Secure your website
· by the Agence Web Premium team, Guéliz Marrakech
Direct answer: the vast majority of site hacks in Morocco are not targeted: they are robots that scan known vulnerabilities. Six simple measures block the essential, and a complete cleaning after infection costs between 1,500 and 4,000 MAD.
A hacked site doesn't just crash: it can be flagged as dangerous by Google, delisted, and used to send spam from your domain name.
How do I know if my site is hacked?
In short: Typical signs: unexpected redirects, unknown pages indexed by Google, alert in Search Console, or red warning in the browser.
Free checks to do immediately:
- Type
site:yourdomain.main Google and look for pages you never created. - Open Search Console, Security and manual actions section.
- Test your site in a browser in private browsing, from a mobile.
- Check the modification date of the files on your hosting.
Many infections are invisible to the owner: they only appear to visitors coming from Google, or only on mobile.
What are the most exploited vulnerabilities?
In short: Non-updated extensions, weak passwords, hacked themes, and no HTTPS. In this order.
- Outdated extensions. This is the number one cause on WordPress. A published flaw is exploited by robots in the hours that follow.
- Weak passwords. “admin/admin123” remains common. Brute force attacks test thousands of combinations per minute.
- Hacked themes and plugins. A “null” version downloaded for free very often contains a backdoor.
- No HTTPS. The identifiers circulate in clear text.
- Poorly partitioned shared hosting. An infected neighboring site can contaminate yours.
- No backup. It's not a flaw, but it's what turns an incident into a disaster.
What to do if the site is already infected?
In short: Do not delete randomly. Isolate, save current state, identify entry point, clean, then change all access.
- Put the site under maintenance to protect your visitors.
- Save the infected state. It contains the traces necessary to identify the entry point.
- Identify the flaw. Cleaning without filling it guarantees reinfection within a few days.
- Clean files and database, or restore a healthy backup from before the infection.
- Change all passwords: administration, database, hosting, FTP, messaging.
- Request a review in Search Console if Google has reported the site.
How can we prevent this from happening again?
In short: Automatic updates, strong passwords, two-factor authentication, outsourced daily backups and application firewall.
Our six standard measurements across all sites we deliver:
- Security updates applied automatically.
- Generated, unique passwords stored in a manager.
- Double authentication on administration.
- Daily backups stored off-server.
- Forced HTTPS on the entire site.
- Limiting connection attempts.
On a static site like the ones we build, the attack surface is drastically reduced: no database exposed, no extension to maintain.
How much does security cost?
In short: From 0 MAD for basic measurements to 1,500 MAD for a complete audit. Cleaning after infection costs 1,500 to 4,000 MAD.
Prevention is ten times cheaper than repair. Most essential measures cost nothing — they just need to be implemented.
Our security audit is free: we check versions, access, HTTPS and the presence of suspicious files, and we tell you what is urgent.
Risk level and remediation cost
| Situation | Risk | Correction | Cost |
|---|---|---|---|
| Extensions not up to date | Very high | Updates + automation | free at 800 MAD |
| Weak password | Very high | Manager + double authentication | free |
| Hacked theme | Pupil | Replacement with a legitimate version | 1,000 – 3,000 MAD |
| No HTTPS | Pupil | SSL certificate | free |
| No backup | Pupil | Outsourced daily backup | 300 – 600 MAD/year |
| Site already infected | Critical | Complete cleaning | 1,500 – 4,000 MAD |
Indicative prices as of October 4, 2026. Free audit.
Frequently asked questions
How do I know if my site is hacked?
Search for site:yourdomain.ma in Google, consult the Security section of Search Console, and test your site in private browsing from a mobile.
What is the main cause of hacks?
Extensions not updated on WordPress. A published flaw is exploited by robots in the hours that follow.
How much does it cost to clean an infected site?
Between 1,500 and 4,000 MAD depending on the size. The preliminary audit is free with us.
My site has been reported by Google, what should I do?
Clean the infection, close the vulnerability, then request a review in Search Console. The delisting is not permanent.
Are static sites safer?
Clearly. No database exposed, no extension to maintain: the attack surface is very small.
Should you pay for antivirus for your site?
Not necessarily. Basic measures — updates, strong passwords, backups, HTTPS — block the vast majority of attacks, and they're free.
How often to backup?
Daily, with off-server storage. A backup on the same server disappears with it.
Do you take care of post-delivery security?
Yes, it's included in the twelve months of monitoring: updates, backups and monitoring.
Free security audit
Send us your site address. We check known vulnerabilities and tell you what is urgent.


