# PatientZero > PatientZero is a UK website and server malware removal service and security platform. It finds the first point of infection, removes every trace of malware from WordPress and PHP sites and Linux servers, and hardens them so it can't come back. Sold as a monthly subscription with unlimited malware removal, 24/7 monitoring, rapid emergency response and hardening. No long-term contract. Also written PatientZer0. Descriptor: Security · Malware Support. Tagline: Detect. Clean. Protect. Repeat. Positioning: Your server's immune system. ## Key facts - Service: unlimited malware removal, 24/7 monitoring, rapid emergency response and hardening for websites and VPS/shared servers - Platform: connects to servers over SSH, deploys a scan engine (/opt/patient-zero/scan-engine), runs Forensic scan (dfir-fast) and Malware sweep (malware-intelligence) across every site on the server, then Harden and Fix; Overview, Servers, Scans, Reports, Activity - Stacks: WordPress, WooCommerce, other PHP CMS (Joomla, Drupal), custom PHP; Linux VPS and shared servers incl. AWS Lightsail, cPanel, CloudPanel, Plesk, GoDaddy, SiteGround - Compromise response: webshells, reverse shells, cron/systemd persistence, rogue WordPress admins, SEO spam, redirects, card skimmers, fake maintenance pages, damaged WordPress core, overwritten wp-config - Evidence and reporting: timestamped removal log, evidence vault with file hashes, before/after verification, plain-English executive summary, technical findings and timeline, HTML report + ZIP - Area served: United Kingdom (remote service) ## Pricing - Single Site: £99/month + one-off £129.99 security audit and setup - Server / Multi-site: POA (whole VPS, every site) - Agency (white-label): from £299/month - Every plan: unlimited malware removal, no long-term contract, cancel any time; fair use applies to full server rebuilds - How to buy: book a demo or call (no self-serve checkout) ## Contact - Phone: 01932 593642 (+44 1932 593642) - Email: repair@patientzerosolutions.co.uk - Hacked right now: https://www.patientzerosolutions.co.uk/emergency ("Under attack?" instant callback on every page) ## Main pages - [Home](https://www.patientzerosolutions.co.uk/): website malware removal and protection - [Malware removal service](https://www.patientzerosolutions.co.uk/malware-removal) - [WordPress malware removal service](https://www.patientzerosolutions.co.uk/malware-removal/wordpress): Backdoors, injected code, rogue admins - [Hacked website repair](https://www.patientzerosolutions.co.uk/malware-removal/hacked-website-repair): Fix and recover a hacked website - [Blacklist removal](https://www.patientzerosolutions.co.uk/malware-removal/google-blacklist-removal): "This site may be hacked" warnings - [Server malware removal](https://www.patientzerosolutions.co.uk/malware-removal/server-malware-removal): UK VPS and Linux server clean-up - [WooCommerce and skimmers](https://www.patientzerosolutions.co.uk/malware-removal/woocommerce): UK shop and checkout malware - [CloudPanel malware removal](https://www.patientzerosolutions.co.uk/malware-removal/cloudpanel): Every site user and the panel itself - [AWS Lightsail malware removal](https://www.patientzerosolutions.co.uk/malware-removal/aws-lightsail): Bitnami WordPress instances and the AWS side - [Emergency hacked website help](https://www.patientzerosolutions.co.uk/emergency) - [Platform](https://www.patientzerosolutions.co.uk/platform) - [Forensic Scan](https://www.patientzerosolutions.co.uk/platform/forensic-scan): dfir-fast: indicators of compromise and persistence - [Malware Sweep](https://www.patientzerosolutions.co.uk/platform/malware-sweep): Signatures and heuristics across every site - [Hardening](https://www.patientzerosolutions.co.uk/platform/hardening): Playbooks that lock the door behind us - [Monitoring](https://www.patientzerosolutions.co.uk/platform/monitoring): 24/7 scheduled scans and alerts - [Reports](https://www.patientzerosolutions.co.uk/platform/reports): Evidence, timelines and audit trail - [For Agencies](https://www.patientzerosolutions.co.uk/solutions/agencies): White-label, whole-server protection - [For Hosting providers](https://www.patientzerosolutions.co.uk/solutions/hosting-providers): Server-side detection across tenants - [For E-commerce](https://www.patientzerosolutions.co.uk/solutions/ecommerce): Protect checkout and customer data - [For Small businesses](https://www.patientzerosolutions.co.uk/solutions/small-business): Security and hosting help for your own website - [Pricing](https://www.patientzerosolutions.co.uk/pricing) - [Get protected (onboarding wizard)](https://www.patientzerosolutions.co.uk/get-protected) - [Case studies](https://www.patientzerosolutions.co.uk/case-studies) - [Security and trust](https://www.patientzerosolutions.co.uk/security) - [About](https://www.patientzerosolutions.co.uk/about) - [Contact](https://www.patientzerosolutions.co.uk/contact) ## Guides - [How Long Does Website Malware Removal Take?](https://www.patientzerosolutions.co.uk/resources/how-long-does-malware-removal-take): What decides how long a malware clean-up takes, what the stages are, and how long to expect for a Google warning to clear once the site is clean. - [Server Malware vs WordPress Malware: What Is the Difference?](https://www.patientzerosolutions.co.uk/resources/server-vs-wordpress-malware): Why a clean WordPress site can still sit on an infected server, how to tell which kind of infection you have, and what changes about the clean-up. - [Webshells Explained: How Attackers Keep Access to Your Server](https://www.patientzerosolutions.co.uk/resources/what-is-a-webshell): A webshell is a small script that gives an attacker a remote control panel on your server. Here is how they hide, how to find them and how to remove them without leaving a way back in. - [White-Label Website Security for Agencies: How It Works](https://www.patientzerosolutions.co.uk/resources/white-label-website-security-agencies): What white-label website security means for a web agency, how the service fits around your client relationships, and what to check before you resell security under your own brand. - [Why Malware Keeps Coming Back: Cron Jobs, Backdoors and Re-infection](https://www.patientzerosolutions.co.uk/resources/malware-keeps-coming-back): If malware returns hours or days after a clean-up, something on the server is putting it back. This guide explains the persistence mechanisms behind re-infection, using a real (anonymised) incident. - [Malware Removal Cost in the UK: One-Off Clean-Up vs Unlimited Plans](https://www.patientzerosolutions.co.uk/resources/malware-removal-cost-uk): How UK malware removal is priced, what pushes the cost up, and how to compare a one-off clean-up with an unlimited monthly plan without being caught out by re-infection fees. - [Remove Japanese SEO Spam from a Hacked Website](https://www.patientzerosolutions.co.uk/resources/seo-spam-hack-removal): Japanese SEO spam and pharma SEO hacks fill Google with fake pages under your domain while the site looks normal to you. Here is how to confirm the keyword hack, clean it properly and recover your search listings. - [Malicious Redirect Hack: Why Your Site Sends Visitors to Scam Pages](https://www.patientzerosolutions.co.uk/resources/website-redirect-hack): Visitors say your site sends them to fake prize, tech-support or crypto pages, but it works fine for you. This guide explains how redirect malware decides who to target, where it hides and how to remove it. - [AWS Lightsail WordPress Hacked? How to Contain and Clean It](https://www.patientzerosolutions.co.uk/resources/aws-lightsail-wordpress-hacked): A practical containment and clean-up guide for hacked WordPress instances on AWS Lightsail: snapshots, firewall lockdown, Bitnami file paths and the checks that stop re-infection. - [WooCommerce Card Skimmers: How to Detect and Remove Checkout Malware](https://www.patientzerosolutions.co.uk/resources/woocommerce-card-skimmer-removal): Card skimmers hide in your WooCommerce checkout and quietly copy customer payment details. Learn the warning signs, where skimmers hide, how to remove them and what your obligations are afterwards. - [Hacked cPanel or CloudPanel Server: A Clean-Up Walkthrough](https://www.patientzerosolutions.co.uk/resources/cpanel-cloudpanel-malware-cleanup): A practical walkthrough for cleaning malware from a cPanel or CloudPanel server: where infections hide on each panel, the commands to find them, and how to stop them returning. - [WordPress Hardening Checklist for 2026](https://www.patientzerosolutions.co.uk/resources/wordpress-hardening-checklist): A practical, prioritised WordPress hardening checklist covering accounts, updates, file permissions, server configuration, backups and monitoring, with the exact settings we apply on client sites. - [Security Plugin vs Server-Side Malware Scanning: What Plugins Miss](https://www.patientzerosolutions.co.uk/resources/security-plugin-vs-server-scanning): Security plugins are useful, but they run inside the thing they are protecting. Here is exactly what they can and cannot see, and where server-side scanning fills the gap. - [Website Hacks and UK GDPR: When a Hack Becomes a Reportable Breach](https://www.patientzerosolutions.co.uk/resources/website-hack-gdpr-breach-reporting): Not every website hack is a reportable breach, but many are. How to decide, what the ICO 72-hour clock means, and the forensic evidence you need to make the call. - [Emergency Malware Removal: What to Do in the First Hour](https://www.patientzerosolutions.co.uk/resources/emergency-malware-removal): Your site has just been hacked. This is the calm, practical plan for the first hour: what to do, in what order, and what not to touch. - [Website Malware Statistics: What the Data Actually Shows](https://www.patientzerosolutions.co.uk/resources/malware-statistics): A sober look at what well-known, attributable sources say about website attacks and malware, where the numbers are weaker than they look, and what to do with them. - [How to Remove a Google Blacklist Warning](https://www.patientzerosolutions.co.uk/resources/remove-google-blacklist-warning): How to get rid of Google's "This site may be hacked" and "Deceptive site ahead" warnings: confirm the problem in Search Console, clean the site properly and request a review. - [12 Signs Your Website Has Been Hacked](https://www.patientzerosolutions.co.uk/resources/signs-your-website-is-hacked): From redirects and Google warnings to unknown admin accounts and rogue cron jobs, these are the 12 signs we see most often on hacked websites, and how to check for each. - [VPS Security: Why One Hacked Site Infects the Rest](https://www.patientzerosolutions.co.uk/resources/vps-server-security): On most VPS servers, sites share a user, a PHP pool and a database login. That is why one hacked site infects the rest, and why cleaning one site at a time never works. - [What Is Malware? A Plain-English Guide for Website Owners](https://www.patientzerosolutions.co.uk/resources/what-is-malware): Website malware is code planted on your site or server to serve the attacker, not you. Here is what it looks like, how it gets in and what to do about it. - [Why Malware Attacks on Websites Are Increasing](https://www.patientzerosolutions.co.uk/resources/why-malware-attacks-are-increasing): Website attacks are cheaper, faster and more automated than ever. Here are the five forces behind the rise, and what each one means for how you protect your site. - [WordPress Malware Removal: A Step-by-Step Guide](https://www.patientzerosolutions.co.uk/resources/wordpress-malware-removal): A practical, step-by-step process for removing malware from a hacked WordPress site, from containment and evidence to database clean-up, root cause and hardening. - [wp2shell Removal: Cleaning WordPress Webshell Infections](https://www.patientzerosolutions.co.uk/resources/wp2shell-removal): wp2shell is the pattern of turning WordPress admin or plugin access into a PHP webshell on the server. Here is how it works, how to find it and how to remove it properly. ## FAQs ### What does unlimited malware removal mean? If any site on your plan gets infected, we clean it, as many times as it takes, at no extra cost. Fair use applies only to full server rebuilds. ### My site is infected right now. What should I do? Call 01932 593642 or use the Under attack? button for an immediate callback. Don't delete files yet, change hosting and admin passwords from a clean device, and take a backup snapshot. ### I only have one business website. Is PatientZero for me? Yes. PatientZero protects single business websites as well as whole servers. The Single Site plan is £99 a month plus a one-off £129.99 security audit and setup, and includes malware removal whenever it is needed, 24/7 monitoring and help with your hosting company. No technical knowledge needed. ### Do you protect one site or every site on my server? Both. Single Site covers one website; Server / Multi-site covers the whole VPS or shared server with every site on it. ### How much does it cost? Single Site is £99 a month plus a one-off £129.99 security audit and setup. Server / Multi-site is POA. Agency (white-label) plans start from £299 a month. No long-term contract. ### How do you stop the malware coming back? We find and close the way in: webshells, cron jobs, rogue admins and backdoors are removed, then the server is hardened and monitored 24/7. ### Which platforms do you support? WordPress and WooCommerce first, plus Joomla, Drupal and custom PHP, on Linux VPS and shared servers including AWS Lightsail, cPanel, CloudPanel, Plesk, GoDaddy and SiteGround. ### Is there a contract? No. Monthly plans, cancel any time. ### Can agencies white-label PatientZero? Yes. The Agency plan is fully white-label with whole-server monitoring, client reports under your brand and priority response.