Confirming the cleanup worked.
WHAT TO CHECK
Run a malware scan Load the site logged out, from a different network Check how it appears in search results Check for unexpected files Check your user list Check cron jobs
THE EXTERNAL CHECK
Load the site on a phone, on mobile data, in a private window.
Some compromises show only to certain visitors.
THE SEARCH CHECK
Search your domain with unrelated terms.
Injected pages may still be indexed.
WHAT TO MONITOR
File changes, for the next few weeks Login activity Resource use
WHY MONITOR
A compromise that returns indicates the entry point was not closed.
HOW LONG TO WATCH CLOSELY
At least a month.
WHAT TO DO IF IT RETURNS
The entry point is still open.
Stop, and investigate properly rather than cleaning again.
WHAT TO ASK US
We can check server-side for anything you cannot see.