What Do Companies Charge To Fix Hacked Websites?

What Do Companies Charge To Fix Hacked Websites? The short answer is, you may have to pay anything from $5 to thousands of dollars, depending on the extent of the damage. In this article, I will go through

  • The types of hacks and how they damage your site
  • How the type of damage affects the pricing       
  • How various companies charge

You might already have a vendor in mind, and you’re only trying to see if their pricing is reasonable, or you might be worried that they might be trying to pull a fast one on their pricing. Or perhaps you are looking for somebody to fix your site, but you’re worried that the cost may be out of reach for you. Whichever it is, read on. You’re on the right page.

Types of Hacks and How They Damage Your Site

In order for us to know how companies charge to fix hacked websites, we should understand the work involved in fixing hacked websites. Some companies charge by the hour, so the more complex the job, the more they will charge.

We’ll look at a few things that hackers do to our websites when they hack them. Depending on their goals, the hackers may

  • add files
  • remove files
  • tamper with the database
  • encrypt and lock the website
  • edit/replace files

Add Files

Hackers may install additional files to create phishing websites or run bots to send out spam emails or even hack other websites. Usually, these work like mini-websites alongside your actual website, so you may not realise that it exists.

Fixing this is generally straightforward, as it involves removing the files that were added. However, if it has gone on for a while, your website or mail server may get blacklisted, and we’ll need to approach the companies operating the blacklists to get your site and IP delisted after cleaning the site.

Remove Files

From my own experience, this doesn’t happen as much, unless you happen to be the target of revenge or a prank. I assume the readers are owners of small and medium-sized websites, and in most cases, hackers hack these sites to make use of the domain and IP for their illicit purposes. Removing files would cause your website to stop working, and they need your website to continue working as usual so that they can stay under the radar.

Of course, this can also happen at the hands of a bungling or mean-spirited hacker, so we won’t rule out this possibility entirely.

If there are backups for the affected files available, we can simply restore them. Otherwise, we may need to recreate the affected files, or even the entire site, depending on the extent of the damage.

Edit/Replace Files

There are a few situations in which this might occur. Some hackers hack websites to present their messages, which are often political or religious in nature. Some do it for vanity, or perhaps publicity; the new page simply shows that your site was hacked by so-and-so.

There’s also SEO spam, which occurs when hackers insert certain anchor text with links to other websites to increase the backlink count for those websites, for search engine optimisation (SEO) purposes. Generally speaking, the more backlinks there are to a site, the more likely that site will rank highly for the words used in the anchor texts, so these hackers are trying to squeeze some SEO mileage from the sites that they hack.

For sites that are written in PHP, like WordPress sites, hackers may insert PHP codes into some, or all, of the PHP files, so that those codes would be executed when those files are called.

Sites hacked in this way may present some challenges to the company fixing the website.  If there are no backups available for the files which have been edited, we may need to edit them individually, which can be very time-consuming.

Tamper with the database

The most common thing that hackers would do with the database is to extract information, but hackers may also delete the database or insert malicious codes into the database.

Again, if backups are available, we could easily restore the database. If not, we would need to go through the database to look for the code and remove them.

Encrypt and lock the website

You may have heard of ransomware, which is software that is inserted to encrypt the website and deny access to the site until the owners pay the demanded ransom.

This hurts big websites more as they have more to lose from a non-functioning website. Restoration from backups may not always be feasible, as the last backup may have been done some time before the site was hacked, and significant user data may be lost in the process. This is why some companies chose to pay the ransom, unwilling as they may have been.

The only ways this can be fixed, other than paying the ransom, are to restore the site from the latest backup or to recreate the site.

How the Type of Damage Affects the Pricing

Generally speaking, if your site’s functionality and contents have not been affected, you should do well with any of the companies on this list, even those with affordable fixed fees. In most cases, all they need to do is to remove the added files and/or replace the WordPress (or any other CMS) core files, and the malware would have been cleared.

If your site no longer works normally, or if the contents have been affected, make sure you check with the companies to see if repairs and restoration are included in the price, as some companies may only provide malware removal within their fixed-price plans.

Some damage can be easily fixed, so some of the companies may be willing to cover those with no extra charges, but in some cases, the site may have to be recreated, and it would not be realistic to expect those companies to do that at those low prices.

Tip: Before you approach the companies, see if you or your web developer has a backup of your website. This will definitely help to reduce the effort and cost, in the event that restoration is required.

Some Companies That Can Fix Hacked Websites and How They Charge

Reminder: Although the companies listed here are well-known companies, we’d still encourage you to check reviews on sites like TrustPilot.com, WordPress.org and Google Reviews before committing to any company.

Most of the companies in this list specialise in website security solutions, and some focus specifically on malware removal, so I guess the pricing is somewhat competitive. There are many digital agencies that will also fix hacked websites as a bespoke service, but their prices can be very bespoke as well, so we’ll not be including those in this article.

Generally speaking, there are two ways these companies charge. Those which offer malware removal as a stand-alone service will charge a one-time fee, while some others provide malware removal as a part of an ongoing security service on a monthly or annual subscription basis.

Some of the companies mentioned in this article have plugins which are able to clean the websites automatically, but for the purpose of this article, we’re focussing only on their manual malware removal service.

1.      Fiverr


There are hundreds of freelancers on Fiverr who will fix your hacked website. I have provided the link to the WordPress security category, but you can also search for “malware removal” or “fix hacked website” and add your content management system (CMS), if you’re not using WordPress.

Pricing

URL:  https://www.fiverr.com/categories/programming-tech/wordpress-services/security?source=gig_nested_sub_category_link

  • The prices range from $5 to about $1000.

Services & Benefits

The services and benefits differ from seller to seller, so I won’t list them here, but I’ll put in a shameless plug for my own Fiverr gig offering to fix hacked websites. As I’m just starting out on Fiverr, I am offering my services at rock-bottom prices in a bid to get reviews, so if you need someone to fix your hacked website, take advantage of this opportunity right now, as my prices will go up once I have enough reviews.

https://www.fiverr.com/peterng/fix-your-hacked-wordpress-website-and-remove-malware-and-viruses-from-it

  • Basic malware removal
  • Installation and setup of malware scanner and firewall
  • Website upgrade
  • Website Backup
  • Website restoration
  • Blacklist removal
  • SSL installation
  • Money-back guarantee

2.      Fix Hacked Site


admin-ajax.png

Fix Hacked Site offers both a one-off malware removal service as well as a malware removal subscription plan. There are different prices for different types of websites. The interesting thing is that they seem to offer malware removal for existing infections on their subscription plans, so that may be a better deal than the one-off malware removal service.

Pricing

One-off Malware Removal

URL:  https://fixhackedsite.com/one-off-website-malware-removal-service/

TypePrice
WordPress sites$77
Joomla, PrestaShop, Magento$97
Custom Site including PHP and ASP$147
Subscription Plan

URL:  https://fixhackedsite.com/malware-removal-subscription-service/

Type of SiteMonthly PriceAnnual Price
WordPress$37/mo$297/yr
Joomla, PrestaShop and Magento$57/mo$397/yr
Custom Site PHP and ASP$77/mo$497/yr

Services & Benefits

  • Malware Removal SLA
  • Malware Removal & Hack clean-up
  • Stop Hacks (Virtual Patching / Hardening)
  • Advanced DDoS Mitigation
  • SSL Certificate Support
  • Firewall – HTTPS & PCI Compliant
  • Customer Support
  • 30-Day Money-Back Guarantee

3.      Sucuri


Sucuri is one of the big names in website security, and its WordPress security plugin is one of the most popular security plugins out there.

It offers its malware removal services as part of its annual subscription plans. The main differences between the plans are the committed response times and the frequency of the advanced security scans.

Pricing

URL:        https://sucuri.net/website-security-platform/

PlanBasic PlatformPro PlatformBusiness Platform
Price$199.99/yr$299.99/yr$499.99/yr
Malware Removal SLA30 hours12 hours6 hours

Services & Benefits

  • Malware & hack removals by our security experts
  • Malware Removal SLA
  • Post-clean-up basic report
  • Frequency of advanced security scans
  • Website Application Firewall (WAF)
  • Blocklist Monitoring & Removal
  • SSL Support & Monitoring
  • Stop Hacks (Virtual Patching/Hardening)
  • Firewall Protection – HTTPS & PCI compliant
  • Advanced DDoS Mitigation
  • CDN Speed Enhancement
  • High Availability/Load Balancing
  • CMS & Hosting Compatibility
  • Support Requests

4.      SiteLock


If you are using one of the big names for your web hosting, you might have already heard of SiteLock, which has partnerships with many of them.

For pre-existing infections, you will need to purchase their  Emergency 911 Cleaning and Ongoing Monitoring service, also called SiteLock 911 Website Expert Clean, priced at $199, although its subscription plans also include malware removal.

Pricing

URL: https://www.sitelock.com/products/fix-hacked-site/

ServicePrice
Emergency 911 Cleaning and Ongoing Monitoring$199

Services & Benefits

  • Priority Access to SiteLock’s team of experts
  • Response within 6 hours of your order
  • Most sites are cleaned within 4 to 6 hours of gaining server access
  • 911 services include both automated and expert manual cleaning techniques
  • 911 repairs are guaranteed to remove malware, SEO spam, backdoors, and blocklist warnings. In the rare case that we cannot remove the identified issues, you will be fully refunded.
  • One year of external monitoring is included, though SiteLock 911 + Pro or Business are recommended to prevent future attacks.

5.      OneHourSiteFix


OneHourSiteFix’s fixes hacked websites for a flat fee of $49, and as its name states, it does so within one hour. It also has a custom-developed AI-powered cloud-based firewall and plugin, which you can use to protect your website from further attacks.

Pricing

URL:  https://www.onehoursitefix.com/fix-my-hacked-website-now-website-malware-removal-prices/

ServicePrice
Rapid Fix$49

Services Provided

  • 1-Hour Fast Malware Removal
  • Platinum level 24×7 support as standard
  • 30-second rapid response times from our industry-leading support team
  • Security Recommendations
  • 30-Day Money-Back Guarantee

6.      WP Buffs


WP Buffs offers malware removal as part of its Perform, Custom and Custom Pro WordPress website maintenance packages. As such, its prices are higher than the companies offering only website security.

Pricing

URL:        https://wpbuffs.com/plans/

PlanMonthly PriceAnnual Price
Platform$219/mo$2196/yr
Custom$347/mo$3480/yr
Custom Pro$447/mo$4476/yr

Services & Benefits

  • Weekly WP Updates
  • 24/7 Emergency Support
  • 24/7 Uptime Monitoring
  • Google Analytics Integration
  • Cloud Backups
  •  24/7 Unlimited Website Edits
  • Security Optimization
  • iThemes Security Pro Premium
  • Speed Optimization
  • Mobile & Tablet Optimization
  • Image & Media Optimization
  • Complete Malware Removal

7.      HackRepair.com


HackRepair.com fixes hacked websites for a fixed price of $279, but they’re offering a $100 discount for small sites less than 50mb or less than 100 files in total. This means that sites running on content management systems like WordPress, Joomla or Drupal would not qualify for this discount.

Pricing

URL:  https://hackrepair.com/services/hack-repair-service-100-discount

Type of SitePrice
Small sites less than 50mb in size or less than 100 files
$179
Sites bigger than 50mb in size or more than 100 files$279

Services & Benefits

  • We start fixing your site immediately, and we will follow up until the matter is fully resolved.
  • Our goal is prevention. We will educate you so this doesn’t happen again.
  • We provide you with a full security review and recommendations report.
  • We include WordPress security plugin installation.
  • We will teach you how to better secure WordPress.
  • We have years of advanced WordPress expertise.
  • We inspect every file on your site for malware.
  • We clear all hack related issues, including blackhat SEO spam injections, phishing, drive-by downloads, backdoors, and other malicious files.
  • We will upgrade your blog(s) and update all plugins as needed.
  • Money-back guarantee if we are not able to resolve your malware issue!

8.      WP Fix It


WP Fix It specialises in WordPress support and it, in its own words, “invented and perfected the flat fee WordPress support model.”

Pricing

URL:  https://www.wpfixit.com/wordpress-malware-removal-service/

ServicePrice
WordPress Malware Removal Service$117

Services & Benefits

  • Same Day Service
  • Detailed Website Scan
  • File & Database Security Audit
  • Server Level Security Check
  • Website User & Role Analysis
  • Full Infection Removal
  • Security Enhancements
  • Blacklist Removal
  • Infection Removal Report

9.      NinTechNet


NinTechNet provides security solutions for WordPress and other PHP websites, in addition to fixing hacked websites. It charges a fixed price of $199 for cleaning 1 site, and there are discounts for cleaning multiple sites.

Pricing

URL:  https://nintechnet.com/ninjarecovery/

ServicePrice
Malware clean-up$199

Services & Benefits

  • Cleaning up the site
  • Finding and patching the vulnerability
  • Securing the site
  • One-month monitoring

10.     Malcare


Malcare is part of a family of websites offering solutions for WordPress, and it offers a security plugin for WordPress as well.

Pricing

URL: https://www.malcare.com/website-malware-removal/

ServicePrice
Emergency clean-up$249

Services & Benefits

  • Website cleaned within 12 hours
  • Full Hack clean-up (No Page Limits)
  • Guaranteed clean-up or 300% money back
  • Dedicated Security Analyst
  • Trusted by over 50,000 customers
  • Exceptional Customer Support

11.     Malcure


Malcure is yet another company that specialises in website security solutions. In addition to WordPress, it also provides malware removal for Drupal sites, which is less common.

Pricing

WordPress

URL:  https://malcure.com/wordpress-malware-removal-service/ (WordPress)

ServicePrice
Complete WordPress Website Malware Removal$147
Drupal

URL: https://malcure.com/drupal-malware-removal-service/ (Drupal)

ServicePrice
Complete Drupal Website Malware Removal$247

Services & Benefits

  • Same Day Service
  • Complete Removal With Proof
  • Security Enhancements & Fixes
  • Full Report of Root-Cause-Analysis
  • Free Removal from Blacklists (worth $35)
  • Restoration of Google Ad Campaigns
  • 15 Days Cover

12.     Wordfence


Wordfence is probably the most popular WordPress security plugin in the world. Their malware removal service is offered as part of the Wordfence Care and Wordfence Response subscription plans.

Pricing

URL:  https://www.wordfence.com/products/pricing

PlanWordfence CareWordfence Response
Price$490/yr$950/yr
Customer Support LevelPriority ticket-based1-hour response time

Services & Benefits

  • The Wordfence Firewall
  • The Wordfence Malware Scanner
  • Real-Time IP Blocklist
  • Country Blocking
  • Hands-on Support from a Dedicated Analyst
  • We Install Wordfence
  • We Configure Wordfence
  • We Optimize Wordfence for Performance & Security
  • We Provide a Security Audit & Recommendations
  • clean-up if We Find Malware During the Audit   
  • Security Audit Follow-up with Customer Q&A    
  • We Monitor your Site Security
  • Investigation and Malware Removal
  • Post-incident Blocklist Removal               
  • Post-incident Search Engine Security clean-up
  • Detailed After-action Reports

13.     Cwatch Comodo


Unlike the other companies featured in this list, which specialise in security solutions for individual websites, Comodo is a leading provider of enterprise cybersecurity solutions, in addition to its solutions for websites, mobiles and desktops.

Cwatch Comodo offers website security subscription plans, but if your site has been hacked, they will fix your website for free with no obligations.

Pricing

URL:        https://cwatchstore.com/pricing/malware-removal/

  • Free Malware Removal

Services & Benefits

  • Absolutely Free, No obligation, hidden charges, fancy pricing or gimmicks.
  • No credit card required. 
  • We remove your malware instantly and repair the damage to your website at no charge.
  • Works for malware, hacker attacks, comment spam, SQL injections, DDos, cross-site scripting, and more.

14.     FixMySite


FixMySite is another company focused on providing support for WordPress websites.

Pricing

URL:        https://fixmysite.com/wordpress-malware-removal/

ServicePrice
WordPress Malware Removal Service$119

Services & Benefits

  • Scan Your Website
  • Remove Malicious Content
  • Check Core WordPress Files
  • Security Hardening
  • Blacklist Removal
  • Report

15.     Websicherheit


Websicherheit is German for web security, so we can see its commitment to providing web security services for websites.

Pricing

URL: https://www.websicherheit.at/en/website-malware-removal/

ServicePrice
Website Malware RemovalUS$149 (€129)

Services & Benefits

  • Immediate Help with “Satisfaction” guarantee
  • Removal of all Malware (clean-up)
  • Remove all Backdoors
  • Protection against future attacks
  • Google Malware / Blacklist Warning removal
  • Tips on keeping your website safe in future
  • 1-year free website monitoring
  • If your website is hacked again within 8 weeks it will be cleaned again free of charge.

16.     Fixed.net


Fixed.net is also a WordPress maintenance service provider that can take care of all your WordPress problems. You can engage them for malware removal on a one-off basis or as a part of one of the ongoing maintenance plans.

Pricing

URL:  https://fixed.net/pricing

One-off Malware Removal
ServicePrice
One-off WordPress clean-up£49
ServiceMonthly Price
Care Plan£39/mo
Unlimited Plan£79/mo
Complete Plan£159/mo

Services & Benefits

  • We quickly clean hacked websites
  • WordPress hardening
  • Ongoing WordPress protection
  • Enterprise-level 24/7 WordPress security

17.     Unhack.net


Unhack.net is a specialist in website security. Unlike the other companies on this list, they don’t offer a flat fee for malware removal.

Pricing

URL:  https://unhack.net/#faqs

  • It depends on the hack. The hack repair can be done for only $250 in many cases, but you’ll need to contact them to get an exact quote.

Services & Benefits

  • Immediate Response
  • Full Problem Ownership
  • Preventive Security Too
  • 30 Days of Coverage
  • Available by Phone
  • Money-Back Guarantee

Parting Words

We hope this article has given you a good idea of the prices charged by the different companies. As you have seen, the services are bundled differently, so we can’t do apples-to-apples comparisons based on the prices alone. Assess your own needs and see if you might need those bundled services, then see if those services might justify the higher prices.

As a parting note, I’d like to remind you that getting a vendor to fix our hacked website requires you to hand over access to our website and server, so please check their reviews on sites such as TrustPilot, WordPress.org (for vendors with their own WordPress plugins) and Google Reviews before making a decision.

If you’re engaging freelancers on platforms such as UpWork, Freelancer or Fiverr, you may be in a better situation. You should still check the reviews of the freelancers on those sites, but even if something happens, you can be sure that your money is protected because your payments will only be released after the work has been completed.

Time-Limited Offer

I am starting to offer my malware removal services on Fiverr, and I need reviews, so I’m pricing the packages at rock-bottom prices, starting with $5. If your site has been hacked, and you need a professional to take care of it, take advantage of this offer now. The prices will be increased once I have garnered enough reviews.