Tell me what broke

Fastest response is WhatsApp. If it's less urgent, the form below reaches me just as reliably.

What I fix

Nearly every WordPress emergency is one of a dozen failure modes wearing a different mask. Below are the ones I handle most often — each links to a full diagnostic guide if you'd rather try it yourself first.

What you seeUsual causeTypical fix time
Blank white page PHP memory exhaustion, fatal plugin/theme error 30–90 min
"Error establishing a database connection" Wrong credentials, crashed MySQL, corrupted tables 30 min–2 h
Spam redirects, pharma pages, browser warnings Compromised plugin, backdoor, stolen credentials 4–12 h
"There has been a critical error on this website" PHP version conflict, fatal error after update 30–90 min
500 Internal Server Error Broken .htaccess, exhausted resources, bad file permissions 30–90 min
Locked out of wp-admin Compromised admin user, corrupted session, plugin conflict 15–60 min
WooCommerce checkout failing Payment gateway conflict, expired API keys, cart session bug 1–4 h
Site suddenly extremely slow Runaway query, cron flood, bot traffic, crypto-miner injection 1–4 h

First aid: do this before you call anyone

Four things, in this order. They cost you five minutes and they protect every option you have left. Do not skip step one — most permanent data loss in a WordPress emergency happens because someone "fixed" things before taking a copy.

  1. Take a backup of the broken state. Files and database, exactly as they are right now. A corrupted site is still recoverable; a corrupted site that someone has already half-repaired often isn't. If you're hacked, this copy is also the forensic evidence that tells us how they got in.
  2. Don't reinstall WordPress. Don't delete "suspicious" files. Reinstalling core over a hacked site removes the evidence and leaves the backdoor. Deleting files at random can take out something your theme depends on. Resist the urge.
  3. Write down what changed in the last 48 hours. A plugin update, a PHP version bump from your host, a new plugin, an expired licence, a migration. Ninety percent of the time the trigger is in that list, and knowing it cuts diagnosis time in half.
  4. If money is moving through the site, put it in maintenance mode. A compromised checkout can be skimming card details. Better to be visibly down for an hour than quietly leaking customer data for a day.

If you're seeing a browser warning or Google flag

"Deceptive site ahead" or a Search Console security notice means the compromise is already public. Don't request a review yet — a rejected review makes the next one slower. Clean first, verify with a fresh scan, then request reconsideration.

How it works, step by step

  1. You message me. WhatsApp, email, or the form below. Tell me the symptom, the URL, and what changed recently. No forms with fourteen required fields — I need three facts to start.
  2. I reply inside the hour with a diagnosis path and a fixed quote. You approve the number before I touch anything. No open-ended meters.
  3. You send access. Hosting panel or SFTP, plus database. I'll tell you exactly what I need and how to send it safely.
  4. I take my own backup, then work on a staging copy where possible. Your live site stops being the laboratory.
  5. I fix the cause, not the symptom. Getting the white screen to go away is the easy part. Finding out why memory was exhausted — that's what stops it recurring next Tuesday.
  6. You get the site back plus a written report. What broke, why, what I changed, and what to do so it doesn't happen again. In plain language, not stack traces.

Response times & pricing

Emergency work is billed hourly with a one-hour minimum, and you always get a fixed quote before work begins. If I can't fix it, you don't pay. That's not a marketing line — diagnosing a WordPress failure is something I'm confident about, and if I'm wrong you shouldn't carry the cost.

SeverityWhat it meansMy response
EmergencySite fully down, hacked, or leaking data. Revenue stopped.Inside the hour, any hour
UrgentSite up but broken — checkout failing, forms dead, admin locked.Same day
NormalSomething's wrong but nothing is on fire.Within 24 hours

Why "cleaned" sites get hacked again

This is the single most common story I hear: the site was cleaned last month — by a plugin, by the host, by another freelancer — and it's infected again. The reason is almost always the same. The cleanup removed the payload and left the entry point.

A real compromise usually leaves three separate things behind: the visible damage (spam pages, redirects), one or more backdoors hidden in innocuous-looking files, and often a rogue administrator account or an attacker-owned SSH key. A security plugin scan finds the first category reliably, the second sometimes, and the third almost never. So the spam disappears, everybody relaxes, and two weeks later the attacker walks back in through the door nobody closed.

A cleanup that actually holds has to answer one question: how did they get in? Until you can name the vulnerable plugin version, the leaked password, or the compromised hosting account, you haven't finished. That's why every cleanup I do ends with a written forensic report naming the entry point — not just a green checkmark from a scanner.

FAQ

How fast can you fix my WordPress site?

I reply inside the hour, 24/7. Once I have access, most emergencies — white screen, plugin conflicts, database errors, fatal PHP errors — are resolved in one to four hours. Hack cleanups typically take four to twelve hours because every file and database table has to be verified, not just the visible damage.

What does WordPress emergency support cost?

Emergency work is billed hourly with a one-hour minimum. You get a fixed quote before any work starts, so there's never a surprise invoice. If I can't fix the problem, you don't pay.

What access do you need to fix my site?

Ideally hosting panel or SFTP access plus database access. If your site is completely down and you can't reach wp-admin, hosting access alone is enough to start. I work from a staging copy whenever the situation allows, so your live site is never the test bed.

My site was hacked. Will it happen again?

Not if the root cause is removed. A cleanup that only deletes visible malware leaves the backdoor in place, which is why so many sites get reinfected within days. Every cleanup I do includes finding the entry point, closing it, rotating all credentials, and removing every backdoor — followed by a written forensic report.

Do you work with my host?

Yes — any host. Shared hosting, managed WordPress (Kinsta, WP Engine, SiteGround, Cloudways), or your own VPS. I've worked inside all of them and know their particular constraints, from disabled PHP functions to restricted file permissions.

Can you help if another developer built the site?

Yes, and it's most of what I do. Inherited sites with no documentation, a departed developer, and a custom theme nobody understands are normal here. I don't need the original developer to be reachable.

Get help now

Three fields minimum. The more detail you give, the faster I can quote.

Or reach me directly: WhatsApp · hello@toumi.us