If your site is showing warnings, redirecting visitors somewhere else, or has been flagged by Google, we clean it, close the way in and get the warning lifted. If it is still healthy, we harden it so it stays that way.
of ecosystem vulnerabilities were found in plugins, not core
median time from public disclosure to attacks at scale
new vulnerabilities recorded across 2025
increase on the year before
The platform is not the weak point. The number of extensions running on it usually is.
Almost never through WordPress itself. Patchstack recorded 11,334 new vulnerabilities across the WordPress ecosystem during 2025, a rise of 42 per cent on the year before, and around 91 per cent of them sat in plugins rather than the core software. Their 2026 report also found that heavily targeted flaws were being exploited at scale within a median of five hours of becoming public. That is faster than most businesses check their email.
Figures from the Patchstack State of WordPress Security report, 2026 edition.
The plugin count on a site is a better guide to its risk than the platform it runs on. A build carrying thirty plugins, several of them abandoned by their developers, is exposed in a way that no amount of good intentions fixes. Updating on the first Monday of the month is not fast enough when the gap between disclosure and attack is measured in hours.
Most owners find out from a customer rather than from a scanner. These are the signs worth acting on the same day.
Chrome or Safari showing a warning before your site loads means Google Safe Browsing has flagged it. Traffic stops almost immediately.
The site loads normally for you and redirects strangers to another site, often only on mobile. That selective behaviour is deliberate.
Search results showing listings for products or services you have nothing to do with. Usually hidden from anyone logged in.
New users with administrator rights, or your own login no longer working, both point at the same thing.
A compromised site is often used to send mail. Your domain reputation suffers before you notice anything on the site.
Someone else code running on your hosting uses your resources. A sudden slowdown with no change on your side is worth investigating.
If any of these apply, avoid logging in from a shared computer and get the site looked at before changing anything yourself.
Deleting suspicious files is the part everybody does and the part that fails. Current reporting shows attackers now writing into legitimate core, plugin and theme files rather than leaving obvious extra ones, so a scan and delete pass alone misses it. The job is finding how they got in and closing that, otherwise the same site is back in the same state within a fortnight.
Files and database are archived before anything is touched, so nothing is lost and the infection can be examined properly.
Every file compared against clean copies of core, themes and plugins, so modified files stand out rather than hiding among legitimate ones.
Access logs, file timestamps, user accounts and the plugin version history are checked to work out how and when it started.
Infected files repaired or replaced, injected database entries removed, unauthorised accounts deleted and any scheduled tasks the attacker left behind cleared.
The vulnerable component is updated or removed, passwords and keys rotated, file permissions corrected and admin access tightened.
Once the site is clean, a review is requested through Google Search Console and any host or blocklist flags are addressed.
Monitoring for two weeks after the clean, because reinfection is the clearest sign the original entry point was missed.
Cheaper than a clean up, and considerably cheaper than losing a month of enquiries. This is what we put in place.
Plugins you no longer use are removed rather than deactivated, and abandoned ones are replaced. Every plugin is a door, whether it is switched on or not.
Application level filtering, because a general server firewall was never designed to recognise an attack aimed at one plugin version.
Your installed components watched against disclosure feeds, so an urgent update is applied the day it matters rather than at the next scheduled visit.
Rate limiting, two factor authentication for administrators and no shared accounts. Weak and reused passwords remain a leading factor in compromised sites.
Stored away from the hosting, kept far enough back to predate an infection, and restored at least once so you know they work.
File permissions tightened, editing disabled from the dashboard, and old developer and staff accounts closed when people move on.
Every job here is priced on what we find, because a single infected file and a site that has been open for months are not the same clean up. Emergency work is quoted as a fixed figure per site rather than by the hour, so the bill does not grow while we work. You get the figure before we start.
Full clean, entry point identified and closed, blocklist review requested, two weeks of monitoring. Priced per site, not per hour.
Written report on plugin risk, user access, backups, hosting setup and configuration, with a fixed list of what to change and in what order.
Updates applied and tested, firewall and monitoring, offsite backups and a restore if anything goes wrong. Included in our maintenance plans.
If we look at your site and find nothing wrong, we tell you that and charge you for the audit only.
Our UK business partner is based in County Durham. Security work is done remotely wherever you are, and if you are near Durham City, Chester-le-Street or Newcastle we can sit down with you afterwards and go through what happened and how to keep it from repeating.
Most cleans are finished within 24 to 48 hours of getting access. Removing a Google warning takes longer, because the review happens on their timetable once the site is verified clean.
No. Everything is backed up before work starts, and the aim is always to repair rather than replace. Content, products and customer records stay intact.
Sometimes, but only if you can be sure the backup predates the infection and the way in has been closed. Restoring onto the same vulnerability puts you straight back where you started, often within days.
Updating helps and it is not a complete answer. Some flaws are attacked before a fix exists, and 2026 has seen cases where legitimate plugins were hijacked and pushed malicious updates to sites that were following the advice correctly.
It is one layer. Plugins help with firewalling, login protection and detection, but they do not remove abandoned components, fix weak passwords or test your backups. Those are decisions, not settings.
It can. Infections spread between sites on the same account, so if you run several sites in one place, all of them need checking, not just the one showing symptoms.
Once the site is verifiably clean, a review is requested through Search Console. Requesting it too early gets the site flagged again and slows everything down.
Usually, provided the site is cleaned properly and the warning lifted quickly. The longer a flagged site stays live, the more ground there is to make up.
Yes. Most security work we take on is for sites built by somebody else, often years ago, and often by a developer who is no longer contactable.
Take the site offline or into maintenance mode if it is redirecting people, change your hosting and administrator passwords from a device you trust, and get in touch. Do not delete files at random, because that removes the evidence needed to find the cause.
Send us the address and tell us what you are seeing. We will confirm whether it is infected, what it will take to clean, and what the fixed cost is before any work starts.