Services

Website Security

Hacked sites cleaned fast, then protected so it doesn't happen again. We built our own WordPress security plugin, Guardian Shield Lite, from the attacks we have investigated and cleaned up, and it runs on the sites we look after.

Book a free call See the services Fixed quote after a free call

When this is for you

  • Your site redirects visitors to spam, or Google shows a warning in front of it.
  • Admin accounts you did not create keep coming back after you delete them.
  • Your host suspended the account for malware and you do not know where it is.
  • You cleaned it once already, and it came back.

What Website Security covers

Hacked sites cleaned fast, then protected so it doesn't happen again.

  • WordPress malware removal

    Infection removed, site restored

    The infection removed from files and database, rogue accounts and hidden plugins taken out, the site restored and checked, with evidence kept before anything is deleted.

    More about WordPress malware removal
  • Incident investigation and recovery

    Find how it happened and recover

    What happened, how the attacker got in and what they could still use, found and closed: stolen passwords, application passwords, API keys, scheduled tasks and vulnerable plugins.

    More about incident investigation and recovery
  • Website security hardening

    Close the gaps attackers use

    The gaps attackers use, closed: outdated software, weak logins, unsafe file permissions, exposed admin tools, and code that can be changed from the dashboard.

    More about website security hardening
  • Monitoring and ongoing protection

    Threats caught early

    Continuous checks for new code, changed files, new administrators and known malware, with alerts sent to a person who can act on them. On the sites we manage this runs through Guardian Shield Lite.

    More about monitoring and ongoing protection
  • Security assessments within an explicitly authorized scope

    Clear review with your written approval

    A structured review of your site's security, done only with your written approval and within an agreed scope, with findings in plain words and fixes in order of importance.

    More about security assessments within an explicitly authorized scope

Who leads this work, and how we keep it to systems we own or are authorized to protect: Security at Codiffy.

Who it helps

  • Owners of a hacked site

    The infection removed, the way in closed and the site back in search.

  • Stores that handle payments

    Hardening and monitoring so an attack is caught before customers see it.

  • Agencies

    White-label cleanups and ongoing protection for your clients' sites.

Why cleanups fail

A malware scanner can delete the files it recognizes, but modern attacks leave more behind: administrator accounts hidden from the Users screen, plugins that remove themselves from the Plugins list, small scripts injected into theme files or the database, and scheduled tasks that put the malware back overnight. If the way in stays open, the site is reinfected within days.

That is why every cleanup we do ends with finding the entry point and closing it, and with passwords, keys and application passwords rotated, not only files removed.

For a worked example, read our BenchmarkTitle.net case study: a hidden SEO spam infection that no scanner reported, cleaned out of the page content and database, with the entry point found and closed.

Built from real incidents

Guardian Shield Lite, our WordPress security plugin, was built from the attacks we investigated: hidden admin accounts, fake plugins, fake browser checks that trick visitors into running commands, and credential stealers. It blocks new code from running until it is approved, removes known malware only after keeping evidence, and reports every site we manage to one central hub. Read more about Guardian Shield Lite.

Security assessments, with written permission

We review sites only with the written approval of the owner and within an agreed scope, and we tell you what we found in plain words, with the fixes in order of importance.

How it works

  1. Contain

    We stop the damage first: block the malicious code from running and protect visitors.

    From you: Access to the site, hosting and, if possible, the DNS.
  2. Keep the evidence

    Before anything is deleted, a copy of each malicious file and database entry is kept, so we can show what happened and nothing is lost by mistake.

  3. Clean

    Malware, rogue accounts, injected scripts and hidden plugins are removed, and core files are checked against the official versions.

  4. Find the way in

    We look for how the attacker got in and what they can still use: old plugins, stolen passwords, application passwords, API keys, scheduled tasks.

    From you: Hosting access logs, if your host provides them.
  5. Protect

    Passwords and keys are rotated, the site is hardened and monitoring is switched on, so a repeat attempt is caught early.

    From you: Help rotating passwords only you control.

What affects the price

Every project gets a fixed quote after a free call, so you know the total before anything starts. These are the things that move it.

  • How widespread the infection is
  • How many sites share the hosting account
  • Whether the site is blacklisted
  • Ongoing monitoring or a one-off cleanup

Where we have done this

WordPress security plugin

Guardian Shield Lite

Our WordPress security plugin: code stays locked, known malware is removed with evidence kept, and every site reports to one hub.

  • Code locked, changes in recorded windows
  • Known malware removed, evidence kept
  • Every site watched from one hub

Questions about Website Security.

My site is hacked right now. What should I do first?

Change your hosting and WordPress passwords from a clean device, then contact us and mark it urgent, or call either office. Avoid deleting files yourself before a copy is kept: you may remove the evidence of how the attacker got in.

Will I lose my content or orders?

We work to avoid it. Evidence and backups are kept before anything is removed, and we clean the infection out of your content rather than rolling the whole site back.

Will Google remove the warning from my site?

Once the site is clean we request a review in Google Search Console. Google makes the decision and sets the timing, but a clean site with the entry point closed is what it looks for.

Do you clean sites for agencies?

Yes, white-label if you prefer. We report to you, and you stay the contact for your client.

Tell us your goal. We'll show you the plan.

Book a free 30-minute call. You'll leave with a clear plan and a fixed quote, whether you hire us or not.

Book my free call
Free call, no obligationBook my call