jompom Free health check

Website security, properly done.

If your site has been compromised we clean it, find the way in, and close it. If it hasn't, we make sure it stays that way. Fixed price, no subscription needed.

The reality

Nobody targets you personally.

That's the uncomfortable part. Most WordPress compromises are automated — bots scanning the whole internet for a known vulnerability in a plugin that hasn't been updated. Your site isn't chosen. It's just reachable.

Vector

Outdated plugins and themes — by far the most common way in, and the easiest to prevent.

Vector

Weak or reused admin passwords combined with unlimited login attempts.

Vector

Abandoned accounts from old developers and staff who never got removed.

Vector

Nulled premium plugins, which frequently ship with the backdoor already installed.

The process

Four stages, in this order.

01

Assess

We take a full backup first, then compare every core file against the official WordPress checksums, scan themes, plugins and uploads, and audit the database for injected content. You get a written finding list before we change anything.

02

Clean

Malware and injected code removed, modified core files restored, unknown admin accounts deleted, and any backdoors traced — because removing the payload without finding the entry point just means it comes back next week.

03

Harden

Login rate limiting, file permissions corrected, XML-RPC and file editing locked down where appropriate, database prefix and privileges reviewed, and bad queries blocked at the edge.

04

Monitor

Continuous scanning so a change to a core file, a new admin account or a suspicious login gets flagged immediately — not discovered by a customer three weeks later.

Sample output

You see exactly what we found.

Real report format

Not a green tick and a promise — the actual findings, line by line.

Security audit — findings

Resolved
  • Pass All core files match WordPress.org checksums
  • Fixed Obfuscated PHP found in uploads — removed
  • Fixed 1 plugin with a known CVE — updated
  • Fixed 2 unrecognised admin accounts — removed
  • Fixed Unlimited attempts — rate limiting enabled
  • Pass No injected rows in options or posts
  • Fixed wp-config.php was 644 — corrected to 600
  • Added Bad-query blocking rules deployed
Included
  • Full malware removal across files and database Included
  • Entry point traced and closed Included
  • Core file integrity restored from source Included
  • Database security review and hardening Included
  • Bad query blocking at the edge Included
  • User & permission audit Included
  • Written findings report Included
  • Continuous monitoring 24/7

Removing malware without finding the way in isn't a fix. It's a delay.

Why the assessment comes first

If your site is currently down or defaced, say so when you get in touch — those go to the front of the queue.

Get it looked at
Common questions

Send us the host's notice along with your URL. Hosts usually name the file they detected, which gives us a head start on finding the entry point.

No. We back up before touching anything, and clean surgically rather than restoring an old copy — so you keep the posts, orders and settings created since the compromise.

Most sites are assessed and cleaned within 24–48 hours. Badly compromised or very large sites can take longer, and we'll tell you that up front rather than after.

If it's the same entry point, we fix it at no charge — that would mean we missed something. A different vector months later is a new job, which is exactly why a maintenance plan works out cheaper.

Find out where you stand.

A free health check tells you whether you have a problem — before you spend anything.