Malware removed, backdoors closed, altered files restored from the official archive, and the hole they came in through sealed. By people who work on nothing but PrestaShop.
One-off fee €345 excl. VATDetailed report handed over at the end. If anything is left behind after our pass, we come back at no charge.
Redirects that only show up from Google, the red "Dangerous site" screen, unknown PHP files in /upload or /modules, spam reported by your host, admin accounts that appeared on their own. Those are the six signs that come up most often.
The details and what to do right nowEvery step has a duration and a deliverable. If your case runs over, several backdoors or a database that has been touched, you hear about it at step three, before we commit the extra time.
You send us FTP or SSH access and the back office. We start within the next working hour.
Intervention slot confirmedFiles and database saved before anything is touched. Nothing we do afterwards is irreversible.
Restore pointCore, modules, themes and uploads, compared against the official archive for your PrestaShop version.
Exact list of rogue files, accounts and cron jobsMalicious code removed, core files restored, rogue accounts and modules deleted, the entry point sealed.
Clean shop, hole closedPrestaSecure module installed. If your domain was blacklisted, we walk you through the review request with Google.
Detailed report, it is yoursThe pattern barely changes. A hole in a third-party module opens the door, a web shell is dropped, then several backdoors are scattered around to keep access even after a quick cleanup. Deleting the file you can see is never enough.
Running totals across every shop we analyse.
We tell you which of these applies to you, with a separate quote if you want one.
No subscription, no setup fee, no surcharge for the number of files or modules. Picked up within two hours.
A cleaned shop stays exposed to whatever brought it down: third-party modules, whose vulnerabilities surface long after they were installed. We track those of 219 different modules, plus the ones in the PrestaShop core. Most never got a fix from their vendor, and close to one in six appears in no public database. Those, we found ourselves.
That is what Serenity covers. Once the shop is clean, we carry on applying fixes, updating vulnerable modules and removing abandoned directories. If the infection comes back anyway, we clean again at no charge.
Two incidents in a year and the subscription has paid for itself. Its real job, mind you, is making sure there is no second incident.
You hear about it at step three, once the scan is done. If the cleanup needs more than the day we planned for, we tell you before carrying on, with the extra time costed. Nothing goes ahead without your say-so.
FTP or SSH access to the server, plus the back office. They are only used for the intervention. Change the passwords right after, it is even advisable: they may have been part of the problem.
No. A full backup is taken before anything is touched, and we do not go near your business database: orders, customers and catalogue stay as they are. We work on the files.
Yes. Once the site is clean, we walk you through the review request in Search Console. Removal usually takes 24 to 72 hours after Google validates it.
We guarantee that the current infection is gone. If anything is left behind after our pass, we come back at no charge. Beyond that, nobody can promise no vulnerability will surface in your modules over the coming months, and that is what the Serenity plan covers.
Hundreds of PrestaShop stores are compromised every day. Attackers exploit a hole in a third-party module, a PrestaShop version that is no longer maintained or a password that was too simple, then inject their code, drop backdoors and siphon off customer data.
Our cleanup does not stop at deleting infected files. We look for how they got in, close that door, and install the protection that prevents a relapse. You walk away with a report listing every file we handled, the vulnerability we identified and the hardening steps to plan for, hosting included.
If you have been hacked once, the odds of it happening again are high: the same modules are still installed, and new vulnerabilities surface in them every month. The Serenity plan covers that risk over twelve months, fixes and cleanups included.
A site blacklisted by Google loses most of its organic traffic. Our team picks it up within two hours.