Sitesetu

Website security and malware removal

Sitesetu cleans hacked websites, removes malware and hardens sites so they stay secure, including WordPress sites. Ongoing security is part of the ₹40,000$799 a year large website maintenance plan. A one-off clean-up of an infected site is quoted after we inspect it.

Signs your website has been hacked

  • Google shows "This site may be hacked" or a red warning screen
  • Visitors are redirected to spam, gambling or pharmacy sites
  • Strange pages in a language you do not use appear in Google results
  • Your host suspends the account for malware or spam
  • New admin users or files you did not create
  • Emails from your domain land in spam or bounce

What a malware clean-up includes

  1. Backup of the infected site for evidence and rollback.
  2. Scan of files and database for malicious code, backdoors and injected spam.
  3. Removal of infected files and code, and replacement of core files with clean copies.
  4. Closing the hole. Updating the outdated plugin, theme or software that let the attacker in, and removing unused ones.
  5. Resetting access. New passwords for hosting, database, admin users and FTP, and removal of unknown users.
  6. Delisting. Requesting a review in Google Search Console once the site is clean, so warnings are removed.
  7. Report of what was found, what was fixed and what to watch.

Hardening so it does not happen again

  • Software, theme and plugins kept up to date
  • Strong passwords and two-factor login for admins
  • Login attempt limits and admin area protection
  • File permissions tightened and file editing from the dashboard disabled
  • A web application firewall where your host offers one
  • SSL certificate and HTTPS everywhere
  • Daily backups stored off the server
  • Uptime and file change monitoring

WordPress security

Most hacked small business sites run WordPress with outdated or abandoned plugins. We audit every plugin and theme, remove what is not needed, replace risky ones and set up automatic security updates. If the site has been hacked repeatedly, a rebuild on a lean custom site is often the more secure and cheaper long-term option. See website redesign.

Security checks we do not do

We do not offer formal penetration testing or compliance audits such as PCI DSS or ISO 27001. For those, use a specialist security firm; we are happy to fix the issues they report.

Maintenance plans
PlanPer year
Small website planFor Starter and Business websites. 1 edit per month, backups, uptime and form checks, software updates.₹10,000$199
Large website planFor Growth and Pro websites. 1 edit per week, backups, uptime and form checks, software and security updates, application bug fixes.₹40,000$799

Questions about this service

How much does malware removal cost?

We inspect the infected site first and then give a fixed quote, because the effort depends on how deep the infection goes. Ongoing security is included in the ₹40,000$799 a year large website maintenance plan.

Can you remove a Google 'This site may be hacked' warning?

Yes. After cleaning the site and closing the vulnerability, we request a review in Google Search Console. Google usually reviews within a few days.

Do you secure WordPress websites?

Yes. We audit plugins and themes, update or remove risky ones, add login protection, tighten permissions and set up backups and monitoring.

Do you offer penetration testing?

No. We do not provide formal penetration testing or compliance audits, but we can fix issues reported by a specialist security firm.

Tell us what you need. We reply with a fixed quote.

Call or WhatsApp +91 79066 77087, or write to info@sitesetu.com.