Hacked WordPress repair, and the hole that let it happen
Cleaning the payload is the easy half. If the route in is still open the site is reinfected inside a week, so every clean-up ends with the hole named, closed and re-tested.
What the work is
Four things, each of which produces a number you can check on your own site afterwards.
Malware removal and integrity check
Core, theme and plugin files diffed against known-good. Database scanned for injected options and users.
Close the route in
On one store a spam purge was only half the job — the open registration path that produced the accounts was closed in the same pass.
Bot and crawler policy
Bot rules must never match wc-ajax: blocking cart fragment refreshes kills every cart on the site. Rules are tested against a real cart before they go live.
Firewall without the own-goals
A bad-bot plugin's honeypot link is an uncacheable full-bootstrap URL — the block amplifies the load it was installed to reduce.
Five jobs. Every month. Each one counted.
Retainers bundle all five. Any one of them can also be bought once, as a single measured pass with a before column and an after column.
Plans priced on the work,
not on the checklist
Month to month, no lock-in. Prices are per site, per month, exclusive of GST. Portfolios and multi-site estates are quoted on the estate.
For a site that just needs to stay up, patched and backed up
For a store where slow pages are costing orders
Running a portfolio you cannot afford to have go quiet? Managed starts from ₹17,999/mo.
The questions
everyone asks first
Straight answers, including the ones about price, access and what we will not do.
Updates, backups, uptime and security are the floor — every plan has those. What separates a retainer from a host's support desk is the measured work underneath: autoload and database health, object cache sizing, bot policy, disk audits, and a quarterly report with a before-and-after column. Your host will never do any of that, because none of it is their responsibility.