Discovering a hacked site is stressful, but a methodical process gets you back online safely.
1. Contain the Damage
Change all passwords immediately — WordPress admin, database, FTP, and hosting account — in case credentials were compromised.
2. Identify the Scope
Check for unfamiliar admin users, unexpected files, and recently modified core files to understand what was actually affected.
3. Restore From a Clean Backup
If you have a backup from before the compromise, restoring it is usually faster and safer than manually cleaning an infected site.
4. Clean and Update Everything
If no clean backup exists, remove malicious code, then update WordPress core, themes, and every plugin to their latest versions.
5. Investigate the Entry Point
Understanding how the attacker got in — an outdated plugin, a weak password — prevents the same breach from happening again.
6. Add Ongoing Protection
A web application firewall and regular malware scanning going forward significantly reduce the odds of a repeat incident.
Español
Deutsch