Maintenance and recovery
Hacked WordPress website: what to do first
Unexpected redirects, advertisements or administrator accounts require incident containment first. Deleting one suspicious file often does not resolve the underlying compromise.
Record symptoms and limit damage
Record affected URLs, observation times, redirect destinations and recent changes. Preserve server logs and an incident-state copy separately from clean backups. If visitors are at risk, agree a safe maintenance page or temporary access restriction with the host. Do not open suspicious downloads or enter credentials through a suspect page. Identify who is authorised to perform recovery.
Investigate the scope beyond one file
Review WordPress files, plugins, themes, uploads, database content, administrator accounts and scheduled tasks. Check other projects in the same hosting account. Comparison with official files of the same version can identify modifications, but custom code needs separate review. Automated scanner results support an investigation; they do not prove complete cleanup.
Verify the backup and restoration
Select a backup preceding the first symptoms and still check its cleanliness. Restore into a separate environment and test the database, files, login, forms and integrations. A backup can restore a vulnerable plugin too, so fix the entry point before reopening. Agree how to preserve orders or enquiries created after the backup date.
Remove the cause and review access
Restore required system files from trusted sources, update supported components and remove unused or untrusted plugins. Review accounts, permissions, server components and exposed secrets. Once the environment is remediated, rotate relevant passwords, keys and WordPress session secrets; add stronger login protection. Changing a password while malicious code remains may not be sufficient.
Check the public site and search status
Test multiple devices for remaining redirects or unexpected records. Review sitemaps, canonicals and spam URLs. Check Search Console security issues and manual actions where applicable, and follow the indicated review process only after remediation. Search results do not update immediately. An SEO check is not a malware audit and cannot establish system security.
Agree prevention and monitoring
After recovery, monitor logs, new accounts, file changes and unusual traffic. Maintenance should include updates, separate backups, restoration tests and a responsible owner. For an enquiry, provide the domain, symptoms, platform, host and backup availability. Do not put passwords in an ordinary contact form; agree secure access transfer. Scope and price depend on the incident and recovery options and need assessment first.
Quick checklist
- Symptoms, logs and incident copy preserved
- Wider scope and clean backup checked
- Entry point fixed and access reviewed
- Monitoring and restoration testing agreed
Apply this to your needs
Sources and further instructions
Apply this to your project.
Send your website URL or describe your needs. We can establish the problem and an appropriate scope first.
