Free audit

WordPress hosting & maintenance — Quebec

Is your WordPress site already hacked without you knowing?

Most WordPress infections stay invisible to the site owner. They switch off while you're logged in, then target your visitors. I detect them, I remove them, and I make sure they don't come back.

No access required · Report within 48 h · No commitment

A service by Roberto Mas — 27+ years of web experience

27+ yrs
of web experience, 20+ with WordPress
100+
WordPress sites managed
31
sites cleaned in a single incident
EN/FR
bilingual service, Quebec time zone

Real case — July 2026

31 sites infected for 7 weeks. Nobody had seen it.

Malicious code installs itself across a fleet of WordPress sites. It intercepts every page, disables the browser's protections and shows a fake "Prove you're human" check that tricks the visitor into running a command on their own computer.

Its trick: it erases itself for logged-in administrators and for their IP addresses. The owners saw a perfectly normal site. Neither the host nor the installed security plugin raised the alarm.

Detected

A cross-checked external scan: cached page against fresh page, and a search for the markers the code leaves behind precisely by hiding.

Cleaned

Malicious code quarantined, database traces purged, every stolen session invalidated. Nothing permanently deleted: everything stays recoverable.

Explained

Point of entry identified with evidence, and proven by elimination across the whole fleet. Skip this step and reinfection is inevitable.

What I take care of

Maintenance isn't just clicking "Update"

Three areas, designed so you never have to think about them again.

Security monitoring

Regular integrity checks on files and the database, detection of injections and conditional redirects. If something shows up, you're the one who's notified — not your customers.

Controlled updates

Core, plugins and theme kept up to date, with a backup taken first and verification afterward. An update that breaks the site is an incident, not a fact of life.

Backups and restore

Regular copies kept off the server, and above all: tested restores. A backup you've never restored isn't a backup.

Pricing

Transparent, no commitment

Prices in Canadian dollars. Cancel anytime.

Hosting

For a site that simply needs to stay online, fast and secure.

$15/ month

or $180 per year

  • Managed server, SSL certificate included
  • Regular backups
  • Per-site isolation
  • Visitor statistics (Matomo)
Request a quote

Complete maintenance

So you never have to touch your site yourself again.

$99/ month

hosting included

  • Everything in the previous plan
  • Priority support
  • Content edits included
  • Priority bug fixing
  • Cleanup included if infected
Get started

Is your site already infected?

Emergency intervention: diagnosis, full cleanup, access rotation and point-of-entry search. Free estimate over the phone.

(819) 803-9916

Also available: .com/.net domains $25/yr, .ca $30/yr · Professional email from $12/yr · Migration from your current host
Prices in Canadian dollars, taxes extra.

FAQ

What we're asked most

How do I know if my site is hacked?
Often, you can't tell just by visiting it. Modern infections switch themselves off for logged-in administrators and their IP addresses: the site looks perfectly normal to you while your visitors receive malicious code. The indirect signals — a Google warning, clients reporting a strange popup, a drop in traffic — usually arrive too late. Only a technical scan settles it.
Is the audit really free?
Yes, with no strings attached. The external scan requires no access to your site: it's done from the outside, like any visitor would. You receive the report whether you decide to work with me or not.
Do I have to change hosts?
No. Maintenance and monitoring work on your current hosting, whatever it is. Migrating to my managed infrastructure is an option if your host is holding you back, never a requirement.
My site is already infected. What do I do?
Call directly, it's faster than a form. Emergency cleanup includes quarantining the malicious code, rotating access credentials, invalidating stolen sessions and finding the point of entry. That last step matters most: without it, the infection comes back.
Why didn't my security plugin catch anything?
Because security plugins mostly compare files against known signatures. An infection that lives in the database, in a browser service worker, or that loads its code from an external source leaves nothing to compare. That's exactly what happened in the case above, despite an active security plugin.

Free audit

Let's check your site

Give me your site's address. Within 48 h you get a plain-language report: what's fine, what's not, and what's urgent. No access requested, no commitment.

The report will be sent there.

Your information is only used to reply to you. No newsletter, no sharing.