Why cleaned sites get compromised again.
THE FOUR CAUSES
A backdoor was missed. Attackers plant several, frequently in unrelated directories and inactive extensions. The vulnerability was not patched. Cleaning files does not update software. Credentials were not all changed. If the attacker has your FTP password, they no longer need the vulnerability. Your own computer is infected, and hands over the new credentials as soon as you set them.
DOING IT PROPERLY
Clean thoroughly, scanning the whole home directory Update core, every extension and every theme Remove anything unused entirely Change every password, everywhere Scan your own computer
Harden: permissions, admin protection, two-factor authentication
Monitor for several weeks
THE FTP CLIENT PROBLEM
FileZilla and similar store saved passwords in a file that malware specifically targets. If a site is repeatedly compromised with no server-side explanation, this is frequently why.
Use a master password, or do not save passwords.
IF IT RECURS
Open a ticket. We can search the account server-side for what you missed.