Four kinds of people can fix a hacked WordPress site: a security company like Sucuri (about $200 to $500 a year, cleanup included), a WordPress maintenance company like us, a freelance developer at $75 to $150 an hour, or you, with a good backup and a few careful hours. Your host usually will not fix it. Here's how to pick fast, because with a hack, speed matters more than price.

First, the ones who won't fix it

Most people email their hosting company first. The host will confirm you're hacked, maybe quarantine the site, and point you at their paid cleanup partner. Keeping the server safe is their job; the malware inside your WordPress files is yours. Knowing this ahead of time saves you the most frustrating day of the whole ordeal.

Your four real options, with honest costs

A dedicated security company

Sucuri and similar services charge roughly $200 to $500 a year and will clean an infected site as part of the subscription. Good choice if you only want the fire put out. They clean the site; they don't update your plugins next month or answer questions about your contact form.

A WordPress maintenance company

This is what we do, so weigh our opinion accordingly. A maintenance company cleans the hack, then fixes the reason it happened: the abandoned plugin, the missing updates, the backups nobody ever tested. Cleanup plus prevention is the difference between this option and the others, and it's why hacked-site owners tend to become long-term clients. Ongoing care starts around $125 a month on our pricing page.

A freelance developer

Expect $75 to $150 an hour, more for senior people, and an unpredictable total because nobody knows how deep the infection goes until they're in it. A good freelancer is a fine choice if you already have one who knows your site. A stranger from a gig marketplace, mid-emergency, is how people get hacked twice.

Yourself

Possible if you have a clean backup from before the infection and you're comfortable with file managers and databases. We wrote a step-by-step guide to recovering a hacked WordPress site. Restore, then change every password, then update everything, in that order. If any of those words felt foreign, this is not the weekend to learn.

Do these three things in the first hour

Whoever you hire, you can limit the damage right now. Change your hosting and WordPress admin passwords. Ask your host to put the site in maintenance mode so visitors and search engines stop seeing spam. And write down what you saw: the weird redirect, the strange new admin user, the pharmacy links. That description shortens the cleanup, and our list of the 12 signs of a hacked site can help you name what you're looking at.

Why waiting costs more than the cleanup

Every day a hacked site stays up, more of the wrong readers see it. Google flags it and warns your visitors. And now there's a newer problem we can measure on our own site: AI crawlers read this website more than 3,000 times in the last 30 days, per our edge logs. A hacked site full of casino spam gets read by the same bots, and that spam becomes part of what AI tools know about your business. Cleanup undoes the infection quickly; being remembered wrong takes longer to fix.

Questions people ask us mid-hack

How much does it cost to fix a hacked WordPress site?

A security subscription with cleanup included runs $200 to $500 a year. Freelancers charge $75 to $150 an hour with an open-ended total. Maintenance companies typically fold cleanup into ongoing care. The expensive option is doing nothing for a week.

Can I just delete the site and start over?

You can, and sometimes that's rational for a small brochure site. You lose your content, your SEO history, and every link ever pointed at you. Price that against a proper cleanup before deciding.

Will it happen again?

If only the symptom gets cleaned, often yes. Reinfection comes from the same open door: the outdated plugin, the weak password, the nulled theme. Whoever fixes your site should tell you how it got in, not just that it's gone.

Written by Jeane Sumner, who has seen what a website looks like at 9pm on the day it started serving casino ads. Here's how we make our content.