Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIf you suspect your WordPress site has been hacked, preserve a copy of its files and database first, then determine whether a verified clean backup is safer than repairing the current installation. Do not treat a malware scan or removal of visible spam as proof that the site is clean: compromised accounts, database content, hidden backdoors, or the hosting environment may still allow an attacker back in.
1. Check whether your WordPress site may be compromised
These signs warrant investigation, but none by itself proves exactly how the site was compromised or how far the intrusion spread. Wordfence advises treating a site as compromised when a warning sign appears until you can establish otherwise. See its hacked-site guidance and the WordPress.org hacked-site FAQ.
- Visitors are redirected to unfamiliar sites, or you see spam, phishing pages, or other content you did not publish.
- There are unfamiliar administrator accounts, or an account has permissions you did not grant.
- Files you do not recognize have appeared or changed unexpectedly.
- A browser, search service, or security scanner warns that the site may be unsafe or infected.
- You have lost access to the site, or your host has suspended it or reported malware.
Record what you noticed and when, including warning messages and affected URLs. That information can help your host or a cleanup professional investigate.
2. Preserve the current site and ask your host for help when needed
Before deleting files, editing the database, or restoring anything, make a copy of the site files and database and keep it separate from the working installation. Treat that copy as evidence and a possible source of recoverable material, not as a clean backup: it may contain the same malware. Wordfence recommends backing up before cleanup, and Sucuri advises backing up before database changes in its WordPress cleanup guide.
#1 Best Overall
Check your host’s backup and incident-response procedures. Contact support promptly if the site is suspended, you cannot access its files or database, or you suspect the issue involves other sites or the server. Ask what was detected, whether the host has a known-clean backup, and what access it can safely restore. Do not assume that a hosting backup is clean unless its date and condition have been checked.
3. Choose a recovery route
There is no universally safest choice between restoring a backup and repairing the existing site. Base the decision on how confident you are that a backup predates the compromise, what data or changes would be lost by restoring it, which customizations must be preserved, and whether the infection appears limited to files or may involve the database, accounts, or hosting environment.
Rank #2
| Route | Best fit | Main risks and checks |
|---|---|---|
| Restore a verified clean backup | You can identify a backup from before the suspected compromise and confirm it is suitable to restore. | Changes made since that backup may be lost. If the backup contains the compromise, restoration can bring it back. |
| Inspect and repair the current installation | No suitable clean backup exists, or you need to preserve newer site content and can carefully compare and replace affected components. | Missed malware or a backdoor can remain. Database or server-level issues may require more than file replacement. |
For a beginner, using a reputable scanner to identify suspicious items and compare files with trusted originals can help with triage, but it is not a complete restoration. Wordfence says its plugin can find and help repair many malicious files but does not fully restore a compromised site; database infections, hidden backdoors, abandoned installations, or server-level problems can require additional investigation. Its help guidance explains the limits and when to seek assistance.
If you cannot confidently decide whether a flagged file is malicious, do not delete or edit it on guesswork. Ask your host or a qualified WordPress incident-response professional. Expert help is especially sensible if the infection persists, returns after cleanup, or appears to involve multiple sites or the server.
4. Restore or repair without losing the path back in
If you are restoring a backup
- Confirm the backup date against the earliest likely sign of compromise and verify that the source is trusted.
- Keep the separate copy of the current, potentially infected site in case you need to recover newer legitimate content or provide evidence.
- Follow your host’s restoration procedure, then check accounts, files, and site behavior rather than assuming the restore alone addressed every access path.
If you are repairing files
- Identify the WordPress version and the affected themes or plugins. Compare suspected files with trusted copies matching the installed versions, and use official or otherwise trusted sources for replacement files.
- Replace compromised WordPress core files and reinstall affected themes or plugins from trusted copies where appropriate. Preserve custom and premium modifications rather than overwriting them blindly.
- When replacing core files, do not overwrite
wp-config.phpor thewp-contentdirectory as though they were disposable core files; they contain site configuration and content, as well as themes and plugins that need separate review.
If database content may be affected
Make another database backup immediately before editing records. Review suspicious pages, posts, options, and user data carefully, and test the site afterward. A suspicious code pattern alone is not proof of malware: functions such as eval or base64_decode can also have legitimate uses. Sucuri’s cleanup guide and WordPress.org’s FAQ outline file and database cleanup considerations.
Deleting a spam page or replacing one infected file may remove a visible symptom while leaving an account, database record, or backdoor that can restore it. Review the broader installation and investigate repeated reinfection rather than repeating isolated deletions.
Rank #4
5. Close access paths and harden the installation
Once you have a cleanup or restore plan, address the credentials and software that could let the attacker regain access. Wordfence and Sucuri describe common entry points and cleanup steps in their Wordfence cleanup guide, Wordfence response guidance, and Sucuri guide.
- Review administrator and other user accounts; remove or correct accounts you cannot explain.
- Reset exposed credentials for WordPress, hosting, SFTP/FTP, and related services. Use unique passwords and enable two-factor authentication for administrators.
- Update WordPress, themes, plugins, and relevant server software. Remove unused extensions and old WordPress installations, and avoid pirated software.
- Ask your host whether other sites in the same hosting environment or server need inspection, particularly if the cause or scope is unclear.
- Review whether backups, configuration files, or abandoned tools were exposed, and follow your host’s recommendations for securing the hosting account.
6. Verify the fix and request warning reviews
Run another security scan after cleanup and test important pages, forms, logins, and other site functions. A clean scan is useful evidence, but it does not by itself establish that the database, every backdoor, or the server is clean. If warnings persist or the site is reinfected, return to the host or a qualified professional for further investigation.
Recommended Free Tools
Best Value
Only after the technical cleanup, request a review from Google or another service that is warning visitors, using that service’s own process. If your host suspended the site, contact the host to ask about lifting the suspension after it verifies the fix. A review can clear an external warning; it does not clean the underlying site.
If your site is on WordPress.com
The file, database, and SFTP/FTP steps above mainly apply to self-hosted WordPress installations. WordPress.com has its own hacked-site support process: reset passwords, enable two-step authentication, reset SFTP/SSH credentials where applicable, review activity logs and scans, update extensions, and contact WordPress.com support. Available access and controls depend on your plan, so do not assume self-hosted database or file instructions apply to your account.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

