Joomla hacked? We clean it up fully – with no data loss

Redirects to unknown websites, spam sent through your system, a warning from Google or a suspension by your host: if your Joomla site is compromised, you do not need a debate. You need someone who fixes the problem at its root.

Many agencies and providers then say: restore an old backup or rebuild the site. In most cases that is wrong – and it costs you exactly the data that has been added since the backup.

We clean the current state: malware and backdoors out, entry point closed, content stays. No articles, menus, orders or customer data are lost – because we do not roll back, we clean up.

Fixed price €490 plus VAT for a standard case. The initial assessment is free and no costs arise without your approval.

  • full clean-up – no data is lost
  • no rebuild, no restore from an old backup
  • response usually within a few hours
  • fixed price for standard cases, assessment free of charge
  • three months of aftercare and monitoring included

Restore a backup or clean up?

The first advice people hear from hosts and many providers is almost always: restore an old backup or rebuild the site. In most cases both are not just needlessly expensive, they destroy your current data.

What others often suggest
  • Restore an old backup – everything since then is gone: orders, forms, new articles, customer accounts.
  • Rebuild the site – weeks of work, high cost, same extensions, often the same break-in afterwards.
  • The entry point and the backdoor are often already inside that backup.
  • A file backup does nothing about a planted administrator, because that is a database record.
What we do
  • We clean the current state – your content stays fully intact.
  • Every file is compared against the original packages; malware and backdoors are removed.
  • The database is reviewed and planted super users are removed.
  • The entry point is closed; credentials and secrets are rotated.
  • No data is lost, because we do not roll back – we clean up.

That is where we differ from many others: clean-up instead of data loss. If a rebuild really is the better route in your case, we will tell you so openly.

4-step process

How the clean-up works

Four clear steps: from the free assessment through to sign-off – without detours.

1

Initial assessment, free

You describe what you are seeing and give us the domain. We tell you whether it looks like a hack and what a standard case costs.

2

Clean up

Compare all files against the original packages, remove malicious code and backdoors, review the database, remove planted administrators.

3

Close the entry point

Bring Joomla and extensions to a safe version, harden the configuration, rotate all passwords, database credentials and secrets.

4

Sign-off and report

Final checks, removal of Google warnings on request, plus a written report covering findings, root cause and the measures taken.

After that, three months of aftercare and monitoring run alongside, because reinfections almost always happen in that window – or not at all.

How to tell your site was hacked

Not every one of these symptoms necessarily means a hack. But each of them needs a quick answer, because the damage grows with every day.

  • your site redirects visitors elsewhere, often only on certain devices or when arriving from search results
  • spam is sent through your system, or your host reports unusual outbound mail
  • there are super users in the backend you never created – addresses ending in @secure.local are a very reliable sign
  • Google Search Console or the browser warns about your site
  • there are PHP files in image and upload folders that have no business being there
  • your site suddenly shows error 500 or a blank page although nobody changed anything

What we need from you

If you no longer have access, that is not a blocker. We sort it out together with your host.

  • access to the hosting, via FTP or SSH
  • access to the Joomla backend, if still possible
  • the name of your host and, if you have it, the abuse or suspension notice
  • a phone number for the short route

These extensions were under active attack in 2026

In most of the cases that reach us, the way in was a known flaw in a widely used extension – not the Joomla core. If one of these runs on your site, that is the first place we look:

JCE Editor, affected up to 2.9.99.4, severity 10.0
SP Page Builder, affected up to 6.6.1, severity 10.0
Helix Ultimate, affected up to 2.2.6

iCagenda, Page Builder CK and Balbooa Forms followed. The full overview with the safe versions is on Joomla vulnerabilities 2026.

The three months of aftercare are not a discount

Reinfections almost always happen in the first weeks after a clean-up. That is exactly why aftercare runs during that window: we see whether something comes back and can react immediately. If something returns through the same entry point during the three months, we clean it again at no charge. After that, aftercare ends on its own – we do not renew anything automatically. Instead we ask you in good time whether you want ongoing care afterwards, for example with Basis-Schutz or another maintenance package.

Joomla clean-up: €490 plus VAT

Fixed price for a standard case: one Joomla installation, access available, no shop. The assessment beforehand is free.

Included in the fixed price:

  • complete clean-up of files and database
  • removal of all backdoors and planted administrators
  • identification and closing of the entry point
  • rotation of all passwords, database credentials and secrets
  • final checks and a written report
  • removal of Google warnings on request
  • three months of aftercare and monitoring included
After the three months, aftercare ends automatically – no renewal and no cancellation needed. Before it ends we ask whether you want ongoing care afterwards, for example with Basis-Schutz (€69 per month, cancellable monthly) or another maintenance package. Larger cases such as several affected sites on one hosting account, shops or multisite installations are clarified transparently after the initial assessment, before we start.
transparent fixed prices

We deliberately look after a limited number of Joomla projects so that quality, personal guidance and reliable response times remain sustainable.

FAQ

Do we have to take the website offline immediately?

If visitors are actively being served malicious code, or spam is going out through your system: yes, until the findings are clear. Maintenance mode is usually enough. In many cases it is not necessary at all and we clean up while the site stays online.

Do you need a clean backup from me?

No. That is the whole point: we clean the current state so your content stays intact. In most cases an old backup would restore both the vulnerability and the backdoor – and wipe everything added since then.

Is any data lost during the clean-up?

No. Articles, menus, media, form submissions, orders and customer data stay intact. Many providers recommend a backup restore or rebuild – that is exactly how current data gets lost. We fully clean the live state instead of rolling back.

What does the clean-up cost?

€490 plus VAT for a standard case, meaning one Joomla installation with access available. The initial assessment is free and you receive a firm answer beforehand. For more involved cases we discuss it first.

How long does it take?

Most clean-ups are finished within one working day. Complex infections or several affected sites take longer – we tell you in advance.

My host suspended the site. Can you get it back online?

Usually yes. That is what the final report is for: it documents what was found and fixed. Hosts require this kind of evidence before lifting a suspension.

Could I not clean it up myself?

Occasionally, with small infections. The problem is the backdoors: attackers place several identical copies in different folders and clean up their obvious traces themselves. Whoever finds and deletes one has often missed three more.

Will the attacker come back?

Not through the same route, because that is exactly what we close. And if something does return through the same entry point during the three months of aftercare, we clean it again at no charge.

What does it cost after the three months?

Aftercare ends automatically after three months – without renewal. Before it ends we ask whether you want to continue. Basis-Schutz then costs €69 per month and is cancellable monthly. It covers updates, security updates, backups and monitoring. If you also want critical vulnerabilities closed immediately and clean-up cover in an emergency, Manage Joomla Care is the right package.

Tell us briefly what you are seeing and give us your domain. You will receive a free assessment of whether and how badly your site is affected, and what the sensible next step is.

Get a free check