Hosting account suspended for malware: how to get your WordPress site back
A host suspends an account to stop a hacked site harming others, and restores it when you show the cause is gone. Ask the host for three things. They are the list of what it found, access to the files and the database, and the steps of its review.
- By
- WP Ministry
- Published
In short
- Reply to the host's notice before you touch the site. Ask for the list of what it found, what access you still have, and what its review needs to see.
- Take a full copy of the files and the database before any cleaning. A suspended account keeps its data. A terminated one does not.
- Start from the host's list and do not stop at it. A scanner lists what it recognized, and one missed backdoor brings the infection back.
- A backup from before the break-in is quick to restore and loses everything added since. It also restores the hole, so update and change passwords before you ask for the review.
- Answer in the host's own ticket with what you removed, what you updated and which passwords you changed.
- If you move to another host, rebuild there from clean copies. An account copied as it is takes the infection with it.
Your host suspended the account to stop a hacked site from harming its other customers and your visitors. It lifts the suspension once you have shown that the cause has been removed. You need three things from the host to get there: the list of what it found, access to the files and the database, and the steps of its review.
Ask for all three in your first reply. Then take a copy of everything, clean the site, and answer in the same ticket with what you did.
What a suspension is, and why hosts do it
A suspension switches an account off without deleting it. cPanel, the control panel many shared hosts run, documents what its own suspension does. Visitors get an account suspended message in place of the site. The owner cannot log in to the panel. FTP users and database users cannot log in, scheduled jobs stop, and the account's mailboxes can neither send mail nor collect it. The limits stay until the host lifts them. Termination is a different act: the same documentation says it permanently deletes all of the account's data from the server.
Hosts give two reasons. GreenGeeks says malware on one site is a risk to every other site on the same server, and calls suspension a precaution, not a punishment. The second reason is mail. WordPress's documentation notes that hacked sites are used to send spam, and that blacklists then flag the server's IP address, which is often the address its other mail leaves from. Bluehost's acceptable use policy says an account that gets its IP space blacklisted is suspended or terminated at once. DreamHost's says it may suspend or terminate a service to protect its IP addresses.
What hosts publish about their own practice
Each row comes from that company's own help pages or policies.
| Host | What its pages say happens | What its pages say comes next |
|---|---|---|
| Bluehost | Lists non-payment, malware, phishing and policy violations as reasons. The page reads "This account has been suspended." and carries a login link. Sometimes one directory is suspended and not the whole account. | Logging in shows the reason and instructions. For malware it writes a malware.txt or scanreport.txt report into the site's main folder, reached through File Manager. Each case is reviewed individually. |
| HostGator | Scans the sites on its servers. Spam links, deceptive content or phishing pages get the account suspended. | It usually emails the reason to the account's primary address. It says it offers no direct malware removal, and asks you to change nothing while a site is under investigation. |
| SiteGround | The site shows "The web service to this account has been limited temporarily", either because it was hacked or because it passed a resource limit. | "Get Limit Removed" leads to the Client Area, which holds the details of the limit. |
| Hostinger | A plan is suspended when a violation of its terms is detected. The websites stop working and cannot be managed from the dashboard. | An email names the suspended services, the specific reason, and the documents or actions needed to ask for the suspension to be lifted. |
| GreenGeeks | Names malware as the most common reason. Says it tries to take the least action that stops the problem while other services stay online. | A notice in the account, with a subject such as "GreenGeeks Malware Notice", says what is required. You reply in that same ticket with every change you made. Its phone and chat staff cannot lift it. |
| DreamHost | Says the customer is responsible for the software on the account. It may assist and is not obliged to. | After cleaning, you contact support and ask for the site to be scanned again. |
| IONOS | Does not close the account. It locks each file that holds malicious code by removing permission to read it, and emails you. | You clean or delete each file and set its permissions back. A file that still holds malicious code is locked again automatically. |
| Kinsta | Describes no suspension. Its security pledge says it works with the customer to try to undo the damage when a WordPress site is hacked there, under stated conditions. | It reinstalls WordPress, removes infected plugins and themes, and gives the customer steps to finish. |
Three things follow.
- The notice is the source. It says why, and usually what the host needs. If you have no email, look in the spam folder, in the host's dashboard, and for a login link on the suspension page.
- What stays open differs from host to host, from nothing at all to everything except a few locked files. Ask.
- None of these pages sets a number of incidents that ends an account. The policies are broader. Bluehost's and GreenGeeks' acceptable use policies allow suspension or termination, with or without notice, for any violation. Both say that failing to respond to an email from the host within 48 hours may itself lead to suspension or termination.
So answer the notice the day it arrives, even if all you can say is that you are working on it.
Reply to the host first
Reply to the notice itself, in the same ticket or thread. GreenGeeks says outright that a second ticket opened to speed things up slows its answer, and that the matter is resolved only in the original notice.
Here is a message to copy. Replace the words in capitals.
Subject: Re: SUBJECT OF THE NOTICE (DOMAIN)
I own the hosting account for DOMAIN. I have your notice of DATE and I am
working on it now.
To clean the whole site, and not only the files already found, please
send or confirm:
1. The scan report, or the full list of flagged files and URLs, and
whether the scan had finished when that list was made.
2. The date and time of the suspension and the reason recorded for it:
malware, phishing, outgoing spam or a complaint.
3. What I can still use while suspended: the control panel, the file
manager, FTP or SFTP, SSH, and the database. If any of these is
closed, how I get the access needed to clean the site, or a full
backup of the account as it stands.
4. Whether you hold backups of this account, the date of each, and
whether I can restore or download one myself.
5. The access logs for the site, as far back as you keep them.
6. What you need to see to lift the suspension, where I send it, and
whether there is a deadline.
7. Whether other sites or mailboxes on the account are affected.
I will reply in this ticket with everything I change.Question 1 matters because a list can be partial. IONOS, for one, says the email it sends does not hold the complete list of infected files if its scan is still running. Question 4 matters because a host's backups may not reach back far enough. DreamHost says its backups are kept for only a few days. Copies held only in the hosting account are also out of reach while it is suspended, which is the case for sending scheduled backups off the server once this is over.
If this notice is the first you have heard of a break-in, the hacked site runbook covers the first hour, including who else to tell.
What you can still reach while suspended
It depends on what the host switched off.
| What the host did | What is usually open | How you get the copy |
|---|---|---|
| Suspended the whole account, the way cPanel does it | Nothing. The panel, FTP and the database are all closed. | Ask the host for temporary access, or for a full backup of the account as it is. |
| Closed the website, or one directory, and left the account running | The dashboard, the file manager, FTP or SFTP and the database | Take it yourself, as below. |
| Locked individual files | Everything. A locked file cannot be read until you change its permissions. | Take it yourself. The locked files are part of the record. |
On a host that locks files and leaves the account open, the site may stay up while some addresses are refused. How to fix the 403 Forbidden error covers the other causes of that message.
Step 1: Save the notice and the report
Keep the host's email and download its scan report before anything else. On Bluehost that is
malware.txtorscanreport.txtin the site's main folder. At Namecheap it is a file whose name beginsscanreport, in the account's home folder. On IONOS it is a log in thelogs/forensicfolder. Switch on hidden files in the file manager if you cannot see it.Step 2: Download every file
WordPress's documentation says a file backup is everything in the WordPress directory, subdirectories included, and the
.htaccessfile. With cPanel, the Backup screen has "Download a Full Account Backup", and under Partial Backups a "Home Directory" download, if your host has left that screen switched on. Otherwise connect over SFTP, show hidden files, and download the whole site folder.Step 3: Export the database
The database holds your posts, pages, users, orders and settings, and no file copy includes it. In cPanel's Backup screen, select the database's name under Databases. In phpMyAdmin, select the database, open the "Export" tab, keep "Quick" selected and select "Go".
Step 4: Check the copy and label it
Open the archive and look for
wp-config.phpand thewp-contentfolder. Open the.sqlfile in a text editor and check that it names your tables, such aswp_posts. Label both as infected, with the date. Keep them off the server, and never restore them over a working site.
If the host leaves SSH open and WP-CLI is installed, two commands run from the site's main folder make the same copy.
wp db export ~/infected-database.sql
tar -czf ~/infected-site.tar.gz .The first writes the database to a file in your home folder, using the database details in wp-config.php. It goes there, and not into the site's folder, because a file in the site's folder can be downloaded by anyone who guesses its name. Where the host has locked the database users, the export fails until access is restored. The second packs the site's folder into one archive, also in your home folder: -c creates it, -z compresses it with gzip and -f names the file.
If tar answers "Permission denied" for some files, the host has locked them and they are not in the archive, although an archive is still written. Those are likely to be the flagged files, so ask the host to make them readable or to send its own copy. If the site's main folder is itself your home folder, ask the host for a folder outside the one it serves and write both files there. Download the archive and the .sql file, then delete both from the server.
Clean it: what is particular to a suspension
The cleaning itself is the same work as for any hacked site, and how to remove malware from a hacked WordPress site has every step. Three things are different when a host is waiting to scan the result.
Start from the host's list, and do not stop at it
The list tells you where the attacker has been. It is a list of what a scanner recognized, not of every file that was changed.
- Namecheap's guide to its own scan report lists a result called "Scan Timeout" for a scan that was interrupted, and another for pattern matches that it describes as false positives.
- Bluehost's page on its report says that a site which keeps getting reinfected may have a backdoor that the malware left behind.
- DreamHost says there is no single-step, foolproof way to find backdoors, and tells customers to go through all of the files under the compromised user, not one site's folder.
A backdoor that is missed lets the attacker put the flagged files back, and the next scan suspends the account again.
Choose a route, and know what each costs
| Clean in place | Restore an older backup, then update | |
|---|---|---|
| What you keep | Everything up to today | Only what existed on the day of the backup |
| What it costs | Time and skill. Every file and the database have to be checked. | Orders, posts, comments and form entries added since. HostGator's page says changes made after the backup date have to be made again. |
| Where it fails | One missed backdoor | A backup taken after the break-in, which Google's guidance tells you to rule out first |
| What it needs from the host | File and database access while suspended | A backup old enough, restored with the site still closed to visitors |
Restore the files and the database from the same point in time. Hostinger's page on reinfection says that restoring only the files can leave an infected database in place.
A restore alone leaves the way in open
A backup from before the break-in holds the same out-of-date plugin, the same passwords and the same keys the attacker used. HostGator's page says so plainly: after a restore, the site will likely have the same vulnerabilities that let it be compromised. Google's guidance for a restored site lists what still has to follow. Install every update, remove software the site no longer uses, correct the vulnerability, and change all the passwords again.
Do that before you ask for the review, while visitors are still kept out. A restored site that goes back online unchanged can be broken into the same way.
Ask for the review
Reply in the original ticket. Say what was done, and say what you could not establish.
Subject: Re: SUBJECT OF THE NOTICE (DOMAIN), ready for review
The site is ready to be scanned again. This is what was done.
Files on your list: each one deleted, or replaced with a fresh copy
from its source. LIST THEM.
Found beyond your list: FILES, USERS, SCHEDULED JOBS, DATABASE ENTRIES,
OR NOTHING FURTHER.
Route: CLEANED IN PLACE, OR RESTORED THE BACKUP OF DATE AND UPDATED.
Way in: THE OUT-OF-DATE PLUGIN, THE STOLEN PASSWORD, OR NOT ESTABLISHED.
Closed by: THE UPDATE, THE REMOVAL OR THE NEW PASSWORD.
Updated: WordPress, every plugin and every theme, on DATE.
Passwords changed: hosting account, FTP and SFTP, database and every
WordPress administrator. Secret keys replaced.
Other sites on the account: CHECKED, OR NONE.
Please scan the account again and tell me what, if anything, is still
flagged.Ask only when the whole account is clean. A second scan that finds the same code costs you another round.
If Google has also flagged the site, that is a separate review which the host's decision does not settle: once the site is clean, select "Request Review" in Search Console's Security issues report, which how to check whether your WordPress site has been hacked shows you how to read.
If the host will not restore the site, or the deadline is short
Your site is two things: the files and the database. With a copy of both, it can run on any host. That is the reason to ask for a full backup of the account early, while it is only suspended.
If the host refuses both access and a backup, ask in writing what its terms give you. Keep the plan paid in the meantime, because an unpaid plan has a clock of its own. Hostinger, for one, says a plan canceled for non-payment is permanently deleted after 30 days.
Moving does not clean anything. An account copied to a new host as it is takes every backdoor with it, and the new host may find them. Kinsta's documentation says its migrations include a scan of all the site's files, and that it pauses a migration when the site turns out to be infected. Move cleanly instead:
Step 1: Start with a new WordPress on the new host
Google's guidance is to make a clean installation and then bring across only content known to be clean. Install WordPress fresh, with a new database, a new database password and new secret keys.
Step 2: Install plugins and themes from their sources
Take each one from WordPress.org or from its author. Do not copy the
pluginsorthemesfolders from the infected copy.Step 3: Bring the uploads across after checking them
Copy
wp-content/uploadsfrom the infected copy only after you have removed every PHP file in it that no plugin accounts for.Step 4: Import the database, then check it
Import your export into the new database. Before anything else, open the Users screen and delete every administrator nobody created, then look through posts, pages and widgets for scripts and links you did not write. WordPress's documentation says that when the domain stays the same, the database can be moved as it is, with
wp-config.phpholding the new database's name and user.Step 5: Change the DNS when the copy is clean
Point the domain at the new host only after the new site has been checked. The website migration checklist covers the day of the move, and what people forget, such as mailboxes that live at the old host.
Google's guidance also names a move as a way to get help: transfer the site to a host that specializes in recovery and recovers it as part of the transfer. Ask a new host before you sign up whether it does that.
Our malware removal service is a one-time clean-up with hardening, a blacklist removal request and a written report. Our WordPress migration service copies the site to the new host and tests the copy there, and only then is the DNS changed.
Suspensions that are not about malware
The same suspension page appears for other reasons, and the notice tells them apart. A notice about phishing pages or outgoing spam is this page's case: on a site that does neither on purpose, someone else put them there.
| What the notice says | What it is | What lifts it |
|---|---|---|
| An overdue invoice, a failed payment or a chargeback | Billing. HostGator calls non-payment the most common reason for a suspension. | Paying what is owed. Bluehost says a shared account comes back only after every past-due invoice on the billing account is paid. |
| Resource usage, CPU, memory, bandwidth or server performance | The plan's limits. Bluehost and SiteGround both describe limiting a site for this. | Bringing usage down or changing plan. See how to fix WordPress hosting problems and the 503 error. Kinsta lists a site that loads unusually slowly as one sign of a compromise, so rule that out. |
| A complaint or a policy violation that names content | The host's acceptable use policy | Removing the content, or answering the complaint in the ticket |
| No suspension page: the domain does not load at all | Possibly the domain, not the hosting. Hostinger's documentation describes a registry putting a domain on hold when it is reported for phishing or malware. | Removing the content, then asking the registry to lift the hold |
Common questions
Will the host delete my site while it is suspended?
A suspension by itself deletes nothing. cPanel's documentation describes it as limits that stay until the host lifts them, and describes termination as the act that permanently deletes the account's data. Hosts' policies do allow termination, so take your copy early and answer every message from the host.
Can the host clean the site for me?
It depends on the host. HostGator says it offers no direct malware removal. DreamHost offers a repair service that customers can request. Kinsta cleans hacked WordPress sites for its customers under the conditions of its security pledge. Ask yours what it does, and what it leaves to you.
I deleted every file on the list and the account was suspended again. Why?
Because the list was not the whole infection. Bluehost's page on its scan report says a site that keeps getting reinfected may have a backdoor left behind. Go through the whole account, including other sites on it, the database and the administrator accounts.
Does a suspension stop my email?
It can. Under cPanel's suspension the account's mailboxes cannot send mail or collect it, and what happens to incoming mail is a setting the host chooses. Where only the website is closed, mail may keep working. Ask the host, and if mail matters to the business, say so in your first reply.
How long does a host take to lift a suspension?
None of the hosts named on this page promises a time. GreenGeeks gives 30 to 60 minutes as its typical response to a compliance ticket, and says a reply can be delayed by 24 to 72 hours. It also says that repeated updates with nothing new in them lengthen the wait, so send one complete message.
- Cost guideWhat WordPress malware removal costs: how it is priced and what a cleanup should include
- ResourceHacked WordPress site: a runbook for the first hour
- GuideHow to audit a WordPress site for security weaknesses
- GuideHow to remove malware from a hacked WordPress site
- GuideHow to set up two-factor authentication in WordPress
- GuideWordPress search results pages (/?s=) in Google and Search Console: what they are and what to do

