Luca Cavallini

Hacked PrestaShop cleanup

Is your PrestaShop shop hacked?

Strange redirects, Google’s red warning screen, an admin account you never created: it can be fixed. I clean the site, close the hole and tell you exactly how it happened. Cleanup from €390.

From €390 Work with me

If you found this page, you probably already know something is wrong: the shop redirects elsewhere, Chrome shows the red warning, or fake orders have shown up out of nowhere. Write to me: cleanup usually takes 24 to 48 business hours once I have access, and if you write URGENT as the first word of your message, I see it first.

Cases

Does this sound familiar?

  • The shop redirects to strange pagesVisitors land on another site, often ads or a phishing page, and you haven’t changed anything.
  • Google shows the red warning screenThe browser tells visitors the site is dangerous, and traffic drops overnight.
  • There’s an admin account you never createdAn unknown account appears in the back office, or you’re getting password-reset emails you never requested.
  • Strange orders or emails are going outThe shop sends order confirmations for purchases nobody made, or customers report suspicious emails from your address.
What I do

What I do, exactly

  • File and database cleanupI remove the malicious code from files and tables, comparing against a clean copy of the core and the modules.
  • Finding the entry pointI trace how they got in: a vulnerable module, an abandoned plugin, a stolen credential, an exposed FTP account.
  • Update and closing the holeI patch the compromised part and close the gap that was found, not just the visible symptoms.
  • Rotating every password and keyAdmin, database, FTP, API keys: all regenerated.
  • Checking admin accountsI review every back-office admin account and remove the ones you don’t recognize.
  • Google review requestIf the red warning is showing, I request Google’s security review once the site is clean.
  • A written final reportA document explaining where they got in and what I did, so you know exactly what happened.
How it works

How I work

  1. You write to me. Tell me what you’re seeing: redirects, the red screen, strange emails. I reply within one business day, and if you write URGENT as the first word I see it first.
  2. I look at the access. You give me access (FTP/SSH or back office), I check files and database and give you a clear quote based on what I find.
  3. I clean up and close the hole. Cleanup, patching, password rotation. Usually 24 to 48 business hours from getting access.
  4. I hand you the report. I explain how they got in, what I fixed, and what you can do to reduce the risk going forward.
Pricing

What it costs

From €390

Hacked site cleanup

File and database cleanup, hole closed, passwords and keys rotated, final written report. The exact price depends on how compromised the site is and for how long.

From €90/month

Monthly maintenance

Updates, backups and ongoing monitoring, to cut the risk of it happening again.

Why me

Why work with me

  • 20 modules for sale, not just claimsI write and sell 20 PrestaShop modules on my own shop: you can see the code I write before you even contact me.
  • A public back-office demopsdemo.cavallini.net is a public demo, open it without asking me first.
  • Published technical guidesI write real guides on PrestaShop performance and compliance, not generic filler articles.
  • Proper Italian invoicingItalian VAT number, regular electronic invoice, no middleman between you and the person doing the work.
FAQ

Questions, answered

How long is the shop down?
Cleanup usually takes 24 to 48 business hours once I have access. If the site has been compromised for a long time or there’s database damage, it takes longer, and I tell you before starting.
Do I lose the orders that came in during the attack?
No, orders and customers stay in the database: cleanup removes the malicious code, not your data.
Does Google’s red screen go away on its own?
No, a security review has to be requested after the site is clean: that’s one of the steps I handle.
How did they get in?
I explain it in the final report: usually a vulnerable module, an abandoned plugin or a stolen credential. Knowing that is the first step to stop it happening again.
Can you guarantee it won’t happen again?
No, nobody honest can guarantee that. I can close the hole I find and cut the risk substantially with updates and ongoing monitoring, which is exactly what the monthly maintenance is for.

Tell me what’s not working, or not talking to what.

New build, a system that needs rescuing, an integration, the June 2026 deadline. One developer who builds it and stays to run it. I reply within one business day.