Not running WordPress?
Malware removal for Joomla, Drupal, Magento and the rest
Most hacked-site help on the internet assumes WordPress. If your site is built on something else, you have probably noticed that the folder names in every guide you read do not match anything on your server. I clean those sites too — same manual work, same written report, same one person answering.
What I clean
Platforms I work on
Each of these has a field guide of its own, written for that platform rather than translated from WordPress advice.
Joomla
Extensions and overrides are the usual way in, and the images and tmp folders are the usual hiding places.
Drupal
Usually an unpatched core advisory or an abandoned contributed module, with cached output hiding the evidence.
Read the guide →Magento & Adobe Commerce
Checkout skimmers stored in the database rather than in files. A payment incident, not just a malware problem.
Read the guide →PrestaShop & OpenCart
All the attention of an e-commerce target with a fraction of the security documentation written for owners.
Read the guide →Static HTML sites
No CMS to exploit, so it was credentials. The cleanup is usually the fastest of any platform.
Read the guide →Laravel & PHP apps
An exposed environment file hands over the database password, the app key and every API credential at once.
Read the guide →Not listed? Ask anyway. I have cleaned forums, learning platforms, billing systems, hand-built PHP applications and a fair number of sites whose owners genuinely did not know what they were running. Identifying the platform is the first five minutes of the job, not something you need to work out before getting in touch.
The same everywhere
What does not change with the platform
The way in
An outdated component, a stolen password, or a neighbouring site on the same hosting account. The names differ; the shortlist does not.
The persistence
Backdoors, scheduled tasks, injected database rows and rogue admin accounts. Miss one and the site rebuilds itself, on any platform.
The fallout
Browser warnings, blacklists, search penalties and email delivery problems are platform-agnostic, and they are cleared the same way.
That is why the cleanup does not cost more because your site is Joomla. What drives the price is how long it ran, how many sites share the account, and whether payment data was involved — not which logo is on the dashboard.
Common questions
Before you get in touch
Do you only work on WordPress sites?
No. WordPress is the majority of what I see because it is the majority of what exists, but the work is the same on any platform: find the infection, find the persistence, find the way in, close it, and write down what happened. I clean Joomla, Drupal, Magento, PrestaShop, OpenCart, Shopify themes, Laravel and other PHP applications, and plain static HTML sites.
Is the price different for a non-WordPress site?
The pricing works the same way. What changes the cost is the size of the mess rather than the platform name — how long it ran, how many sites are in the account, and whether payment data was involved. Tell me what you have and I will tell you what it takes before you commit to anything.
My store takes card payments and I think it has a skimmer. What should I do first?
Disable checkout, then contact me. A live skimmer is one of the few situations where I actively recommend taking part of the site offline immediately, because every additional order is another customer's card details taken. It is also a payment card incident with its own notification obligations, which run in parallel with the technical cleanup.
Can you help if I do not know what my site is built on?
Yes, and that is a common situation when a previous developer built it and disappeared. Send me the address and I will tell you what it is running, what state it is in, and what it needs. Identifying the platform is the first five minutes of the job, not a prerequisite for asking.
What if my site is on a hosted platform like Shopify or Wix?
Those are a different shape of problem, because you do not control the server. Compromises there are usually a stolen login, a malicious or compromised app or theme, or injected code in a template — all of which are fixable, and none of which involve cleaning files off a server. Ask and I will tell you honestly whether it is something I can help with.
Whatever it is built on, it can be cleaned.
One accountable person, manual investigation, and a written record of what was found — on WordPress or anything else.