Security & access
WordPress hacked: plan malware removal and verify the recovery
Preserve incident evidence, define cleanup scope, and check access, software, and business functions before reopening.
If you suspect your WordPress site has been hacked, preserve evidence, contain ongoing harm, and establish a trustworthy recovery path. Deleting an unfamiliar file or installing a scanner may remove a symptom while leaving the entry point and unauthorized access intact.
For a business site, malware removal should have a defined scope and acceptance criteria. “The scan is clean” and “the website is safe to reopen” are different conclusions.
Record the symptoms before changing the site
Save the affected URLs, screenshots, time and timezone, browser warnings, suspicious accounts, and messages from the host. Note recent updates and who had access. The WordPress incident FAQ recommends documenting symptoms and involving the hosting provider.
Ask for preservation of relevant access logs and account activity. Keep an isolated copy of the current files and database for investigation, clearly marked as potentially compromised. Prevent an automatic retention job from replacing your last useful recovery point with only recent infected copies.
If visitors are being redirected or exposed to harmful content, work with the host to restrict the affected service while preserving recovery access. A store processing suspicious transactions needs immediate help from its payment provider and an incident-response specialist.
Define the cleanup boundary
| Area | What to ask the responder |
|---|---|
| Files and database | Were both examined, including injected content and persistent access? |
| Related sites and accounts | Could other installations or shared credentials reintroduce the problem? |
| Initial access | What evidence identifies the entry point, and what remains uncertain? |
| Recovery and follow-up | Which restore point was used, what was validated, and who handles recurrence? |
A remote scanner sees a different surface from a filesystem or database inspection. Use results as evidence within the investigation; a tool’s lack of findings cannot prove every component is clean. Ask for the work performed and remaining limitations rather than a generic completion message.
Recover from sources you can trust
A responder may rebuild from verified software packages and inspected content, or restore an appropriate earlier backup. Neither route should silently discard newer orders or enquiries. Plan how business data will be preserved and reconciled.
Do not assume that a backup predating discovery predates compromise. The restoration guide explains how to isolate a recovery copy and check it before replacing the live site. Moving an infected archive to a new host can simply move the infection.
Close access and maintenance gaps
The WordPress hardening handbook treats security as risk reduction shared between the hosting environment and the application owner. Supported software, trusted installation sources, limited access, and independent backups all matter.
From a trusted device, coordinate credential rotation and session revocation with the responder. Review WordPress administrators, hosting users, transfer credentials, API keys, and delegated access. Remove unauthorized access and replace unsupported components implicated in the incident. Changing only the WordPress password may leave other routes open.
Record who owns future updates and monitoring. A cleanup subscription may not include correcting custom code, maintaining plugins, or investigating every related system.
Accept the result with business checks
Check the original symptoms across affected URLs and relevant visitor conditions. Then confirm login, forms, media, search, and the site’s revenue workflow in an appropriate controlled environment. Review remaining browser or search-service warnings through the issuing service’s review process after remediation.
Keep the incident timeline, cleanup report, recovery date, and follow-up owner. If customer or payment data may have been exposed, obtain qualified incident and legal guidance on the obligations for your situation. Reopening the home page does not resolve that separate question.