Guides

What to do when it happens. Written from real incidents.

Practical, evidence-dense guides by our senior engineers. The free steps genuinely work — use them. When you want it handled instead, you know where we are.

Removing Google's "this site may be hacked" warning

How to remove Google's "this site may be hacked" warning: clean the actual infection first, then request review via Search Console — with realistic timelines and traps to avoid.

by Ken Armitt · updated Jul 2026 Read the guide →

Website redirecting visitors to spam sites

Website redirecting to spam, scam or pharmacy pages? Where malicious redirects hide (.htaccess, injected JS, database, plugins), why you can't see it, and how to remove it properly.

by Ken Armitt · updated Jul 2026 Read the guide →

Japanese keywords in your Google results

Seeing Japanese spam titles for your domain in Google? The Japanese keyword hack explained: auto-generated spam pages, cloaked sitemaps, rogue Search Console owners — and the proper cleanup.

by Ken Armitt · updated Jul 2026 Read the guide →

Your website has been defaced

Website defaced with someone else's page or message? What to do first, why a backup restore alone isn't the fix, how attackers got in, and how to stop it coming straight back.

by Ken Armitt · updated Jul 2026 Read the guide →

Phishing or spam sent from your domain

Customers getting phishing or spam from your domain? How to tell spoofing from a real compromise, and how to stop each — SPF, DKIM and DMARC, or hunting the mailer backdoor.

by Ken Armitt · updated Jul 2026 Read the guide →

A ransom or extortion demand

Received a ransom demand about your website or customer data? How to check whether the threat is real, why paying rarely ends it, what evidence to preserve, and the notification clock you may be on.

by Ken Armitt · updated Jul 2026 Read the guide →

Locked out of your WordPress admin

Hacked and locked out of WordPress — password changed or admin user gone? How to regain access through your host and database, find the rogue admin accounts, and lock attackers out for good.

by Ken Armitt · updated Jul 2026 Read the guide →

The red "Deceptive site ahead" screen

The full-page red "Deceptive site ahead" or "Dangerous site" warning is Google Safe Browsing. What triggers it, how to clean the cause, and how to request the review that removes it.

by Ken Armitt · updated Jul 2026 Read the guide →

Removing malware from WordPress

How WordPress malware removal actually works: finding injected files and database infections, the backdoors scanners miss, closing the entry point, and verifying the site is genuinely clean.

by Ken Armitt · updated Jul 2026 Read the guide →
Call now — 24/7+1 469 489 7950