Why the Order of Steps Matters
A hacked site is a situation where doing things in the wrong order actively makes it worse — restoring from a backup before finding the entry point just gets the site reinfected, and leaving the site live while investigating lets malicious code keep affecting visitors, search rankings, and potentially spreading further into the server. The sequence below is built specifically to avoid those mistakes.
Step 1: Contain It — Take the Site Offline
Put the site into maintenance mode, or if the compromise is serious (malware actively serving to visitors, defaced content, spam injection), take it fully offline at the hosting level. This stops the immediate damage — to visitors, to your search rankings, and to your reputation — while you work through the rest of the process without the pressure of live traffic hitting a compromised site.
Step 2: Change Every Password, Everywhere
Treat every credential associated with the site as compromised: WordPress admin accounts, the database user, the hosting account login, and FTP/SFTP credentials. Change all of them before doing anything else, from a device you trust. If an attacker had access to any of these, leaving even one unchanged gives them a way back in during cleanup.
Step 3: Identify the Entry Point
Before restoring or cleaning anything, figure out how the attacker got in — otherwise you're cleaning up the same door they'll walk through again. Check your hosting account's access and error logs around the time the compromise likely started, and audit every plugin and theme for outdated versions with known vulnerabilities, which is the single most common entry point for WordPress compromises. A security scanner like Sucuri or Wordfence can identify known malware signatures and often point directly to the affected file.
Step 4: Clean the Site — Backup or Manual Removal
If you have a backup from before the compromise, and you've confirmed the entry point is now understood and will be closed, restoring that backup is the fastest and most reliable path back to a clean site. If no clean backup exists, or you need to preserve legitimate content created after the infection, manual removal is necessary: this means going through theme and plugin files for injected code, checking for unfamiliar admin users, and scanning the database for injected spam content or redirect scripts.
Step 5: Close the Entry Point and Harden
Update every plugin, theme, and WordPress core to their latest versions — if the entry point was an outdated plugin, updating it (or removing it if it's abandoned/unmaintained) is what actually prevents reinfection. Remove any plugins or themes you're not actively using; unused, outdated software is attack surface with no offsetting benefit. Add server-level hardening — a web application firewall, login attempt limiting, and file integrity monitoring — so a similar attempt is caught before it succeeds next time.
Step 6: Address Google Safe Browsing Flags
If the site was serving malware or spam to visitors, Google Safe Browsing or Search Console may have flagged it, which can show visitors a warning page even after cleanup. Once you've confirmed the malicious code is fully removed, submit a reconsideration request through Google Search Console — this typically clears within a few days.