Frequently Asked Questions
Website security, answered plainly.
Everything clients ask us before, during and after a security engagement — from “is my site actually hacked?” to what a report contains and how we keep a site clean afterwards.
No jargonNon-destructiveFast answers
Scan
Malware & injected code
Known vulnerabilities (CVE)
Blacklist & reputation
Headers & SSL/TLS
Exposed files & config
01
Hacked & infected websites
How do I know if my website has been hacked?
Common signs include Google or browser "deceptive site" warnings, unexpected redirects (often only on mobile or from search), spam pages or pop-ups you never created, a sudden drop in search traffic, new admin users, or your host suspending the account. A security scan confirms whether malicious code, backdoors or injected scripts are actually present.
How fast can you remove malware from my website?
Most WordPress malware removals are completed within 24–48 hours of receiving access. Emergency response is available when your site is down, redirecting visitors, or blacklisted — those jump the queue.
Will my site stay online during the cleanup?
Yes. We work non-destructively and take a full backup first, so your content, orders and data are safe. For severe infections we can work on a staging copy so visitors never see downtime.
My site was cleaned before but got infected again. Why?
Reinfection almost always means the entry point was never closed. Most 'cleanups' delete the visible payload but miss backdoors, rogue admin accounts, malicious cron jobs or the vulnerable plugin that let the attacker in. We find and close the vector, then harden the site so it can't respawn.
Can you recover a site that has already been taken offline by the host?
Usually yes. We work with your hosting provider, clean the account from a backup or the suspended files, remove the malicious activity that triggered the suspension, then provide the documentation hosts ask for before reinstating.
Do you remove malware from non-WordPress sites?
Yes. WordPress is our specialty, but we also clean and secure other PHP and business websites, including custom builds and other CMS platforms.
02
Security scans, audits & VAPT
What does a website security scan check for?
Malware and injected code, known software vulnerabilities in core/plugins/themes mapped to current CVEs, blacklist and reputation status, missing security headers, SSL/TLS configuration, exposed files and backups, user enumeration, and outdated software — each finding rated by severity.
Is a free online scanner enough?
Free remote scanners are a useful first signal, but they only see what's publicly visible and often miss server-side malware, backdoors and configuration issues. A professional audit combines external testing with deeper checks and gives you an actionable report rather than a pass/fail badge.
What's the difference between a vulnerability assessment and penetration testing (VAPT)?
A vulnerability assessment identifies and rates weaknesses; penetration testing goes further and safely validates which ones are genuinely exploitable. VAPT combines both, so you get a prioritised list of real, confirmed risks rather than raw scanner noise.
Will testing affect my live site?
No. Our assessments are non-destructive and read-only by default — we never modify your data, orders or content. Anything that could change data or affect availability is documented as a theoretical/proof-of-concept path, not executed against production.
What do I receive at the end?
A clear, client-ready report: an executive summary, severity-rated findings with evidence and CVSS scores, malware/IOC analysis where relevant, and a prioritised P0–P3 remediation plan. You can act on it yourself or have us fix it.
Do you provide reports suitable for compliance or client assurance?
Yes. Our reports are OWASP-aligned, CVSS-scored and written for both technical and non-technical readers, so they work for internal sign-off, client due-diligence requests and insurer questionnaires.
03
Google warnings & blacklists
Why is my site showing "Deceptive site ahead"?
Google shows that red warning when Safe Browsing detects malware, phishing or malicious redirects on your site. It stays until the malware is removed and you request a review — so the fix is to clean the site properly first, then submit for re-evaluation.
How long does it take to remove a Google blacklist warning?
Once the site is fully cleaned, Google typically processes a Safe Browsing review within a few hours to about 72 hours. We clean the malware, close the entry point, and submit the review on your behalf to avoid rejections and repeat flags.
Which warnings and blacklists do you handle?
Google Safe Browsing ("deceptive site", "this site may harm your computer"), Google Ads and Merchant Center disapprovals caused by malware, host suspensions for malicious activity, and major vendor blocklists such as McAfee and Norton.
Will my search rankings recover after de-listing?
In most cases yes. Rankings usually recover as Google re-crawls the clean site, though how quickly depends on how long the site was flagged and how much spam was indexed. We also help clean up injected spam pages so they drop out of the index.
04
Hardening & ongoing protection
What is website hardening?
Hardening closes the doors attackers use before they're used: security headers, enforced 2FA, WAF tuning, least-privilege access, safe patching, and locking down risky configuration. It shrinks your attack surface and stops the large majority of automated attacks.
Will hardening break my website?
No. We apply changes carefully with a backup first and test each one, so functionality, forms and checkout keep working. Anything that could affect behaviour is validated before and after.
Is hardening a one-time job?
The core hardening is one-off, but security drifts as plugins, users and configuration change. Continuous monitoring and periodic reviews keep the hardening effective over time.
What does monitoring actually watch?
Malware and injected code, file-integrity changes, uptime and response, blacklist/Safe Browsing status, and SSL/TLS certificate expiry — with instant alerts when something changes so you can act in minutes rather than weeks.
What happens if monitoring finds a problem?
You get an immediate alert with the detail, and we can move straight into cleanup and hardening. Monitoring clients get priority, faster response.
05
Working with us
Do you offer website security services in Cebu, Philippines?
Yes. JS Web Design Services is based in Cebu, Philippines and provides security scans, WordPress malware removal, VAPT and hardening for local businesses and clients worldwide. Everything is handled remotely over a secure connection, so we can start fast wherever your site is hosted.
Do you work with clients in Australia and other countries?
Yes. We regularly work with clients in Australia, the Philippines, and internationally. All work is delivered remotely, and we schedule communication around your timezone.
How much does it cost?
Pricing depends on the size and complexity of your site and whether you need a one-off scan, a full malware cleanup, penetration testing, or ongoing monitoring. Contact us for a fast, no-obligation quote and we'll recommend the right level of protection.
What access do you need?
It varies by service. A scan can start with just your URL. Cleanup and hardening typically need WordPress admin plus hosting/file access (SFTP or control panel). We only ask for what the job requires, and you can revoke access when the work is done.
Do you offer a guarantee?
We stand behind our cleanups: if malware returns from the same vector after we've hardened the site, we'll re-clean it. Because sites can be re-compromised through new vulnerabilities or credential leaks, we recommend pairing cleanup with monitoring.
How do I get started?
Send us your URL and a short description of what you're seeing. We'll confirm scope, run a preliminary assessment, and come back with findings and a clear recommendation — usually within 48 hours.
Still have a question?
Tell us what you're seeing on your site and we'll give you a straight answer — no obligation.