Your Client's Site Is Hacked Right Now — And They Don't Even Know It
WordPress powers 43% of the web — and suffers 90% of all CMS hacks. The average site owner discovers the breach days or weeks later, when Google blacklists them or customers report the defacement. By then, malware has spread, SEO rankings have tanked, and customer data is gone. SiteRescue finds it, cleans it, and restores it — in one click, before the damage compounds.
The Clock Is Ticking — And Every Hour Costs Real Money
When a WordPress site gets hacked, every passing hour makes it worse. Malware spreads deeper. Backlinks get poisoned. Google crawls the infected pages. By the time a human gets to it, the cleanup is 10x harder than it needed to be.
The Discovery Gap Is Killing Revenue
Most site owners discover they've been hacked when a customer emails them — or when they Google their own business and see "This site may be hacked." That's 6 to 72 hours after the breach. E-commerce sites lose £200–£800 per hour of downtime. A 48-hour gap = £9,600–£38,400 in lost sales. And the owner didn't even know.
Manual Cleanup Is a Nightmare
Cleaning a hacked WordPress site manually means: diffing every file against originals, scanning the database for injected scripts, checking wp-content/uploads for backdoors, reviewing .htaccess for redirects, and manually removing malware that's often buried 4–5 directories deep. A skilled dev takes 4–8 hours. At £75/hr, that's £300–£600 per site — eating your entire retainer for the month.
SEO Damage Is Often Permanent
Hackers inject pharmaceutical spam, Japanese keyword pages, and redirect scripts into your client's site. Google indexes these within hours. Once blacklisted, recovery takes 1–4 weeks. And here's the kicker: 72% of hacked sites never fully recover their original rankings. The business loses the traffic they spent years building — because of one breach they didn't cause.
Re-infection Is the Silent Killer
Here's the dirty secret of manual cleanup: you remove the visible malware, but miss the backdoor. Two weeks later, the site is hacked again. The client thinks you didn't fix it properly. They cancel. You lose a £300/mo retainer over a single overlooked PHP file in /wp-content/uploads/2023/03/. Backdoors survive manual cleanup 23% of the time. That's a 1-in-4 chance of losing the client — after you already did the work.
SiteRescue — One Click. Full Scan. Complete Recovery.
SiteRescue connects to any WordPress site, runs a forensic-grade malware scan across every file and database table, removes all infections, closes the backdoor, and restores the site to clean state. No manual diffing. No shell access required. No missed backdoors.
Connect
Paste the site URL and an admin login. SiteRescue connects via WordPress REST API — no FTP, no cPanel, no shell access needed.
Scan
Deep scan across 14 malware signatures: obfuscated PHP, base64 injections, database spam, backdoor shells, redirect scripts, cryptominers, and pharma SEO pages.
Clean
All infected files are quarantined and replaced with clean originals. Database injections are rolled back. Backdoors are closed. wp-admin users are audited and rogue accounts removed.
Restore
Google Search Console is pinged for re-indexing. Security plugins are hardened. A recovery report is generated for the client. Total time: under 15 minutes.
What SiteRescue Actually Does
This isn't a scan-and-pray plugin. It's a complete automated recovery pipeline — the same process a £150/hr security consultant would follow, executed in minutes by AI.
🔍 14-Signature Malware Detection
Scans every PHP, JS, and HTML file against known malware patterns — obfuscated eval(), base64_decode injections, webshells (WSO, c99, r57), pharma spam keywords, hidden iframes, cryptomining scripts, and redirect chains. Catches what Wordfence and Sucuri miss because they rely on signature databases that are always 24 hours behind.
Detection🗃️ Database Sanitisation
Scans every wp_posts, wp_options, wp_usermeta row for injected scripts, hidden admin users, rogue plugin activations, and SEO spam links. Rolls back to clean state using known-good WordPress schema. No manual SQL queries. No risk of breaking serialised data.
Core🔐 Backdoor Elimination
The #1 reason hacked sites get re-infected: the backdoor survives. SiteRescue identifies and removes: unauthorised admin users, modified plugin files, hidden wp-cron jobs, rogue .htaccess redirects, and uploaded PHP shells disguised as images. Then it hardens login — enforcing 2FA, limiting XML-RPC, and blocking the attacker's IP range.
Critical🔄 One-Click Core + Plugin Restore
Replaces every WordPress core file, plugin, and theme with clean originals from the WordPress.org repository. Modified files are flagged in the report so you know exactly what changed. Custom themes and child themes are preserved — only known-good sources are used for replacement.
Restore📊 Client-Facing Recovery Report
Auto-generates a branded PDF report for your client: what was infected, what was removed, what was restored, and what security measures are now in place. Turns a panic call into a trust-building moment. Shows you earned your retainer — with receipts.
Trust🔔 Google Re-indexing + Blacklist Removal
Automatically submits a reconsideration request to Google Search Console and forces a re-crawl of the cleaned pages. Monitors Google Safe Browsing status until the blacklist warning is removed. Gets the business back in search results — fast.
RecoveryThe Numbers
Hack recovery is the highest-margin service in WordPress. Clients don't negotiate when their site is down. They pay whatever it takes.
| Item | Per Incident | Monthly Retainer | Notes |
|---|---|---|---|
| SiteRescue One-Time Cleanup | £79 | — | Full scan, clean, restore, report. One site. |
| Emergency Same-Hour Response | £199 | — | Priority queue, 60-min SLA. For e-commerce. |
| SiteRescue Protect (monitoring) | — | £19/mo per site | Daily scans, instant alerts, auto-clean on detection |
| Agency White-Label | — | £299/mo | Up to 50 sites. Branded reports, bulk dashboard. |
| Revenue at 30 agency sites | — | £570/mo | Pure margin — automated service, zero labour |
How Most Freelancers Handle a Hacked Site vs. SiteRescue
🕳️ The Manual Panic
- Client calls in panic at 8pm on a Friday
- Spend 1 hour just finding the infection source
- Manually diff files against originals (4+ hours)
- SQL queries to find injected database rows
- Miss 1 backdoor in 4 — site gets hacked again
- Client cancels retainer because "it happened again"
⚡ SiteRescue
- Client logs in, clicks "Scan" — results in 90 seconds
- 14-signature engine finds everything — no guesswork
- Full file + database clean in under 15 minutes
- Backdoor elimination with verified closure report
- Branded client report proves the work was done right
- Client upgrades to monitoring because they trust you
Pricing
Pay per rescue, or protect everything proactively. One price. No surprises.
One-Time Rescue
Full malware scan, clean, backdoor removal, core restore, and recovery report. One site. Pay when you need it.
SiteRescue Protect
Daily scans, instant WhatsApp alerts, auto-clean on detection. The site gets cleaned before the client even knows it was hit.
Agency White-Label
Up to 50 sites. Branded reports, bulk dashboard, priority queue, API access. Resell at your own price — we never reveal ourselves.
Common Questions
What if the site is completely down — I can't even log in?
SiteRescue can work via FTP/SFTP or cPanel file manager as a fallback when the WordPress admin is inaccessible. If the database is intact, we can restore WordPress core from a known-good copy and regain admin access. If everything is gone — we guide you through a backup restoration with the recovery report so you know exactly what to harden before going live again.
Does this replace a security plugin like Wordfence?
No — SiteRescue is recovery, not prevention (unless you're on Protect). Wordfence and Sucuri try to stop attacks before they land. SiteRescue cleans up after they've already landed. They're complementary. We recommend running both: Wordfence for the firewall, SiteRescue for the moment the firewall fails.
How do I know you won't make things worse?
SiteRescue never deletes anything. Every infected file is quarantined — moved to an isolated directory where you can review it before permanent deletion. Every database change is logged. Core files are replaced from wordpress.org originals — the same files you'd get from a fresh install. Custom themes and child themes are never overwritten. If something looks wrong, there's a one-click rollback.
Can this handle WooCommerce / e-commerce sites?
Yes — and they're our highest-priority customers. WooCommerce sites lose real money per hour of downtime. SiteRescue handles WooCommerce order tables, product data, and customer records with extra care. No order data is ever modified. The scan excludes wp_woocommerce_* tables from automatic changes — they're flagged for manual review only.
What's the difference between this and paying a security consultant £150/hr?
Speed, cost, and consistency. A consultant takes 4–8 hours and charges £600–£1,200. SiteRescue takes 15 minutes and costs £79. The consultant might be having a bad day and miss a backdoor. SiteRescue runs the same 14-signature scan every time — it doesn't get tired, doesn't skip steps, and doesn't charge overtime for weekend emergencies.
Every Hour a Hacked Site Sits Unfixed Is an Hour of Revenue Gone. And Rankings That May Never Come Back.
Your clients trust you to handle this. Don't spend your weekend diffing PHP files at 2am. SiteRescue does the scan, the clean, the backdoor hunt, and the recovery report — while you get back to building the business.
Rescue a Site Now — £79 →