Website Redirect Hack Removal
Malicious redirect hack removal for websites across Europe. Fixed-price cleanup, entry-point found, blocklist help and a free retest. Get a quote.
Website redirect removal is the work of finding and pulling out the code that quietly bounces your visitors to spam, pharma, scam or adult sites, then closing the hole that let it in so the redirect does not come straight back. If your pages open normally on your office desktop but send phone visitors or people arriving from Google to somewhere you have never heard of, you almost certainly have a redirect hack, and this page explains exactly how we clean it.
What a redirect hack looks like from the outside
A redirect hack rarely announces itself. The homepage still loads for you because the malicious code is written to skip logged-in administrators and known IP addresses, and to fire only for a fresh visitor on a mobile browser or someone who clicked through from a search result. That selectivity is the point. It keeps the site owner calm while the attacker monetises your traffic and your search ranking.
The symptoms clients describe
People contact us with the same handful of stories. A customer phones to say the site “took them to a betting page”. Google Search Console flags “Deceptive site ahead” or the browser paints a red interstitial. Analytics shows a cliff in mobile conversions with no change to desktop. Sometimes the only clue is a staff member’s own phone opening a different site than their laptop does on the same URL.
Why it targets some visitors and not others
Injected redirect code reads the request before it decides what to do. It checks the user agent for a mobile signature, looks at the HTTP referer for a search engine, and often sets a cookie so the same person is only redirected once. If you keep refreshing from your own machine you will conclude the site is fine. That is why owners lose days before they accept there is a real problem.
Where the redirect actually lives
In most redirect cleanups we handle, the malicious instruction is hiding in one of a small number of predictable places. Knowing them is half the job; the other half is proving we found every copy, because attackers plant several so that removing one changes nothing.
The database is the part people forget
Cleaning files and leaving the database is the classic reason a redirect returns within hours. We search the full database, not just wp_options, for encoded strings, script tags in post content, and injected rows in the users table. A single overlooked entry in the active theme’s options can rebuild the entire attack.
Multisite and shared hosting cases
On a multisite network or a reseller account with several sites in one hosting space, a redirect can jump between neighbours through a shared uploads directory or a common cron. We check every site that shares the account, because signing off on one while its neighbour is still infected buys you a reinfection by the weekend.
How we find and remove the redirect
Our redirect removal is manual and evidence-led. We do not simply run a plugin scanner and hand you its output, because those tools miss custom obfuscation and flag harmless code as dangerous. An engineer reads the site the way the attacker did.
Integrity comparison against clean core
We download a pristine copy of your CMS core and the exact plugin and theme versions you run, then diff your files against them. Anything that differs from the vendor original is a candidate. This surfaces the two extra lines dropped into an otherwise legitimate file, which is where redirects love to hide.
Pattern hunting and manual review
Alongside the diff we grep the codebase for the tell-tale constructs: eval, base64_decode, gzinflate, str_rot13, long hexadecimal blobs and document.location rewrites. Every hit is read by a person before anything is deleted, so a legitimate caching plugin that happens to use base64 is never mistaken for malware.
Finding the entry point in the logs
Removing the redirect is not the finish line. We pull your web server access logs and correlate the file modification timestamps with the requests around them. That usually pins the exact vulnerable plugin, upload endpoint or stolen login that let the attacker in, which is the information you need to make sure this does not happen again.
Clean removal without breaking the site
Because we identify precisely which bytes are malicious, we remove the injection rather than deleting whole files and hoping. Your layout, your content and your working plugins stay intact. Where a core or plugin file has been tampered with, we replace it with the clean vendor version so nothing you rely on stops working.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Getting off Google’s blocklist
Once a redirect is caught by Google, the “This site may be hacked” label or a full Safe Browsing warning can cost you more traffic than the hack itself. Removal is only useful if we also lift the flag.
The review request, done properly
After the site is verified clean we help you file the security-issue review in Search Console and, where a browser warning is present, the Safe Browsing review. We make sure the request is submitted only when the site is genuinely clear, because a rejected review resets the clock and can leave you flagged for longer.
Restoring trust with hosts and blocklists
Some hosting providers suspend an infected account, and third-party blocklists such as those used by antivirus vendors can also mark you. We provide the clean-up evidence you need to get an account reinstated and to request delisting from the major blocklists.
Hardening so the redirect stays gone
The reason clients come back to a cheaper “clean” they bought elsewhere is that nobody closed the door. We finish every job by removing the way in and reducing the ways back.
Closing the entry point
If the logs point to an out-of-date plugin, we update or replace it and remove any abandoned plugins that are no longer maintained. If a login was brute-forced, we reset credentials and enforce two-factor authentication on administrator accounts.
Reducing the blast radius
We tighten file permissions, disable the in-dashboard file editor, lock down the uploads directory so it cannot execute PHP, and remove the fake admin users and rogue cron jobs the attacker left as a way back in. On request we set a web application firewall in front of the site to block the injection attempts before they land.
Optional ongoing protection
For sites that were compromised once through a known-weak stack, we offer a low-cost monthly monitoring option that watches file integrity and alerts on new admin users, so a repeat attempt is caught in hours rather than after your customers notice.
Pricing
Redirect removal is priced as a fixed package by how much of the site is affected and whether the infection has spread across several sites in one hosting account. Here is the shape of a typical European engagement.
| Package | What’s included | Timeline | Price |
|---|---|---|---|
| Single site clean | One website, full file and database scan, redirect removal, entry-point identification from logs, free retest | 1–2 working days | from €350 |
| Clean + harden | Everything above plus closing the entry point, credential reset, 2FA on admins, file-permission and uploads lockdown | 2–3 working days | from €450 |
| Blocklist recovery | Clean plus Search Console and Safe Browsing review assistance, host and blocklist delisting evidence | 2–4 working days plus Google review time | from €600 |
| Multi-site / reseller account | All sites sharing one hosting space cleaned and hardened together to stop cross-reinfection | on scoping | from €900 |
| Ongoing monitoring add-on | File-integrity monitoring, new-admin and change alerts, priority reclean if it returns | continuous | from €120/month |
| Custom / large estate | Many sites or a complex custom application, scoped to your setup | on scoping | custom |
Every clean-up is fixed-price, quoted after a free 20-minute scoping call, and the retest that confirms the redirect is gone is included at no extra cost. Get a fixed quote
Why a scanner alone will not fix this
Free malware plugins are useful as an alarm and useless as a cure. They read a signature list, so a payload written for your specific site slips past, and they cannot tell you how the attacker got in. We have cleaned sites that three separate scanners declared healthy while they were still redirecting phone users to a casino. A person who reads the logs and diffs the code finds what a signature misses.
Evidence you can act on
You receive a short written summary: what was infected, where the redirect lived, the entry point we found in the logs, what we removed, and the hardening we applied. That record is what your host, your insurer or your compliance officer will ask for, and it is what tells you the job was done properly rather than papered over.
How we work with you
SafetyBis is a European offensive-security team that cleans and hardens compromised websites for clients across the EU and remotely worldwide. The engineers who do the removal hold OSCP and OSWE certifications and have spent years on the attacking side, which is exactly why they know where redirect code hides. Every engagement runs under an NDA, and for a live, spreading compromise our 24/7 incident-response line means you are not waiting until Monday.
FAQ
How much does website redirect removal cost?
How quickly can you remove the redirect?
The redirect only happens on mobile or from Google. Can you still reproduce it?
Will cleaning the site break my design or content?
Why did my last redirect removal come back?
Can you get rid of the Google “this site may be hacked” warning?
Do you find out how the site was hacked?
Do I need the monthly monitoring afterwards?
Related services
Site owners, agencies and IT leads whose website is bouncing visitors to spam or scam pages, has been flagged by Google or a browser, or has been cleaned before only for the redirect to return.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.