Hacked? We clean it and lock the door.

A public plugin hole gets used within hours. We clean the damage, close the way in, and watch the site after.

Two engineers reviewing a site together at a laptop
Hacked right now?Say so in the form. It goes to the top.
WordPressWooCommerceShopifyElementorWixSquarespacePHPLaravelNode.jsNext.jsReactTypeScriptTailwindPostgreSQLMariaDBRedisDockerAstroVercelWordPressWooCommerceShopifyElementorWixSquarespacePHPLaravelNode.jsNext.jsReactTypeScriptTailwindPostgreSQLMariaDBRedisDockerAstroVercel

What a security job covers

Malware removalEvery infected file cleaned, backdoors and spam pages gone.
PatchingYour plugins checked against the live hole list, and fixed.
FirewallBad traffic stopped before it reaches your site.
Login lockdownTwo-factor, login limits, file editing switched off.
Blacklist removalThe Google warning and host suspension lifted.
Backups and watchDaily backups, and 30 days of watching after.

Cleaned is not the same as closed

Delete the malware and leave the door open, and it is back in two weeks.

The usual

  • Malware deleted, door left open
  • Same hack a fortnight later
  • Nobody knows how they got in
  • Old passwords still working

With Norval

  • The way in found and closed
  • Every password changed
  • Hardened, then watched 30 days
  • A plain note of what changed

The rescue, step by step

  1. First hourContain itTake a snapshot before anything changes.
  2. Same dayClean itRestore files from known-good copies.
  3. Same dayClose the holeFind the real way in, and shut it.
  4. 30 daysWatch itHarden, change passwords, keep watching.

What you are left with

  • A clean site, off every blacklist
  • The way in named and closed
  • A short report of what changed
A developer checking code on a laptop

Not sure how exposed you are?

The free scan shows open holes, missing protection and an expiring certificate in about ten seconds.

Questions

How fast can you start on a hacked site?

We reply the same business day, and urgent requests go first.

Will you find how they got in?

Yes. Cleaning without closing the way in means the hack comes back, so finding it is part of the job.

Can you remove the Google warning?

Once the site is clean we ask Google for a review in Search Console. Google decides how long that takes, usually days.

Do I still need a security plugin afterwards?

A firewall and login protection are part of hardening. Which tools depends on your site and host.

Will my site be offline during the clean-up?

Only if it is harming visitors, for example redirecting them to scams. Then we take it offline briefly while we work.

Hacked right now? Tell us.