Is your website in trouble?
Breathe first.
We check the symptoms, explain the recovery steps, then make the cost clear. Start with the URL alone — no access needed yet.
We reply during business hours, usually in under 2 hours.
The initial diagnosis is free. The price is fixed before we touch anything.
WhatsApp: +62 823-2569-9629
Baca halaman ini dalam Bahasa Indonesia
- Access only after you agree
- Backup before changes
- One-time payment
Which of these looks most like yours?
You do not need the technical terms. Open the card that feels closest; these symptoms are early clues, not a verdict.
Malware / virus The site redirects, the browser blocks it, or hosting sends a warning. Moderate · 1–3 business days
Visible signs
- The website suddenly slows down and files appear that you do not recognise.
- Hosting sends a malware or suspicious-activity warning.
- A visitor antivirus blocks the site; the browser or search result shows “This site may be hacked”.
- When opened, pages redirect visitors to another site.
If left alone: Visitors can be affected, data may be taken, and hosting may suspend the website.
This estimate is for a basic infection. If it spread into the database or other sites on the same hosting account, the scope and timing must be reassessed.
Online-gambling injection Gambling pages appear, or Google titles change, though you did not create them. High · 2–5 business days
Visible signs
- Gambling pages or articles appear that you never created.
- The navigation menu grows by itself.
- Page titles and descriptions on Google change into gambling promotions.
- Foreign .php files sit in the wp-content/uploads folder.
- The homepage injects an iframe or script from an outside site.
If left alone: Your business name is tied to gambling, visitors are sent elsewhere, and attackers can keep coming back through a back door.
Gambling injections are usually not only in files. They also enter the database — the posts, options, and users tables — and often create hidden admin accounts. Cleaning files alone is not enough.
Google index spam / clean index A search for site:yourdomain.com returns hundreds of foreign pages. Moderate–high · 3–10 business days + Google wait
Visible signs
- A “site:yourdomain.com” search returns hundreds or thousands of foreign pages in English/Japanese, or gambling pages.
- Search Console reports thousands of URLs you never created.
- The website appears on Google with strange titles, even though the front page looks normal.
If left alone: Search results mislead potential customers and spend Google attention on fake URLs instead of your business pages.
What we can do: remove fake files and pages, clean the sitemap, fix .htaccess, close the gaps, install attack barriers, then file Removals through Search Console and repair the signals to Google.
Removals hide results temporarily. To stop them returning, the fake URLs must actually be deleted (404/410), not merely blocked via robots.txt.
What cannot be guaranteed: when Google clears the remaining search results. Usually a few days up to several weeks, and it can be longer. That is entirely Google's decision. No vendor can guarantee a date.
Website down / critical problems Error 500/503, database not connecting, or the homepage replaced. High; depends on hosting & backup condition · 1–7 business days
Visible signs
- The website cannot be reached at all: error 500, 503, or ERR_TOO_MANY_REDIRECTS.
- The database is corrupt, or “Error establishing a database connection” appears.
- The website is defaced: the homepage has been replaced by someone else.
- Disk quota is full, WordPress core files are damaged, or the hosting account is locked.
- The website needs to be restored from backup.
If left alone: Service and transactions stop. Trying to restore or delete files without a copy can reduce the chance of saving the data.
This case does require cPanel, file manager/SFTP, or database access. Access is requested only as needed, after you agree — not during the initial diagnosis. How it is secured is explained below.
See how we protect your accessSpam posts / spam comments Comments full of foreign links, articles publishing themselves, or flooding notifications. Light–moderate · 1–2 business days
Visible signs
- The comment section fills with spam for pills, gambling, or foreign links.
- Articles or pages publish themselves without you creating them.
- Comment notification emails flood your inbox.
- Foreign users appear with the author/contributor role, and bot traffic spikes.
If left alone: Reputation and hosting resources are drained. A foreign account can also become a path to a more serious attack.
If the spam comes from a compromised admin account or injected code, handling is not just deleting comments; the access gap must be cleaned too.
Suddenly slow / frequently down Pages take forever to open, or go unreachable again and again. Moderate–high · 1–7 business days
Visible signs
- Pages that used to be fast keep loading or stop halfway.
- The website is often unreachable, then normal again without you changing anything.
- Hosting CPU, memory, or disk usage spikes; visitors complain they cannot open pages.
If left alone: Visitors and transactions can be lost. The cause may be bots, plugin conflicts, hosting limits, or an infection — not always malware.
Moderate-to-high difficulty, depending on the source. The times above are the range for tracing/critical repair, not a promise that every slow website needs work that big.
The time ranges on the cards are working time after access is ready, not Google waiting time. Diagnosis may show lighter or wider work.
This is not about you not understanding.
Attacks often run automatically, looking for an open door. The point is not only cleaning up, but closing the way in so the problem does not come back.
- Old plugins or themes not yet updated, leaving known gaps wide open.
- Weak or reused passwords; one leaked account can open the others.
- Pirated (nulled) themes/plugins can carry hidden code from the start.
- Shared hosting with poor isolation can be affected by a neighbour account under attack.
- Without an application firewall and monitoring, suspicious activity stays invisible longer.
- No backup is not the cause of an attack, but it makes a small mistake much harder to recover from.
One step first. You still decide.
-
Free initial diagnosis
You send the URL and symptoms. We check from the outside, without asking for any access first. This initial check does not replace a thorough examination inside the hosting.
-
Findings, fixed price, and estimate
We explain what is visible, what must be done, the cost, and the estimated time. No follow-up charges or scope expansion without your approval.
-
You agree, then access is prepared
We agree on the temporary access needed and how to share it safely. You do not have to hand over the main hosting account password.
How is access secured? -
Backup first, then the work
Files and database are copied before any change. Only then are they cleaned, repaired, gaps closed, and tested again.
-
Handover and report
You receive the findings, a change log, what still needs watching, and prevention advice. Temporary access can be revoked once finished.
The cost follows the damage, not your panic.
The number of infected files/URLs, database size, hidden accounts, component condition, and backup availability set the range. We do not charge for everything at once if it is not needed.
| Tier | Problem | Price range | Estimate | What is included |
|---|---|---|---|---|
| Tier 1 | Comment & post spam | Rp350k–750k | 1–2 business days | Spam removed, comment gaps closed, filters installed, foreign users removed. |
| Tier 2 | Basic malware cleanup | Rp750k–1.5m | 1–3 business days | Full scan, malicious files removed, components updated, rescan. |
| Tier 3 | Online-gambling injection (files + database) | Rp1.5m–3m | 2–5 business days | Files & database cleaned, hidden admins removed, .htaccess repaired, gaps closed. |
| Tier 4 | Google index cleanup | Rp1m–2.5m Add-on after malware / gambling-injection cleanup (tier 2 or 3). | 3–10 business days + Google wait | Fake URLs removed, sitemap & robots fixed, Removals filed in Search Console, monitored. |
| Tier 5 | Critical / cPanel needed | Quote after diagnosis Down, defaced, corrupted database, or a server issue that needs tracing. | 1–7 business days | Restore/repair, hosting account secured, backup, monitoring within the agreed scope. |
Business-day estimates start once the scope is approved and access is ready. Waiting on a hosting provider, recovery material, or Google can add calendar time; we tell you if the estimate changes.
- The prices above are ranges, not promises. The exact price is given after the initial diagnosis and does not change without your approval.
- If the problem turns out lighter than expected, we say so plainly and the cost drops with it.
- Emergency work is one-time payment. We do not force you into a subscription. But we will be honest if your website is at risk of breaking again next month.
If you later need routine care, monthly plans are available as an option, not a condition of the repair.
Giving access is not giving up control.
It is reasonable to be careful. The initial diagnosis needs no access. When work is approved, we ask only for access with a clear reason.
What might be needed?
- Temporary WordPress admin
- To inspect plugins, themes, content, and users; remove foreign accounts and update components as needed.
- cPanel / file manager / SFTP
- To back up and clean files, check .htaccess, logs, disk quota, and core files. Limited to the website being handled where hosting supports it.
- That website’s database
- To make a copy, clean injections in posts/options/users, or repair a damaged database — not to access any other database.
- Search Console user invitation
- Only for Google index cases: checking URLs, sitemaps, and filing Removals. Not a request for your Google account password.
Not every access above is always requested. Payment account access, personal email, and main registrar accounts are not part of ordinary cleanup.
Lines we hold
- We never ask for the main hosting account password over chat. We ask for a limited account/sub-account or temporary access, depending on what your hosting supports.
- Temporary access is shared through an agreed secret-sharing channel. Passwords live in a password manager, not in notes or chat. Change them once the work is done.
- Files and database are backed up before changes. If a copy cannot be made, we stop and discuss the options first.
- Every change is logged and reported. No change to the domain, ownership, or hosting plan without your permission.
- When the work is done you can revoke all access. Accounts and working copies stay in your control.
Not comfortable giving access? You keep the screen.
We can guide you step by step over a call. If your hosting does not support limited sub-accounts, we discuss safe temporary access or choose guided assistance — never asking for the main password over chat.
Ownership of the website, domain, and hosting stays 100% yours.
We do not sell hosting and take no commission from your hosting.
You may stop at the repair. Or continue with care.
Routine updates and backups, uptime monitoring, an application firewall, and file-change monitoring all help reduce the next risk. We tell you what is needed and what is not.
You can run it yourself or have the team help. See the care scope and monthly plan options if they are genuinely needed.
Reasonable questions.
How long until my website is normal again?
It depends on the damage, access availability, and backup condition. As a guide: spam 1–2 business days, basic malware 1–3 business days, gambling injection 2–5 business days, and critical cases 1–7 business days. The estimate starts once the scope is agreed and access is ready; hosting problems or waiting on other parties can extend it. We give a specific estimate after diagnosis, rather than promising everything is finished within hours.
Will my data or articles be lost?
We back up before changes and separate your original content from injected content. The aim is to preserve your data. But data already deleted or damaged before we arrive may not be recoverable, especially without a clean backup. We explain the risks and restore options before you agree to anything.
Do you guarantee the website will never be hacked again?
Nobody can guarantee a website is 100% safe. What we can promise is closing the known gaps, explaining the remaining risk, monitoring, and responding quickly if it happens again within the agreed scope and service period. Ongoing monitoring can be chosen separately; it does not automatically become an unlimited service after the one-time job is done.
What if you cannot clean it successfully?
We tell you which parts could not be recovered and do not cover that up with a “it is clean” claim. We discuss restore options from a viable backup, alternative recovery, or help from your hosting provider. Terms for work already done, cancellation, and refunds are agreed in writing before we start. No automatic extra work or charges.
Do I have to subscribe afterwards?
No. Emergency work is a one-time payment. You receive the report and can revoke access afterwards. Monthly care is only an option; we will still be honest if outdated components or maintenance habits put the website at risk of another attack.
My website was built by someone who has disappeared. Is that still possible?
We can look into it first. Send the URL and explain which accesses you still hold — without sending passwords. If hosting access is lost or locked, recovery needs to involve the hosting provider and proof of ownership. We cannot bypass ownership verification or promise the account will definitely return.
How long does Google take to remove spam pages from search?
Usually a few days up to several weeks, and it can take longer. We remove the fake URLs, fix the sitemap and index signals, then file Removals through Search Console. Removals hide results temporarily; they do not remove the source of the infection. The remaining cleanup timing is entirely Google’s decision; no vendor can guarantee a date or a ranking recovery.
Do you need my hosting password?
Not for the initial diagnosis. For certain work we need file/database or cPanel access, but not the main password sent over chat. We prefer a limited account or temporary access through a secure channel. If your hosting does not support that, or you are not comfortable, you can keep the screen yourself and we guide you over a call.
How do I know you will not misuse my access?
Scope and permissions are agreed before access is given, a backup is made before changes, and every change is recorded in the report. You keep the main accounts and can revoke temporary access. Ownership of the website, domain, and hosting does not move. If you want direct control, choose screen sharing: you run the steps.
Can you help in the middle of the night or at weekends?
Messages can be sent anytime. Our business hours are 09.00–18.00 WIB (GMT+7), Monday to Saturday. We reply during business hours, usually in under 2 hours. Outside those hours, handling depends on team availability and must be confirmed first. We do not promise round-the-clock standby for new emergency requests. Monthly plan SLAs follow their plan agreement and do not automatically apply to this service.
Tell us what you are seeing.
No access required yet. The URL and the symptoms are enough to start.
Prefer to explain it over chat?
WhatsApp for website emergencies+62 823-2569-9629. Just send the URL and symptoms, never passwords.