The whole category in one page.
THE FIRST HOUR
Back up the compromised state Establish scope Change every credential, from a clean computer Tell us Take the site offline if it is harming visitors
THE PRINCIPLE THAT MATTERS MOST
Remove the compromise and close the entry point.
Doing only the first means it returns within days. That is why sites are compromised repeatedly.
THE STEP MOST CLEANUPS SKIP
Cron jobs and scheduled tasks.
Attackers use them to reinstate themselves after cleaning.
THE MOST RELIABLE CLEANUP
Replace rather than clean. Fresh core, fresh plugins and themes from legitimate sources, keeping only your own content after checking it.
You cannot be certain you found everything by cleaning.
BEFORE RESTORING A BACKUP
Establish when the compromise started. A backup from last week may already contain it.
And restoring does not close the entry point.
CHECK FROM OUTSIDE
Logged out, on a phone, from another network, and in search results.
Many compromises hide from the site owner deliberately.
IF SPAM WAS SENT
Tell us immediately. Server blacklisting affects everyone and we can address it.
AFTERWARDS
Updates, two-factor authentication, backups off the server, monitoring.
Most compromises follow neglect, which is why they are preventable.