Google warning if applicable.
-
Strengthening monitoring
Setting up a regular check after the incident, to catch any sign of recurrence earlier.
- 2019 e-commerce developer since
- 3 platforms: PrestaShop, WooCommerce, Shopify
- 3 working languages: FR, EN, TR
- 100 % direct contact with the developer
No middleman: the person who replies is the one who works on the code.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.