Home/Services/Website Redirect Hack Removal
security service

Website Redirect Hack Removal

Malicious redirect hack removal for websites across Europe. Fixed-price cleanup, entry-point found, blocklist help and a free retest. Get a quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

Website redirect removal is the work of finding and pulling out the code that quietly bounces your visitors to spam, pharma, scam or adult sites, then closing the hole that let it in so the redirect does not come straight back. If your pages open normally on your office desktop but send phone visitors or people arriving from Google to somewhere you have never heard of, you almost certainly have a redirect hack, and this page explains exactly how we clean it.

What a redirect hack looks like from the outside

A redirect hack rarely announces itself. The homepage still loads for you because the malicious code is written to skip logged-in administrators and known IP addresses, and to fire only for a fresh visitor on a mobile browser or someone who clicked through from a search result. That selectivity is the point. It keeps the site owner calm while the attacker monetises your traffic and your search ranking.

The symptoms clients describe

People contact us with the same handful of stories. A customer phones to say the site “took them to a betting page”. Google Search Console flags “Deceptive site ahead” or the browser paints a red interstitial. Analytics shows a cliff in mobile conversions with no change to desktop. Sometimes the only clue is a staff member’s own phone opening a different site than their laptop does on the same URL.

Why it targets some visitors and not others

Injected redirect code reads the request before it decides what to do. It checks the user agent for a mobile signature, looks at the HTTP referer for a search engine, and often sets a cookie so the same person is only redirected once. If you keep refreshing from your own machine you will conclude the site is fine. That is why owners lose days before they accept there is a real problem.

Where the redirect actually lives

In most redirect cleanups we handle, the malicious instruction is hiding in one of a small number of predictable places. Knowing them is half the job; the other half is proving we found every copy, because attackers plant several so that removing one changes nothing.

Obfuscated JavaScript injected into theme header, footer or a legitimate plugin file
Rewrite rules added to .htaccess or an nginx server block that route mobile traffic away
Poisoned siteurl and home values in the wp_options table pointing at an attacker domain
Hidden admin accounts and fake plugins that reinstall the redirect after a manual clean
Malicious WP-Cron jobs and mu-plugins that rewrite files on a schedule
Base64 or eval-packed payloads in wp-config.php, index.php and uploaded fake image files

The database is the part people forget

Cleaning files and leaving the database is the classic reason a redirect returns within hours. We search the full database, not just wp_options, for encoded strings, script tags in post content, and injected rows in the users table. A single overlooked entry in the active theme’s options can rebuild the entire attack.

Multisite and shared hosting cases

On a multisite network or a reseller account with several sites in one hosting space, a redirect can jump between neighbours through a shared uploads directory or a common cron. We check every site that shares the account, because signing off on one while its neighbour is still infected buys you a reinfection by the weekend.

How we find and remove the redirect

Our redirect removal is manual and evidence-led. We do not simply run a plugin scanner and hand you its output, because those tools miss custom obfuscation and flag harmless code as dangerous. An engineer reads the site the way the attacker did.

Integrity comparison against clean core

We download a pristine copy of your CMS core and the exact plugin and theme versions you run, then diff your files against them. Anything that differs from the vendor original is a candidate. This surfaces the two extra lines dropped into an otherwise legitimate file, which is where redirects love to hide.

Pattern hunting and manual review

Alongside the diff we grep the codebase for the tell-tale constructs: eval, base64_decode, gzinflate, str_rot13, long hexadecimal blobs and document.location rewrites. Every hit is read by a person before anything is deleted, so a legitimate caching plugin that happens to use base64 is never mistaken for malware.

Finding the entry point in the logs

Removing the redirect is not the finish line. We pull your web server access logs and correlate the file modification timestamps with the requests around them. That usually pins the exact vulnerable plugin, upload endpoint or stolen login that let the attacker in, which is the information you need to make sure this does not happen again.

Clean removal without breaking the site

Because we identify precisely which bytes are malicious, we remove the injection rather than deleting whole files and hoping. Your layout, your content and your working plugins stay intact. Where a core or plugin file has been tampered with, we replace it with the clean vendor version so nothing you rely on stops working.

48h
typical turnaround for a single-site redirect clean
100%
manual review before anything is deleted
Free
retest after cleanup to confirm it stays gone
Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Getting off Google’s blocklist

Once a redirect is caught by Google, the “This site may be hacked” label or a full Safe Browsing warning can cost you more traffic than the hack itself. Removal is only useful if we also lift the flag.

The review request, done properly

After the site is verified clean we help you file the security-issue review in Search Console and, where a browser warning is present, the Safe Browsing review. We make sure the request is submitted only when the site is genuinely clear, because a rejected review resets the clock and can leave you flagged for longer.

Restoring trust with hosts and blocklists

Some hosting providers suspend an infected account, and third-party blocklists such as those used by antivirus vendors can also mark you. We provide the clean-up evidence you need to get an account reinstated and to request delisting from the major blocklists.

Hardening so the redirect stays gone

The reason clients come back to a cheaper “clean” they bought elsewhere is that nobody closed the door. We finish every job by removing the way in and reducing the ways back.

Closing the entry point

If the logs point to an out-of-date plugin, we update or replace it and remove any abandoned plugins that are no longer maintained. If a login was brute-forced, we reset credentials and enforce two-factor authentication on administrator accounts.

Reducing the blast radius

We tighten file permissions, disable the in-dashboard file editor, lock down the uploads directory so it cannot execute PHP, and remove the fake admin users and rogue cron jobs the attacker left as a way back in. On request we set a web application firewall in front of the site to block the injection attempts before they land.

Optional ongoing protection

For sites that were compromised once through a known-weak stack, we offer a low-cost monthly monitoring option that watches file integrity and alerts on new admin users, so a repeat attempt is caught in hours rather than after your customers notice.

Pricing

Redirect removal is priced as a fixed package by how much of the site is affected and whether the infection has spread across several sites in one hosting account. Here is the shape of a typical European engagement.

Package What’s included Timeline Price
Single site clean One website, full file and database scan, redirect removal, entry-point identification from logs, free retest 1–2 working days from €350
Clean + harden Everything above plus closing the entry point, credential reset, 2FA on admins, file-permission and uploads lockdown 2–3 working days from €450
Blocklist recovery Clean plus Search Console and Safe Browsing review assistance, host and blocklist delisting evidence 2–4 working days plus Google review time from €600
Multi-site / reseller account All sites sharing one hosting space cleaned and hardened together to stop cross-reinfection on scoping from €900
Ongoing monitoring add-on File-integrity monitoring, new-admin and change alerts, priority reclean if it returns continuous from €120/month
Custom / large estate Many sites or a complex custom application, scoped to your setup on scoping custom

Every clean-up is fixed-price, quoted after a free 20-minute scoping call, and the retest that confirms the redirect is gone is included at no extra cost. Get a fixed quote

Why a scanner alone will not fix this

Free malware plugins are useful as an alarm and useless as a cure. They read a signature list, so a payload written for your specific site slips past, and they cannot tell you how the attacker got in. We have cleaned sites that three separate scanners declared healthy while they were still redirecting phone users to a casino. A person who reads the logs and diffs the code finds what a signature misses.

Evidence you can act on

You receive a short written summary: what was infected, where the redirect lived, the entry point we found in the logs, what we removed, and the hardening we applied. That record is what your host, your insurer or your compliance officer will ask for, and it is what tells you the job was done properly rather than papered over.

How we work with you

SafetyBis is a European offensive-security team that cleans and hardens compromised websites for clients across the EU and remotely worldwide. The engineers who do the removal hold OSCP and OSWE certifications and have spent years on the attacking side, which is exactly why they know where redirect code hides. Every engagement runs under an NDA, and for a live, spreading compromise our 24/7 incident-response line means you are not waiting until Monday.

FAQ

How much does website redirect removal cost?
A single-site clean starts from €350 as a fixed package, with clean-and-harden from €450 and blocklist recovery from €600. You get the exact number after a free scoping call, so there are no hourly surprises.
How quickly can you remove the redirect?
Most single-site redirect removals are done within one to two working days of getting access. If the redirect is actively costing you sales, tell us on the call and we will prioritise it through our incident-response line.
The redirect only happens on mobile or from Google. Can you still reproduce it?
Yes. We test the way the attacker’s code checks visitors, spoofing mobile user agents and search-engine referers, so we can trigger the redirect on demand and confirm every copy of it is gone.
Will cleaning the site break my design or content?
No. We remove only the malicious bytes and restore any tampered core or plugin file to its clean vendor version. Your theme, pages and working plugins are left exactly as they were.
Why did my last redirect removal come back?
Almost always because the database, a hidden admin account or a malicious cron job was left behind, or the entry point was never closed. Our website redirect removal service cleans files and database together and shuts the way in, and the free retest checks it holds.
Can you get rid of the Google “this site may be hacked” warning?
Yes. Once the site is verified clean we help you submit the Search Console security review and, if a browser warning is showing, the Safe Browsing review, and we give you the clean-up evidence hosts and blocklists ask for.
Do you find out how the site was hacked?
We correlate file change times with your server logs to pin the entry point, whether that was a vulnerable plugin, a stolen login or an exposed upload. Knowing the vector is what lets us close it rather than just wipe the symptom.
Do I need the monthly monitoring afterwards?
It is optional. If your site runs a stack that has been attacked before or you cannot patch quickly, the monitoring add-on from €120 a month catches a repeat attempt in hours. Many clients take it for the first few months and then decide.

Related services

Who needs this

Site owners, agencies and IT leads whose website is bouncing visitors to spam or scam pages, has been flagged by Google or a browser, or has been cleaned before only for the redirect to return.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Website Redirect Hack Removal"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.