Objective
This guide explains how to safely order the cleanup of a hacked site from the public area (without logging in). You will learn the steps: select the platform (WordPress, WooCommerce or PrestaShop), describe the incident, enter your contact details, pay, and receive access to the tracking and secure transmission of credentials for the intervention.
Who this article is for
For owners, administrators or agencies responsible for a compromised site who want to purchase a professional cleanup through the public flow. Suitable for WordPress (including WooCommerce) and PrestaShop (1.7 to 9).
Before you start (prerequisites)
- Have a valid email address and a payment method (bank card). We use a secure payment within the order page.
- Prepare a precise description of the incident: observed signs (unknown pages, redirects, errors, spam emails), approximate date/time, recent actions (updates, new plugins/modules).
- Never send passwords by email or chat. Sensitive information is shared only in the secure client area after payment.
- If you prefer that we do not obtain access, read the "precautions" section below.
Step‑by‑step
-
Access the public “Order the cleanup” page
- Go to the Securantis order page from the marketing site. You will see a multi‑step form.
-
Step 1 — Choose the site / platform
- Enter the URL of the affected site.
- Select the platform: WordPress, WooCommerce (for an e‑commerce site on WordPress) or PrestaShop. The choice adjusts the assessment and the team that will intervene.
- Why this matters: each CMS has a different architecture and attack vectors; the analysis and cleanup procedure differs.
-
Step 2 — Describe the incident
- Provide a short title and a detailed description: symptoms, first appearance, affected pages, whether backoffice access is still possible, site availability.
- Indicate if you have already taken the site offline or enabled maintenance mode.
-
Step 3 — Contact details
- Enter your contact details (name, email, phone) and billing information if required.
- If you represent an agency, specify the role and the main contact.
-
Step 4 — Summary
- Verify the selected platform, the requested diagnostic and the estimated price. You can add an additional license if desired.
-
Step 5 — Payment
- Proceed to payment via the secure module. Once the transaction is accepted, you will receive a confirmation email.
- After payment, a client account is created or activated if you already had an account; instructions for secure access to communications and transmission of credentials will be provided.
-
After payment — transmission of credentials and start of intervention
- We request the necessary credentials via the secure client area (not by email). You choose when to provide these credentials.
- The team begins with an initial audit and will send you a preliminary report and an intervention plan.
Platform‑specific behavior
- WordPress: the audit checks file integrity, compromised plugins/themes, access security rules and the presence of malicious elements injected into the database. If WooCommerce is detected, additional checks on payment pages and order data are performed.
- WooCommerce (on WordPress): the intervention takes into account risks related to the checkout flow and sensitive customer data. We avoid any manipulation that could alter ongoing orders without informing you.
- PrestaShop (1.7 to 9): the analysis focuses on modules, front/back controllers, overrides and characteristics specific to PrestaShop. The cleanup preserves the shop operation and the orders database.
Expected outcome after ordering
- Written confirmation of the order and creation of the client file.
- Initial audit with a list of suspicious items and a proposed action plan.
- Cleanup intervention applied after your agreement on the proposed actions (quarantine, restore, manual file removal, hardening). Important: quarantine, restoration or deletion always requires your human approval.
- Final detailed report and recommendations to prevent recurrence (updates, 2FA, CAPTCHA, backups).
Cautious settings and immediate recommendations
- Activate or request activation of a maintenance mode to protect your visitors during the analysis if the site receives public traffic.
- Change administrator account passwords only via your interface, after receiving recommendations and under the guidance of the team. Never send them by email.
- Prepare a full backup (files + database), stored offline, before any restoration. We can advise you on the procedure if needed.
- Enable 2FA and CAPTCHA on access pages after the cleanup.
Common mistakes and pitfalls
- Trying to fix it yourself without a backup: risk of worsening the compromise or losing data.
- Providing credentials by email: stop this practice immediately; use the secure client area.
- Not specifying the exact platform: choose precisely WordPress vs PrestaShop; report WooCommerce if present.
- Assuming automatic deletion: never assume the malware is removed without human decision and a documented report.
Quick troubleshooting (before the intervention)
- If the site is completely inaccessible, note the exact error (HTTP code, server message) and attach it in the incident description.
- If you have a backup from before the incident, keep it and inform us. Do not restore anything without coordination.
- If you suspect a leak of customer emails or sensitive data, report it immediately; we will prioritize the investigation.
Legal and confidentiality precautions
- We do not require or request passwords by email or chat. Credentials for the intervention are requested and transmitted only via the secure client area, after payment.
- Interventions are documented; any intrusive action (file deletion, restoration) is performed only after your approval.
- If personal data has been compromised, inform yourself about your legal obligations; we can advise on technical steps but not on legal compliance specific to your jurisdiction.
When to contact support before/during the order
Contact support if:
- You are not sure of the site platform (we need to know if it is WordPress/WooCommerce or PrestaShop).
- The site contains sensitive customer data and you want prioritized handling.
- You have time constraints for the intervention (e.g. do not intervene during traffic peak times).
- You have already taken actions and fear you modified critical elements (backups deleted, partial restorations).
Final notes
- Ordering via the public page allows for fast processing and creation of a secure client area.
- Professional cleanup always follows a sequence: audit, action plan, client validation, execution, report and recommendations.
- We do not claim to automatically remove malware without validation: every action is explained and documented.
If you are ready, go to the order page, choose the platform corresponding to your site and describe the incident as precisely as possible. A team will contact you after payment for the next steps of the intervention.