What WordPress malware removal costs: how it is priced and what a cleanup should include
A WordPress malware cleanup is priced by how it is sold (a fixed fee, an hourly rate or a subscription) and by what counts as clean. Compare quotes on scope. Check that the way in is found and closed, and that a review request, a written report and a guarantee are included.
- By
- WP Ministry
- Published
In short
- Compare quotes by what they cover, not by the amount. A complete cleanup has nine parts, listed below.
- Ask whether the quote covers finding and closing the way in. Removing what is visible is a smaller job, and it is the one that gets paid for twice.
- Count the sites in the hosting account. A quote for one leaves the others as they are.
- Ask your host what it covers before you pay anyone. Some hosts include a cleanup, and others leave the site's software to you.
- Nobody you hire controls how long Google's review takes, and nobody can promise the site will never be attacked again.
- A backup from before the break-in, and notes of what you saw and when, shorten the work.
What a WordPress malware cleanup costs depends on two things: how it is sold, and what the seller takes "clean" to mean. It is sold as a one-time fixed fee, by the hour, or as part of a security subscription paid by the month or the year. The cheapest quote is often the one that removes the visible symptom and leaves the way in open, and that site gets paid for twice.
This page gives no going rate, because a going rate would not tell you what a quote includes, and that is where quotes differ. It sets out how the work is sold, what a complete cleanup contains, what makes one site more work than another, and the questions to send to anyone who quotes. It names no company and ranks nobody.
The ways a cleanup is sold
| How it is sold | What you pay for | What to confirm | The risk |
|---|---|---|---|
| One-time fixed price | One cleanup of one site, for an amount agreed before the work starts | The scope, in writing, and what happens if the infection turns out wider than expected | The amount is fixed, and the scope may be narrow. A price for removing what a scanner finds is not a price for finding the way in. |
| Hourly rate | The time the work takes, whatever it turns up | An estimate, a ceiling that cannot be passed without your say, and whether looking for the way in is part of the hours | Nobody knows the total until the end. How deep the infection goes is your risk, not the seller's. |
| Subscription that includes cleanup | A term of cover, by the month or the year, with cleanup as one part beside scanning or a firewall | Whether a site that is already infected is accepted, how many cleanups the term allows, and what the plan renews at | You pay for the whole term whether or not the site is infected again. The scope of the cleanup is whatever the plan's terms say. |
| Do it yourself | Your own time, and any tools you buy | That you can do it. Google's guidance says the work takes the ability to read code and to use command-line server tools. | A backdoor you miss. Google's guidance describes back doors left behind to let the attacker in again, or to put back the code you removed. |
Your hosting company is a fifth possibility, and the first one to check. Hosts differ. One managed host's documentation says that if a WordPress site is hacked while hosted there, it will work with the customer for free to try to undo the damage, on conditions. Another host's says the customer is responsible for the site's software, and that the host may assist but is not obligated to. Ask yours which it is, in writing, before you pay anyone.
What a complete cleanup includes
These nine parts come from WordPress's documentation for hacked sites and Google's guide to recovering one. Hold each quote against the list.
- A copy of the site as it is, taken first. WordPress's documentation recommends one more snapshot before cleaning, infected or not, so that there is a copy to go back to if the cleanup fails. Google's guidance says the same, and says to label the copy as infected.
- Finding and removing the malicious files and database content. Google's guidance lists where it can sit: server configuration files such as
.htaccess, code injected into pages, and records in the database, which it says to investigate record by record. A quote should say whether the database is covered. - Finding how the attacker got in. WordPress's documentation calls this forensics: understanding the route the attacker used, so that it cannot be used again. Google recommends looking for further holes after the first is found, because there may be several independent hacks in place.
- Closing it. That means fixing what was found, whether an out-of-date plugin, a stolen password or file permissions left too loose.
- Replacing every credential and the secret keys. WordPress's documentation counts every access point: FTP or SFTP, the dashboard, the hosting control panel and the database, for every user. New secret keys in
wp-config.phpforce off anyone who is still logged in. WordPress and Google both say to change the passwords again once the site is clean. - Updating. WordPress's documentation says to update once the site is clean, because older versions are more prone to hacks. Google's guidance asks for a clean installation and not only an upgrade, since an upgrade can leave files from the previous version.
- Requesting removal from blocklists and a review by Google. A warning does not lift by itself. In Search Console's Security issues report, someone selects "Request Review" and describes what was fixed. Google lists a corrected vulnerability among the things to have done before asking. WordPress's documentation adds that Bing and desktop antivirus products keep lists of their own.
- A written report of what was found. It should say what was infected, how the attacker got in, what was changed and what is left for you to do. Google says a good review request explains the issue, describes the steps taken to fix it and documents the outcome, so the report is also the material for that request and for your host.
- A guarantee period if it comes back. Google's guidance warns that if an infected file remains on the server, the site is more likely to be hacked again. A guarantee says who pays when that happens. Look for a stated length and stated conditions.
A quote that covers only the second part is a quote for removing the symptom. The third and fourth parts are what stop you paying twice. They are also the hardest: WordPress's documentation says the analysis is often very difficult for a site owner, for lack of technical knowledge or of available data.
What moves the price
| What differs | Why it changes the work |
|---|---|
| The number of sites in the hosting account | WordPress's documentation says a hack may have affected more than just your site, especially on shared hosting. Every site in the account has to be checked, and the work is counted per site. |
| The size of the site and its database | There are more files to compare and more records to read. WordPress itself can be replaced with fresh copies. Code with no clean original, such as a custom theme, has to be read by hand. |
| Whether it is a store, or holds customer data | A store takes orders while the work goes on, so going back to an older backup loses what arrived since. WooCommerce's documentation says the card industry's rules still apply to a store that sends payment to an outside gateway, because the site serves the checkout page. Personal data also raises the legal question further down. |
| Whether a clean backup exists | Google's guidance splits the work three ways: a clean and current backup, a clean but outdated one, or none. With the first, the job is a restore, then updates, the fix for the way in and new passwords. With none, the files and the database are cleaned by hand. The backup has to date from before the break-in. |
| Whether the host has suspended the account | A host can suspend an account it finds compromised. Ask the host what it needs to see before it lifts the suspension, and pass that on with its message. |
| Whether Google is warning visitors | It adds the review request, and ownership of the site has to be verified in Search Console first. Google says a malware review takes a few days and a review of a site hacked with spam can take up to several weeks. The wait is Google's, and no payment shortens it. |
| How fast you need it | Work started at once, or outside working hours, may be quoted higher. Ask when work would start at the ordinary price. |
Questions to put to anyone quoting
Send these as they are. The written answers are the scope.
- Which of these are in the price: a copy taken before any change, cleaning the files, cleaning the database, finding how the attacker got in, closing it, new passwords and secret keys, updates, the review request, a written report?
- Is the price fixed? What would change it, and would you ask me first?
- Does it cover every site in my hosting account, or one?
- Do you look for the way in? What do you do if you cannot find it?
- Do you send the review request to Google, and to any other list the site is on? What happens if the review is refused?
- Is there a guarantee if the infection returns? For how long, on what conditions, and does it mean a second cleanup or a refund?
- Does a person read the site, or does a scanner do the work?
- What will the report contain?
- What access do you need, and what do you do with it when the work is done?
- What do I have to do afterward to keep the guarantee?
Three things help in reading the answers.
Access. A cleaner needs the access points WordPress's documentation lists: SFTP, the dashboard, the hosting control panel and the database. Where your host allows it, make separate logins for the job and keep your own. When the work is done, delete them and change every password that was shared.
Promises. WordPress's hardening guide describes security as "risk reduction, not risk elimination". A promise that the site will never be hacked again is one nobody can keep. Nor can anyone promise when Google's warning will go, because Google reviews the site and decides.
Scanners. WordPress's documentation says of scanners that no one solution is the best approach, so "the scan is clean" says less than "the site is clean". After any cleanup, you can run the checks in how to check whether your WordPress site has been hacked yourself.
What it costs to do nothing, or to do it yourself
Doing nothing has costs that no quote shows.
- The warning stays. Google can label the site's results, leave them out, or add its pages to the Safe Browsing list, which most major browsers use to warn a visitor before a page opens. Google says the warnings remain until a review finds the site clean.
- Inquiries and sales stop arriving. A visitor who meets a warning page goes elsewhere. The downtime cost calculator works out what an outage costs in sales not made, from your own revenue and the hours involved. Count the hours behind a warning as hours down, and hold each quote against the result.
- Visitors are put at risk. Google's overview of hacked sites gives the example of harmful code that records keystrokes on visitors' computers.
- Your email can suffer. WordPress's documentation notes that when a site is abused to send spam, the server's address can be put on email blacklists, and that address is often shared with the server that sends your mail.
- The law may apply. If the site holds personal data, some laws require telling a regulator or the people affected about a breach. The GDPR's Article 33, where it applies, requires a breach to be reported to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to put people's rights and freedoms at risk. The US Federal Trade Commission notes that every state has a breach notification law. This is not legal advice, so ask counsel which rules apply to you.
Doing it yourself costs no fee and a good deal of time. It is a reasonable choice when you have a backup from before the break-in, the site runs no custom code and it holds no customer data. The runbook for the first hour has what to do before any cleaning, and how to remove malware from a hacked WordPress site has the cleaning. Count your hours at what they are worth to the business, and count the days the site stays flagged while you learn. WordPress's documentation points anyone short of money to the Hacked and Malware forums on WordPress.org as a place to start. If the infection returns after your own cleanup, something was missed, and that is the point to pay for help.
How to keep the cost down
- Confirm it is a break-in. WordPress's documentation notes that your host may be able to say whether you are looking at a hack or a loss of service. The hacked-site check reads a site from outside and reports signs, not a verdict.
- Ask your host first. Ask what it covers, which files it flagged and when, and for the access logs.
- Hand over what you know. WordPress's documentation says to write down what you see, when you noticed it and what changed on the site recently, and that the record will prove invaluable whether you do the work yourself or engage a professional. Send it with the host's report, so nobody is paid to find out what you already know.
- Leave the evidence alone. Do not delete files or reset the site before a copy exists. One host's documentation asks customers not to, because a reset removes the evidence needed to investigate and does not necessarily remove the underlying vulnerability.
- Have a backup from before the break-in, and know that it restores. Google's guidance says to check first that the backup was created before the site was hacked. WordPress's documentation says a full restore needs both the database and the files, and recommends keeping at least three backups in different places. How to schedule automatic WordPress backups covers setting that up.
- Act early. Google notes that knowing when the hack first took place helps determine which backups might still be clean. Backups and logs are not kept forever, so every week of delay leaves fewer clean copies and a shorter record.
- Do not ask for Google's review early. Google says requesting a review while the problem still exists only prolongs the time the site is flagged. Search Console's help adds that it can lengthen the turnaround of the next request, or get the site marked as a repeat offender.
Afterward, Google's guidance recommends regular automated backups and keeping software updated. Our WordPress security page describes that routine as a care plan, with weekly updates, security scanning and daily offsite backups, and the pricing page shows the plans beside the one-time cleanup.
What we charge
Malware removal
$99
Start with a free diagnosis
Common questions
Why do quotes for the same site differ so much?
They may not be for the same work. One quote can cover removing what a scanner finds on one site. Another can cover the database, the way in, the review request, a report and a guarantee. They are also sold differently, as a fixed fee, as hours or as a subscription term. Send every seller the same questions and compare the written answers.
Does a cleanup remove Google's warning?
Not by itself. The warning goes after Google reviews the site and finds it clean. The review is requested in Search Console's Security issues report, and Google says it takes a few days for malware and up to several weeks for a site hacked with spam. Once Google finds the site clean, it says the warnings in browsers and search results are removed within 72 hours.
Is a subscription better value than a one-time cleanup?
It depends on what else looks after the site. A subscription buys a term of cover, so it makes sense when you want the rest of the plan for that term. If the site is already maintained and you only need this infection gone, a one-time cleanup with a guarantee period is the narrower purchase. In both cases, read what the cleanup itself covers.
The malware came back after I paid. What now?
Go back to whoever cleaned the site, with the date and what you see, and ask for the guarantee. Google's guidance describes how a return happens: a back door that lets the attacker in again or puts back code that was removed, or a second, independent hack that was never found. If there was no guarantee, put the questions on this page to the next seller before you pay.
- GuideHow to remove malware from a hacked WordPress site
- GuideHow to set up two-factor authentication in WordPress
- GuideWordPress search results pages (/?s=) in Google and Search Console: what they are and what to do
- GuideHow to audit a WordPress site for security weaknesses
- GuideHow to install a free SSL certificate on WordPress and move the site to HTTPS
- GuideThe EU Cyber Resilience Act and WordPress: who it applies to and when

