Visible malware is not the whole incident
Injected spam, redirects or defaced pages may be the symptom. The attacker can persist through hidden files, modified plugins, rogue admin users, scheduled tasks or database payloads.
WORDPRESS SECURITY / PERTH, WA
WordPress security for sites that need prevention, malware recovery or a stronger recovery plan. We separate containment, evidence, clean-up, access control and hardening so a compromised site is not simply 'cleaned' and returned with the original entry point still open.
snapshot before destructive cleanupscan files + database + admin accountsremove persistence / patch entry pointverify -> harden -> monitor SECURITY IS A RECOVERY SYSTEM, NOT A SINGLE PLUGIN
A secure WordPress site depends on several layers working together: patched software, controlled accounts, clean backups, sensible server configuration, login protection and a known recovery path. If the site is already compromised, containment and root-cause work come before cosmetic cleanup.
Injected spam, redirects or defaced pages may be the symptom. The attacker can persist through hidden files, modified plugins, rogue admin users, scheduled tasks or database payloads.
Old administrator accounts, shared passwords and unnecessary privileges create risk even when the codebase is current. We review who can access WordPress and how that access is protected.
A backup stored only on the same compromised hosting account can disappear with the incident. Recovery planning includes a clean restore point and off-site strategy where possible.
We document what was found, what was changed and which risks remain. That gives your team or future developer a starting point instead of repeating the same investigation after the next incident.
FIND THE RISK BEFORE PRESCRIBING THE CONTROL
The audit looks at the WordPress application, accounts, dependencies and hosting-facing controls so the hardening work is based on the actual attack surface.
Review administrator accounts, stale users, privilege levels, password-reset paths and whether stronger authentication is practical for the people who maintain the site.
Inventory versions, unsupported components, abandoned plugins and custom code that can no longer receive vendor security fixes.
Compare WordPress core files where practical, scan for suspicious PHP / JavaScript patterns and inspect the database for injected content or unexpected administrator records.
Check obvious hosting-level weaknesses, PHP/runtime age, SSL behaviour, file permissions and whether firewall or WAF controls are available in the current environment.
CLEAN-UP WITHOUT ROOT CAUSE IS JUST A PAUSE
A compromised site is handled as an incident: preserve a snapshot, contain obvious abuse, identify persistence, replace unsafe components, patch the entry path and verify the cleaned build before declaring recovery.
HARDENING SHOULD ADD LAYERS, NOT JUST ONE WALL
Hardening reduces the number of easy paths into WordPress and limits what a compromised account or vulnerable component can do. Controls are selected to fit the hosting stack and editorial workflow.
Protect privileged accounts and reduce the damage from reused or phished passwords.
Use hosting or edge firewall controls where available to block common exploit and bot traffic before WordPress handles it.
Keep supported software patched and remove abandoned components that no longer receive security fixes.
Give users only the capabilities they need and remove stale administrator access.
Maintain backups that remain usable when the live hosting account is the thing that has failed or been compromised.
Keep enough visibility to spot recurring login abuse, unexpected changes or re-infection signals after recovery.
PATCH THE SOFTWARE YOU DEPEND ON
A WordPress site can be fully updated and still carry risk if a plugin is abandoned, a premium extension no longer receives updates or custom code depends on an obsolete PHP version. We review lifecycle and support status, not just whether an update button exists.
A STOLEN PASSWORD SHOULD NOT EQUAL TOTAL CONTROL
Access controls are tuned to the site rather than blindly locking down features the business still needs. The goal is to make automated abuse harder, privileged access stronger and recovery from a stolen credential faster.
Security and recovery work can be delivered remotely across Perth metro. We commonly scope different risks for professional firms in West Perth and Subiaco, commercial businesses around Osborne Park, service businesses in Joondalup and Wanneroo, hospitality around Fremantle and ecommerce / local retail in Cannington and Rockingham.
Enable stronger authentication for privileged accounts where the site's workflow and hosting stack support it.
Reduce automated credential stuffing and brute-force attempts without making normal customer or editor logins unusable.
Disable or restrict legacy / unnecessary entry points when the site does not rely on them.
Reduce the ability to alter executable code from the dashboard and review file permissions that are broader than necessary.
Review practical browser / transport controls supported by the hosting configuration without claiming headers alone secure WordPress.
After an incident, define which WordPress, hosting, database, SFTP and integration credentials need rotation rather than changing only one admin password.
RECOVERY SHOULD EXIST BEFORE THE NEXT INCIDENT
Security is stronger when the business already knows how to restore a clean site, who controls the domain and hosting, and which credentials or systems must be rotated if an incident happens.
Document who controls hosting, domain / DNS, WordPress administrators, SFTP and any security or backup tools required for recovery.
Output: access and ownership checklistEstablish a clean or post-hardening backup outside the normal WordPress media library and confirm where it is stored.
Output: documented recovery copyRecord the sequence for restoring files, database, DNS / SSL, plugin licences and external integrations so recovery is not improvised under pressure.
Output: practical restore sequenceIdentify which accounts and secrets must be changed after compromise, including WordPress, hosting, database, email/API keys and vendor dashboards where relevant.
Output: credential reset checklistAfter recovery, verify login, forms, booking or checkout, email delivery and other business-critical paths before declaring the site operational.
Output: post-recovery verification listINCIDENT SCOPE CHANGES THE PRICE
The first package is preventative. The next two are recovery scopes for sites with evidence of compromise. Pricing increases with the depth of investigation, cleanup, credential rotation and verification required.
Alpha guide rates preserve the Services hub positioning at about 40% below a conservative professional benchmark. The comparison also aligns with Perth technical-support rates around A$180/hr for deeper rescue work, while Alpha's approved additional security engineering remains A$90/hr.For a live WordPress site with no known active compromise that needs a security baseline, access review and practical hardening.
Typical delivery: 1–2 business daysFor a site showing malicious redirects, injected files, spam pages, rogue admins or malware warnings that can be recovered without a full rebuild.
Typical delivery: 2–4 business daysFor deeper compromise, repeated reinfection, unknown persistence or a site that needs clean component replacement, stronger access controls and a documented recovery path.
Typical delivery: 3–7 business daysGuide prices are in AUD and assume one WordPress installation with working administrative / hosting access. They do not include forensic services for legal proceedings, data-breach notification advice, penetration testing, server rebuilds outside normal WordPress hosting scope, third-party SaaS compromise or recovery of accounts the client cannot prove ownership of. If personal information may have been exposed, legal / privacy obligations should be assessed separately.
Additional approved security / recovery engineering: A$90/hrPREVENT THE SECOND INCIDENT
The cleanest recovery is the one you do not need twice. After hardening or malware cleanup, ongoing maintenance keeps software patched, backups current and obvious security signals monitored.
Explore WordPress Maintenance →Apply WordPress core, plugin and theme updates with a backup and functional check instead of leaving known vulnerabilities open indefinitely.
Keep recoverable copies independent of the live WordPress install so a hosting or account incident does not remove every restore point.
Use recurring monitoring to surface obvious reinfection, availability problems or security alerts earlier.
Remove stale accounts, review administrator access and keep privileged logins protected as staff and vendors change over time.
SECURITY QUESTIONS BEFORE YOU TOUCH THE COMPROMISED SITE
These answers focus on recovery, scope, access and the practical controls that matter after a WordPress security incident.
Avoid random cleanup before a snapshot is taken if the site is still accessible. Secure the relevant accounts, preserve a backup or incident copy, contain obvious malicious behaviour and then investigate files, database, users and vulnerable components in a controlled order.
Often yes. If the database and content are recoverable and compromised core / plugin / theme files can be replaced from clean sources, the site may not need a full redesign. Repeated reinfection or heavily modified unknown code can make a cleaner rebuild the safer option.
Our guide pricing is A$720 for Malware Recovery and A$1,200 for deeper Incident Recovery & Rebuild. A preventative Security Audit & Hardening package is A$360. The final scope depends on access, persistence, affected components and whether ecommerce or booking functionality also needs verification.
The baseline includes administrator access review, stronger authentication where practical, login protection, core / plugin / theme patching, abandoned-component review, permission / file-editor controls, backup guidance and firewall / WAF configuration review where the hosting environment supports it.
No. A security plugin can help with scanning, login controls and firewall rules, but it cannot replace supported software, clean administrator access, secure hosting, independent backups and a recovery process.
Yes, where the incident scope requires it. Compromises can inject spam, scripts, malicious options or rogue users into the database even when the visible PHP files look clean.
For business-critical sites, privileged accounts should use stronger authentication where the workflow supports it. The number of administrator accounts should also be kept as low as practical.
We re-scan, patch or replace vulnerable components, rotate relevant credentials, harden access, create a clean backup, verify critical site functions and document remaining risks. Ongoing maintenance is recommended for sites the business depends on.
Yes, but recovery must include store-specific checks such as cart, checkout, payment / shipping integrations and order-email behaviour. If customer or payment-related data may have been exposed, the business should also obtain appropriate privacy / legal advice.
Yes. We work remotely across Perth CBD, West Perth, Subiaco, Osborne Park, Joondalup, Fremantle, Cannington, Midland, Wanneroo and Rockingham, and can assist WordPress sites elsewhere in Australia.
IF THE SITE IS COMPROMISED, SEND THE SYMPTOMS FIRST
Tell us what changed and what access you still have.
Share the website URL, any warnings or redirects you have seen, whether hosting and WordPress access still work, and whether the site handles bookings, customer accounts or ecommerce. We will scope containment and recovery before making destructive changes.