If your website has been hacked, the most important thing is to stay calm and avoid making the problem worse. Randomly deleting files without understanding the infection can remove evidence, break the website or leave hidden backdoors behind.
Signs of compromise
- Unexpected redirects.
- Spam pages appearing in search results.
- Security warnings from browsers or Google.
- Unknown admin users.
- Strange files in website directories.
- High CPU usage or outgoing spam.
Immediate steps
- Change passwords for hosting, WordPress, FTP and email.
- Take a copy of the current site for investigation.
- Check recent admin users and plugin changes.
- Scan files for malware.
- Remove infected files and backdoors.
- Update WordPress, plugins and themes.
- Review file permissions.
Why cleanup alone is not enough
If the original entry point is not fixed, the site may be reinfected. Common entry points include outdated plugins, weak passwords, abandoned themes and compromised administrator accounts.
When to contact support
If the site is business-critical or blacklisted, open a ticket immediately. We can help identify the cause, clean the infection and advise on hardening.
Need help?
Open a support ticket directly from within your GetHosting.online customer account. Phone support is also welcome on (+44) 01457 337 247. For international contact numbers, please see our contact page.
GETHOSTING.ONLINE is a subsidiary of GetUK Support.