We reply 24/7 every day · usually within 2 h

SajtjourenHacked WordPress · cleanupGet help now

Emergency help for hacked WordPress sites

Hacked WordPress site? We clean it up and help you get back on track.

For businesses, organisations and individuals. We go through the site and tell you what's wrong and what it costs – from €229 excl. VAT. You approve the price before we touch anything.

  • Replies 24/7, usually within 2 hours
  • Price before we start – no extra hours without your OK
  • Sweden, Norway and the rest of the world
Example case

Case #0042

example.com

Inspection in progress

Host
Shared hosting
Opened
09:14
Symptom
Redirects to a casino site
  1. Received
  2. Inspection
  3. Quote
  4. Cleanup
  5. Done

Inspection · logwp 6.4.3 · php 8.1

SCANwp-content/ · 4 812 files

FOUNDeval(base64_decode(...)) in wp-content/uploads/2024/03/cache.php

FOUNDunknown admin: wp_support_admin

FOUNDwp_options.siteurl → hxxps://casino-bonus.example

FOUND.htaccess: redirect for mobile visitors

INFOwp core verify-checksums · 3 files

SCANwp_posts · 2 318 rows

Example case. The site and findings are made up, but typical.

Process

How it works

Five steps. You know what's wrong and what it costs before we start cleaning.

  1. Contact

    Fill in the form and tell us what you see. We reply around the clock, every day – usually within 2 hours.

  2. Inspection

    We look at the site as it is now: files, database and users. Nothing is changed.

    Malware scan1 finding
    PHP backdoor: eval(base64_decode)example.com/wp-content/uploads/2024/03/cache.php
  3. Quote

    If we're confident it can be fixed within the included hours, you get a starting price. You approve before we start.

  4. Cleanup

    We remove backdoors and injected code, replace modified core files, clean the database and close fake accounts.

    diff .htaccess−2
    - RewriteCond %{HTTP_USER_AGENT} (android|iphone|mobile) [NC]- RewriteRule ^(.*)$ hxxps://casino-bonus.example/ [R=302,L]  # BEGIN WordPress  RewriteEngine On
  5. Report + recommendations

    You get a report on what we found, how the break-in most likely happened and what to do next.

Get help now

Services

Three levels, depending on how deep the break-in goes

Level 1

Files only

For when the break-in is in the site's files. We remove malicious code and hidden backdoors and replace modified WordPress files with clean originals.

  • wp-config.php
  • wp-includes/*.php
  • wp-content/uploads/*.php

From€229€286 incl. VATincl. 2 h

Choose this package: Files only

Level 2

Files + database

Everything in Files only, plus the database. We remove scripts planted in posts and pages, unknown admin accounts and changed settings that send visitors to other sites.

  • wp_posts · <script>
  • wp_users · wp_support_admin
  • wp_options · siteurl, home

From€365€456 incl. VATincl. 3 h

Choose this package: Files + database

Level 3

Files, database + hardening

Everything in Files + database, plus hardening. We update everything, replace the site's security keys, tighten who can change files and advise on a firewall and two-step login. Afterwards we monitor the site for 30 days.

  • AUTH_KEY … NONCE_SALT
  • chmod 644 / 755
  • 30 days of monitoring

From€595€744 incl. VATincl. 5 h

Choose this package: Files, database + hardening

Each hour beyond what's included: €72/h (€90 incl. VAT)

Prices exclude VAT. Individuals pay the price incl. VAT.

Pricing

How the price is set

You pay for time, and you know roughly how much before we start. If we need more time than included, we tell you first.

  1. You contact us.

  2. We look at the situation.

  3. If we're confident it can be fixed within the included hours, you get a starting price.

  4. Each extra hour costs €72/h. We ask before going over.

  5. You approve before we start.

Can't be saved?Then you only pay for the inspection: €72 excl. VAT

No subscriptionsYou pay per case. Monitoring is only part of level 3.

Get help now

Contact

Get help now

The more you tell us, the faster we can start. If you don't know an answer, skip it.

24/7

Every day, weekends included. We usually reply within 2 hours.

hjalp@sajtjouren.com

Don't send passwords here. We'll arrange access securely when we get in touch.

What are you seeing?
How urgent is it? (optional)
More details (optional)
What access do you have? (optional)

Not sure? Leave it blank and we'll figure it out together.

SSH (command-line access to the server)
Your hosting account panel (where you manage files and the database)
Which package do you want?

Required to send.

Sending the request is free.

Questions

Common questions

Who is behind it?

Sajtjouren is run by Eric Sjöberg, a platform engineer and consultant. Day to day he works with web hosting and server operations: Linux servers, automation, email, DNS and SSL. He also builds backend services and internal tools, and troubleshoots production problems across the whole chain, from the server to the application.

How soon do you start?

The same day you approve the price, usually within a few hours. Any day of the week, weekends included.

Do you work evenings and weekends?

Yes. We reply around the clock, every day – usually within 2 hours.

What about passwords?

Never put passwords in the form. We'll arrange access securely when we get in touch. If you don't know how to log in to your hosting account, we'll guide you.

Will the site be down while you work?

Usually not. We always take a backup first and may put the site in maintenance mode for a short while as we clean it.

What if the site gets hacked again?

No one can promise it never happens again. The hardening in level 3 lowers the risk, and we then monitor the site for 30 days afterwards. A new break-in is handled as a new case.

Could something stop working?

It can happen. Infected plugins or themes may need to be removed or replaced. We always tell you what we did.

When do I pay?

You get an invoice once the site has been cleaned and we've verified the result. Payment is due within 10 days.

What should I do while I wait?

Don't delete anything, not even files or accounts that look suspicious. Note down what you've seen and when. If you think your email has been affected, change its password.