MogaCode Essaouira Maroc
Website hacked? Every hour makes the situation worse. Google blacklists within 48 hours.
WORDPRESS EMERGENCY · RESCUE + CARE

Your WordPress site
Has it been hacked?

Google blacklists infected sites within 48 hours. Your hosting provider may suspend your account without notice. Your customer data may already have been exfiltrated.

21 sites cleaned
Computer forensics expert
Response in less than 4 hours
RECOGNIZING THE INFECTION

8 signs that your WordPress site
is already compromised

Most owners discover the infection weeks after it has occurred.

Strange redirects

Your visitors are being sent to gaming, pharmaceutical, or adult content sites.

Google Chrome alert

"Ce site pourrait nuire à votre ordinateur", vos visiteurs fuient

Unknown pages in Google

"Unwanted Software" or "Phishing" message in your Google console

Unknown files

Mysterious .php files in your wp-content or uploads folders

Sudden slowness

Le serveur envoie du spam en arrière-plan, votre CPU explose

wp-admin inaccessible

The attacker created their own admin account and changed your access credentials.

SEO spam injected

Des centaines de pages en langues étrangères apparaîssent dans votre source HTML, invisible à l’œil, dévastateur pour le SEO

Hosting provider that suspends

Compte bloqué sans préavis, tous vos sites hors ligne en une seconde

Any one of these symptoms is enough. To fail to act is to choose to worsen the situation.

WHILE YOU WAIT

What an infected website costs you
with each passing hour

48 hours
maximum time before
Google blacklist
-89%
organic traffic
from the moment of the blacklisting
4 weeks
to return to Google
after cleaning
100%
hosting providers suspend
without notice

The real-life case: In April 2026, an Infomaniak shared hosting account hosting 21 WordPress sites was massively infected via null plugins. The result: 14 active backdoors, 485 MB of exfiltrated data,Admin accounts created without the owners' knowledge. Response time: 12 hours. Source: MogaCode cleanup.

PREUVE PAR L'EXPÉRIENCE, AVRIL 2026

21 sites cleaned.
12 hours flat.

What we found

  • 14 active backdoors, dissimulées dans des fichiers PHP à noms légitimes, dans wp-content/uploads et les dossiers de plugins
  • 485 MB of exfiltration archive, base de données, fichiers clients, configurations SMTP déjà copiés sur un serveur externe
  • Injection signature identified, chaîne cAT3VWynuiL7CRgr in the Elementor Pro and RevSlider plugins
  • WordPress admins created, 3 comptes admin fantômes sur 7 sites, avec emails jetables comme adresse de récupération

What we did

  • Suppression de tous les fichiers infectés et backdoors identifiés, vérification fichier par fichier via analyse forensique
  • Resetting all WordPress salted keys and administrator passwords on 21 sites simultaneously
  • Activation et configuration de Wordfence sur chaque site, règles de pare-feu, scan planifié, alertes email activées
  • Documented incident report with a comprehensive list of all deleted files and identified attack vectors

Result: 21 clean, secure sites back online in less than 12 hours. No sites were blacklisted by Google.

Patrick, auditeur forensique, MogaCode Rescue

""Bad plugins are the number one cause of mass infection on shared hosting. A single infected site can contaminate all neighboring accounts. We don't compromise on that.""

Patrick, Expert judiciaire informaticien · Tribunal de Commerce de Bruxelles · Fondateur MogaCode

OUR METHOD

5 steps.
Certified clean result.

1

Audit forensique complet, inclus dans l'offre 49€

Scan of all WordPress files, identification of backdoors, files modified outside the update cycle, unauthorized admin accounts, vulnerable plugins, and incorrect permissions. Detailed PDF report delivered within 24 hours.

2

A precise quote before work begins

Based on the audit, a fixed quote is provided before any work begins. No surprises. No additional hours of service being charged without the client's knowledge. A firm price, confirmed before starting.

3

Surgical cleaning of infected files

Removal of every identified backdoor and malicious file. Replacement of WordPress core files with official versions. Verification of the integrity of every active plugin and theme.

4

Hardening WordPress

Resetting salted keys, changing all admin passwords, checking file permissions, configuring Wordfence firewall, disabling PHP execution in uploads, protecting wp-login.

5

Forensic report + recommendations

A comprehensive document listing: identified attack vectors, deleted files, actions taken, and recommendations to prevent recurrence. Useful in case of litigation or insurance claims.

Your site can be saved.
Do not choose the nuclear option.

Many come to us after hearing the most destructive advice on the web: «"Delete everything and start from scratch."». This advice is wrong, costly, and unjustified in 95% of cases.

Rebuilding from scratch = disaster

  • 3 to 8 weeks minimum work
  • Total loss of content, pages, forms
  • SEO anéanti, mois ou années de référencement perdus
  • Reconstruction budget: €800 to €5,000+
  • Without forensic testing, reinfection is guaranteed within 72 hours.

MogaCode Rescue, la bonne option

  • Intervention within 24 to 72 hours
  • All your content preserved
  • SEO et URLs inchangés, aucune perte de trafic
  • À partir de 99€, devis ferme avant intervention
  • Full forensic report delivered

The trap of rebuilding without cleaning up: If the initial vulnerability is not identified and patched, the new site will be infected in less than 72 hours. A proper forensic analysis is non-negotiable before any reconstruction.

The truth that plugins will never tell

Wordfence, Sucuri, MalCare…
Too late for them. That's why.

These plugins are excellent for prevention. After infection, they are outdated.

Ability Wordfence Sucuri MalCare MogaCode Rescue
Preventive scan✓ Included
Removing obfuscated backdoors✗ Unreliable~ Sometimes✗ Unreliable✓ 14 backdoors eliminated (real case)
Identification of the infection vector✗ No✗ No✗ No✓ Full forensic report
Cleaning DB injections/WP tables✗ No✗ No~ Limited✓ Tables inspected line by line
Spam content injected into pages✗ No✗ No✗ No✓ Pages, posts & options cleaned up
If the hosting provider suspends the account✗ Impossible✗ Impossible✗ Impossible✓ Direct server access
Active cleaning price~179$/year
(plan required)
~199$/incident
(12-30 hour delay)
~149$/year
(semi-automatic)
Starting from €99
Human · documented · guaranteed

Why Wordfence fails after infection: un malware bien installé peut désactiver activement Wordfence, se masquer dans des extensions légitimes ou se recharger via wp-cron compromis. La présence de Wordfence sur un site infecté ne signifie pas que le site est propre, ça signifie que l'attaquant a désactivé la détection. Seule une inspection humaine fichier par fichier est fiable.

TARIFS TRANSPARENTS, PAS D'ABONNEMENT

Two one-off offers.
Quote before any action.

FIRST STEP

Security Audit

On inspecte. On documente. On vous dit exactement ce qui ne va pas, et ce que ça coûtera de corriger.

49

Fixed price · PDF report within 24 hours

  • Complete scan of all WP files
  • Backdoor & malware detection
  • Analysis of plugins & themes
  • PDF report + quote for services if necessary
Commencer l'audit, 49€
EMERGENCY
COMPLETE CLEANING

Rescue Intervention

On nettoie. On sécurise. On documente. Devis ferme avant d'agir, aucune surprise.

Price upon request

From €99 · Quote before work begins

  • Complete cleanup (files + database)
  • Removal of all backdoors
  • Hardening WordPress Complete
  • Forensic report + 30-day guarantee
Request emergency intervention

No mandatory subscription. No contract. Written quote before each service. Fixed price.

WHY TRUST US

This is not our first
forensic context.

Patrick, fondateur MogaCode, spécialiste sécurité WordPress

Patrick

Founder of MogaCode · 30 years in IT

Computer forensics expert

Agréé par le Tribunal de Commerce de Bruxelles. Habitué à produire des rapports forensiques recevables en justice, le même niveau de rigueur s'applique ici.

30 years of experience in information systems

Before CMSs and null plugins, there were misconfigured servers and rootkits. Attack vectors change. The rigor of analysis does not.

Infomaniak Partner · Clients in Belgium, France, Morocco

40+ sites gérés en production continue. On connaît l'infrastructure, les limites des hébergeurs mutualisés, et les vecteurs d'infection réels, pas théoriques.

Cas documenté, résultats réels, pas un discours commercial

Le cas des 21 sites décrit sur cette page est réel. Les chiffres (14 backdoors, 485 MB) sont exacts. On a vécu le problème de l'intérieur, c'est pour ça qu'on le résout pour les autres.

Frequently Asked Questions

What we are asked most

How can I tell if my WordPress site has been hacked?
The most visible signs: redirects to unknown websites, "dangerous site" alerts in Chrome, malware messages in Google Search Console, content modified without your intervention, sudden slowness, and spammy contact forms. If you have any doubts, a €49 audit will give you a precise answer within 24 hours.
How long does it take Google to blacklist my site?
Generally, this occurs between 24 and 72 hours after infection detection. Once blacklisted, your Google traffic drops by 80 to 95% immediately. Recovery from the indexes takes 2 to 4 weeks after a complete cleanup and submission of a reconsideration request.
Can my hosting provider really suspend my account?
Oui, et sans préavis. Les hébergeurs (Infomaniak, OVH, Ionos...) suspendent automatiquement les comptes qui envoient du spam ou hébergent du contenu malveillant. La suspension peut affecter l'ensemble des sites hébergés sur le même compte, pas seulement le site infecté.
How do useless plugins infect a website?
"Vanished" plugins (pirated, available for free on dubious websites) deliberately contain backdoors. The attacker who distributes them thus creates a network of infected sites that they control remotely. This was the exact vector of the Infomaniak infection in April 2026: pirated Elementor Pro and RevSlider plugins with the signature cAT3VWynuiL7CRgr.
What is included in the €49 audit?
The audit includes: a complete scan of all WordPress files (core, plugins, themes, uploads), identification of backdoors and malicious files, verification of unauthorized admin accounts, analysis of file permissions, and a review of vulnerable or outdated plugins. All of this is delivered in a detailed PDF report within 24 hours, with a quote for intervention if necessary.
How much does a cleaning service cost?
L'intervention est sur devis à partir de 99€. Le devis précis est établi après l'audit, en fonction de la complexité de l'infection et du nombre de fichiers touchés. Le devis est fourni par écrit avant toute intervention, aucune surprise sur la facture finale.
Is there a guarantee after cleaning?
Yes. If a missed backdoor is discovered within 30 days of the intervention, the fix is free. Furthermore, each cleanup includes WordPress hardening, which significantly reduces the risk of reinfection: salted keys are reset, the firewall is configured, permissions are corrected, and wp-login is protected.
Do you manage sites outside of Morocco?
Oui. Nous intervenons à distance sur des sites hébergés partout dans le monde. Nos clients actuels sont en Belgique, France, Luxembourg et Maroc. Le nettoyage se fait via accès SFTP/SSH, la localisation géographique du site n'a aucune importance.
While you're reading this, your site continues to lose Google rankings.

Has your website been hacked?
We will respond within the hour.

Direct WhatsApp with Patrick. Not a chatbot. Not a form that gets lost in the shuffle.
Free diagnosis in less than 15 minutes.

Available 7 days a week · Belgium, France, Morocco, Luxembourg · Response within 24 hours

Notre différence

Ce qu'un plugin de sécurité ne fera jamais à votre place

Un plugin scanne et vous laisse seul face au résultat. Nous, on entre dans le serveur, on retire le code injecté fichier par fichier, on remonte jusqu'à la faille d'entrée pour la refermer, et on demande à Google de lever la mise en garde. Vous récupérez un site propre et une explication claire de ce qui s'est passé, pas une liste d'alertes incompréhensibles. Un seul interlocuteur, joignable même le week-end, parce qu'un piratage ne prévient pas.

Let's discuss your project on WhatsAppDécouvrir la méthode MisterGoo →
Une fois votre site nettoyé, l'étape suivante est de le protéger durablement : voyez notre approche de la sécurité WordPress et notre maintenance WordPress au Maroc, pour ne plus jamais revivre un piratage.
Chat with Patrick