Skip to content

WordPress security and hacked sites

How to tell whether a WordPress site has been broken into, what to do in the first hour, how to clean it, and how to close the ways in so that it does not happen again.

By
WP Ministry
Published

There are two kinds of security work, and which one you need depends on what you are looking at.

Something looks wrong now. Do not delete anything yet. Check whether the site has been hacked, or run the check from outside, which reads the site as a stranger is served it. If a check comes back positive, follow the first-hour runbook, then the full cleanup.

If you already know what you are looking at, go straight to it: visitors sent to another site, a red warning in the browser, spam pages under your name in Google, an administrator nobody created, a hosting account suspended for malware, or malware that comes back after every cleanup.

Nothing is wrong and you want to keep it that way. The security guide puts the work in order of what it prevents. The measures that stop the most for the least effort are two-factor sign-in, limits on password guessing, correct file permissions, and updates applied safely and on time. An audit tells you where a particular site stands.

If you are getting quotes for a cleanup, what malware removal costs says how cleanup is sold and what a complete one includes.

If you would rather hand it over, malware removal is a cleanup with the way in closed and a written report, and the security service is the upkeep that follows.

Guides

What it costs

Runbooks and checklists

Tools

Malware removal, done for you

Malware removal is $99. Full clean-up, hardening, blacklist removal request and a written report. 30-day re-clean guarantee. It starts with a free diagnosis.