Before you start
- Identified administrator accounts and protected access.
- A separate backup and several recovery dates.
Preserve incident evidence before deleting files. A recent backup may already be infected.
Protect all important access
Website security extends beyond WordPress to hosting accounts, administrator email and connected services. A stolen password can bypass a security plugin. Assign individual accounts and review access whenever a provider or team member changes.
- Use unique passwords and additional authentication where available.
- Reserve administrator privileges for people who need them.
- Remove obsolete access after checking ownership of content and connected services.
Maintain components and backups
Keep WordPress, themes and plugins maintained through a tested update process. Modified commercial packages and unknown download sources increase risk. A backup should remain accessible if hosting or account access is compromised; test restoration on a copy.
- Remove unused plugins and replace abandoned ones.
- Keep several backup dates: the most recent backup may already contain an infection.
- Maintain a separate protected copy of both files and database.
Recognize an incident
Unknown redirects, new administrators or unusual files justify investigation. Slowness alone does not prove hacking. Record observations and circumstances without following suspicious links or entering credentials on unexpected pages.
- Keep affected URLs, dates, messages and screenshots without unnecessary private details.
- Check administrator accounts and recent changes.
- For a store handling customer information, assess connected services and applicable obligations with the responsible people.
Contain damage and preserve evidence
For a likely infection, arrange appropriate temporary access restrictions during recovery. Preserve the compromised state and logs before cleaning; they can help identify the cause. Avoid mass deletion that removes evidence or makes reconstruction impossible.
- Keep a separate copy clearly identified as suspicious.
- From a trustworthy device, secure essential access and revoke suspicious credentials.
- Do not immediately restore a backup without checking its date and the vulnerability that allowed the infection.
Resolve the cause and verify recovery
Scanners can flag anomalies without finding every persistence mechanism. Cleaning may require investigation of files, database content, accounts and scheduled tasks. Replacing components with official versions does not necessarily remove all malicious data.
- Compare plugins, themes and custom changes with legitimate sources.
- Correct the identified entry point and assess other sites sharing the affected access.
- Check pages, forms and payments after intervention and confirm suspicious redirects are gone.
Monitor after reopening
Keep incident records and watch for returning files, accounts or redirects. Reinfection after restoration can indicate an unresolved cause. No plugin can promise absolute security.
- Review access and required updates after recovery.
- Check the backups and alerts that are actually configured.
- For a complex infection, use our hacked-site recovery service rather than improvised cleanup.
Related service
Website malware removalOfficial documentation
Labels and options vary with versions, plugins and your account. Refer to publisher documentation for your configuration.