Skip to content

Sites

The site the last developer left behind. Brought back.

Abandoned, broken or hacked sites, restored and moved to a supported stack. A free call first, then a fixed price per item. We take a checked backup before we touch anything, quarantine before we delete, and log every change with a way back.

Price
Fixed per item
Backups
Checked, before we touch anything
Support desk
North America
Changes
Logged, with a way back

Sound familiar

How a site ends up here

  • The developer is gone

    The person who built it moved on. Nobody has the passwords, the hosting login, or the site's files.

  • It runs on something old

    PHP 5 and a WordPress that stopped updating years ago. The host wants to shut it off.

  • It is broken or hacked

    White screen, redirects to somewhere else, or a warning in the browser. And there are no backups.

Which job is yours

The usual cases, priced

Hacked, on a platform we run

The rescue, $750, one-time. The scan and first look are free support and say in writing that the price applies.

Hacked, on a host that will not give us server access

Most shared hosts do not. Expect the move: the stack upgrade from $499, one-time brings it onto a platform we run, then the rescue runs there. Your domain stays yours and the old copy stays up for a week, so this is not a lock-in.

Old PHP 5, not hacked, host closing the account

The stack upgrade from $499, one-time: the site, the plugins and code that break, tested before the switch. What moves the price up is how many plugins need repair and any abandoned or private add-ons. When that means a rebuild, we say so.

Rescue

Rescue, $750, one-time

Contained the same desk day (desk hours are 8 am to 6 pm Pacific, Monday to Friday), clean within 2 business days of access and your OK, written up, and re-cleaned free within the window if we missed a back door.

Included

  • One WordPress install on one domain on one hosting account, on a PHP version that is still supported, on a platform we run or a server where we hold root (sudo counts). Your diagnosis report, or the free first look on our platform, says in writing whether this price applies before you pay
  • A checked backup of the site exactly as it is, before anything is touched. We keep it for the 30-day window and you get a copy
  • Contained the same desk day we get access on our platform (spam stopped, the bad page locked); on another host, as far as that host lets us
  • Malware, back doors and rogue accounts found and quarantined (moved to a locked folder, not deleted). Everything we plan to remove, accounts included, goes on one list you approve. Quarantined files are deleted only after the 30 days
  • Passwords, the database password and the salts (the secret keys WordPress uses for logins) changed and handed to you alone; you decide who gets access back. The report lists third-party keys you must change yourself
  • WordPress core reinstalled clean; plugins and themes updated. An update that breaks the site's look or features is fixed at the desk-hours rate after we tell you
  • The site hardened, and a written report naming what got in (or that we could not tell), the hand-off date, and what to keep doing
  • Clean within 2 business days of getting access and your OK on the removal list. The clock stops while we wait on you or your host
  • Re-infected within 30 days of the hand-off date through a back door we missed? We clean it again free, as long as you changed the passwords we listed, nothing we told you to remove was put back, the site is still on a server we can reach, and other sites on the same account were cleaned or moved to their own account

Not included

  • A new hole in a different plugin or theme, a stolen password from your own computer, or changes you or your developer make after hand-off. Each is a new job
  • Pirated (nulled) themes or plugins. They are removed; replacing them is quoted
  • Other sites on the same hosting account. Each is its own rescue
  • A hacked site still on PHP 5. It cannot be made safe on an unsupported PHP: it is contained first, then moved (the stack upgrade), then cleaned on the new server
  • The server itself broken into, not just the site. That is server work at the hourly rate (Servers), or a move (Environments)
  • The browser warning. It is Google's to lift; the report shows you how to ask, and the timing is theirs
  • Sites that are not WordPress, and infections that reached several accounts. Quoted after the diagnosis
  • If your hosting plan already includes malware cleanup, use it. Rescue is for sites with no such cover, or off our platform

Moving a site

Stack upgrade, from $499, one-time

The old site is not touched until the new copy is checked. Nothing on the new server runs on an unsupported PHP: what needs it is updated, replaced or removed, and abandoned add-ons may not survive.

  • The old site stays live until you approve the switch after checking a private staging copy (a copy only you and we can see). The switch is a DNS change. We keep our checked backup of the old site for a week after it; the old host's copy stays as long as that host allows.
  • Email is not part of a site move. If your email lives at the old host and that host closes your account, your email goes with it: tell us on the call and we quote a separate mail move. If your domain's nameservers move to us, we copy your mail records exactly as they are before the switch and check them after.
  • A healthy site on a current PHP moving onto a standard shared plan is not a Sites job; the hosting brand that sells the plan moves it. Sites is for sites that cannot be copied as they are: hacked, on an unsupported PHP, or with nobody holding the logins.
  • From another kind of host we copy the files and the database ourselves; we need a file login and a database export or login. Sites that are not WordPress are quoted after the diagnosis.

Where we can work

Access, and what we need from you

Access

  • A rescue runs on a platform we run, or on a server where we hold root (a login to the server itself, not just to WordPress; sudo counts). A WordPress login, FTP or a plain shell is not enough to find what got in, because a back door outside the site folder survives a file-only clean.
  • If that access cannot be granted, the site moves to us first, then the rescue runs there.
  • If the server itself is broken into, not just the site, that is server work at the hourly rate: see Servers.

What we need from you

  • Proof you control the domain or the business behind it
  • The domain name and whoever controls it
  • Any hosting or domain registrar login (where the name was bought) you still have
  • What the site has to keep doing after it comes back

Missing some of it? Bring what you have. Finding the rest is part of the diagnosis.

What we do

Site restore

Every item here is work our desk already does on sites we host and sites we do not.

  • Find out why a site shows an error, a white screen or a server error, and fix the cause: PHP version, .htaccess, file permissions, a stale cache, a full disk
  • Check a WordPress site for malware: scan it, hunt for web shells and hidden PHP in uploads, check cron jobs and .htaccess, and confirm files on disk before calling it hacked
  • Contain a hacked site: stop it sending spam, lock the bad page, quarantine suspect files (moved to a locked folder, not deleted) until you say go, then reinstall clean WordPress core and update every plugin and theme
  • Move an old WordPress site off PHP 5 onto current PHP and WordPress: test every plugin and theme, update what can be updated, replace or remove what cannot, and log every step
  • Repair broken WordPress core files, reinstalling the exact version after a bad copy or a failed patch
  • Take a checked backup before any change, and restore from the server's own backups when asked
  • Point a domain at the new site the safe way: web records first, nameservers only once our zone is live, and never touch mail records during a web move
  • The method is our own Managed WordPress recovery runbook: website only, checked backup with checksums before every step that changes anything, no PHP 5 on the new server, a gated switch-over and a week of watching after it

Tell us what is broken.

30 minutes. We scope it. No cost for the call, and if it points to a rebuild we say so then.