Hacked PrestaShop cleanup
Is your PrestaShop shop hacked?
Strange redirects, Google’s red warning screen, an admin account you never created: it can be fixed. I clean the site, close the hole and tell you exactly how it happened. Cleanup from €390.
If you found this page, you probably already know something is wrong: the shop redirects elsewhere, Chrome shows the red warning, or fake orders have shown up out of nowhere. Write to me: cleanup usually takes 24 to 48 business hours once I have access, and if you write URGENT as the first word of your message, I see it first.
Does this sound familiar?
- The shop redirects to strange pagesVisitors land on another site, often ads or a phishing page, and you haven’t changed anything.
- Google shows the red warning screenThe browser tells visitors the site is dangerous, and traffic drops overnight.
- There’s an admin account you never createdAn unknown account appears in the back office, or you’re getting password-reset emails you never requested.
- Strange orders or emails are going outThe shop sends order confirmations for purchases nobody made, or customers report suspicious emails from your address.
What I do, exactly
- File and database cleanupI remove the malicious code from files and tables, comparing against a clean copy of the core and the modules.
- Finding the entry pointI trace how they got in: a vulnerable module, an abandoned plugin, a stolen credential, an exposed FTP account.
- Update and closing the holeI patch the compromised part and close the gap that was found, not just the visible symptoms.
- Rotating every password and keyAdmin, database, FTP, API keys: all regenerated.
- Checking admin accountsI review every back-office admin account and remove the ones you don’t recognize.
- Google review requestIf the red warning is showing, I request Google’s security review once the site is clean.
- A written final reportA document explaining where they got in and what I did, so you know exactly what happened.
How I work
- You write to me. Tell me what you’re seeing: redirects, the red screen, strange emails. I reply within one business day, and if you write URGENT as the first word I see it first.
- I look at the access. You give me access (FTP/SSH or back office), I check files and database and give you a clear quote based on what I find.
- I clean up and close the hole. Cleanup, patching, password rotation. Usually 24 to 48 business hours from getting access.
- I hand you the report. I explain how they got in, what I fixed, and what you can do to reduce the risk going forward.
What it costs
Hacked site cleanup
File and database cleanup, hole closed, passwords and keys rotated, final written report. The exact price depends on how compromised the site is and for how long.
Monthly maintenance
Updates, backups and ongoing monitoring, to cut the risk of it happening again.
Why work with me
- 20 modules for sale, not just claimsI write and sell 20 PrestaShop modules on my own shop: you can see the code I write before you even contact me.
- A public back-office demopsdemo.cavallini.net is a public demo, open it without asking me first.
- Published technical guidesI write real guides on PrestaShop performance and compliance, not generic filler articles.
- Proper Italian invoicingItalian VAT number, regular electronic invoice, no middleman between you and the person doing the work.
Related work
Questions, answered
How long is the shop down?
Do I lose the orders that came in during the attack?
Does Google’s red screen go away on its own?
How did they get in?
Can you guarantee it won’t happen again?
Tell me what’s not working, or not talking to what.
New build, a system that needs rescuing, an integration, the June 2026 deadline. One developer who builds it and stays to run it. I reply within one business day.
Prefer email?
luca@cavallini.net