{"id":365,"date":"2026-01-01T11:03:24","date_gmt":"2026-01-01T19:03:24","guid":{"rendered":"http:\/\/stackguard.demoavatar.top\/?p=365"},"modified":"2026-01-01T19:58:30","modified_gmt":"2026-01-02T03:58:30","slug":"wordpress-hacked-step-by-step-recovery-guide","status":"publish","type":"post","link":"https:\/\/stackguard.demoavatar.top\/index.php\/2026\/01\/01\/wordpress-hacked-step-by-step-recovery-guide\/","title":{"rendered":"WordPress Hacked? Step-by-Step Recovery Guide (2025)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Your WordPress site has been hacked. Maybe you discovered it yourself, maybe Google warned your visitors, or maybe your hosting company sent an alarming email. However you found out, you&#8217;re now facing a situation that feels overwhelming.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Take a breath. A <strong>WordPress hacked<\/strong> situation is stressful, but it&#8217;s fixable. Thousands of websites get hacked and recovered every day. With the right approach, you can clean your site, restore normal operations, and come back stronger than before.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide walks you through the complete recovery process, step by step. Follow it in order, don&#8217;t skip steps, and you&#8217;ll have your site back under your control.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Before You Start: What You&#8217;ll Need<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Gather these resources before beginning the recovery process:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Access to your hosting control panel<\/strong> (cPanel, Plesk, or your host&#8217;s dashboard)<\/li>\n\n\n\n<li><strong>FTP\/SFTP credentials<\/strong> or file manager access<\/li>\n\n\n\n<li><strong>Database access<\/strong> (usually through phpMyAdmin)<\/li>\n\n\n\n<li><strong>Your most recent backup<\/strong> (if you have one)<\/li>\n\n\n\n<li><strong>A notepad<\/strong> to document what you find<\/li>\n\n\n\n<li><strong>1-3 hours of uninterrupted time<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you don&#8217;t have some of these, contact your hosting provider. They can help you get access and may have backup copies even if you don&#8217;t.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Stay Calm and Document Everything<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Panic leads to mistakes. Before changing anything, document the current state:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Take Screenshots<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Screenshot any error messages or warnings<\/li>\n\n\n\n<li>Screenshot strange content or redirects<\/li>\n\n\n\n<li>Screenshot your WordPress dashboard (if accessible)<\/li>\n\n\n\n<li>Screenshot any emails from Google or your host<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Write Down What You Know<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>When did you first notice the problem?<\/li>\n\n\n\n<li>What symptoms are you seeing?<\/li>\n\n\n\n<li>Have you made any recent changes to the site?<\/li>\n\n\n\n<li>When was your last known good backup?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This documentation helps you (or a professional) understand what happened and prevents the same attack from succeeding again.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Put Your Site in Maintenance Mode<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your site is actively harming visitors (redirecting to malware, displaying inappropriate content, or spreading infections), take it offline immediately.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Option A: Use Your Hosting Control Panel<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Most hosting providers have a one-click option to suspend or put a site in maintenance mode. Check your hosting dashboard for this option.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Option B: Rename Your Index File<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Using FTP or your host&#8217;s file manager:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Navigate to your site&#8217;s root directory (usually public_html or www)<\/li>\n\n\n\n<li>Rename index.php to index.php.hacked<\/li>\n\n\n\n<li>Create a new index.html file with a simple &#8220;Site under maintenance&#8221; message<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Option C: Password Protect the Directory<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In cPanel, use &#8220;Directory Privacy&#8221; to password-protect your entire site while you work on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t Skip This If Your Site Is Dangerous<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your site is redirecting visitors to malware or phishing sites, every minute it stays live is harming real people. Take it offline first, then proceed with cleanup. Your reputation can recover from downtime. It&#8217;s harder to recover from infecting your customers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Change All Passwords Immediately<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Assume every password has been compromised. Change them all, starting with the most critical:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Priority 1: Hosting and Database<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hosting control panel password<\/li>\n\n\n\n<li>FTP\/SFTP passwords<\/li>\n\n\n\n<li>Database password (you&#8217;ll need to update wp-config.php afterward)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Priority 2: WordPress Accounts<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All administrator accounts<\/li>\n\n\n\n<li>All editor and author accounts<\/li>\n\n\n\n<li>Any account with dashboard access<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Priority 3: Connected Services<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email accounts associated with the site<\/li>\n\n\n\n<li>Payment processor accounts<\/li>\n\n\n\n<li>Any third-party services connected to WordPress<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Use strong, unique passwords for each.<\/strong> Now is not the time for &#8220;password123.&#8221; Use a password manager to generate and store complex passwords.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Update wp-config.php with New Database Password<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After changing your database password, update wp-config.php:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open wp-config.php via FTP or file manager<\/li>\n\n\n\n<li>Find the line: define(&#8216;DB_PASSWORD&#8217;, &#8216;your_old_password&#8217;);<\/li>\n\n\n\n<li>Replace with your new database password<\/li>\n\n\n\n<li>Save the file<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Scan Your Site for Malware<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before cleaning, you need to know what you&#8217;re dealing with. Run multiple scans:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Online Scanners (Free)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Sucuri SiteCheck:<\/strong> sitecheck.sucuri.net<\/li>\n\n\n\n<li><strong>VirusTotal:<\/strong> virustotal.com (enter your URL)<\/li>\n\n\n\n<li><strong>Google Safe Browsing:<\/strong> Check your URL at transparencyreport.google.com\/safe-browsing\/search<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">WordPress Security Plugin Scanners<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you can still access your WordPress dashboard:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Install a security plugin (Stack Guard, Wordfence, or Sucuri)<\/li>\n\n\n\n<li>Run a full malware scan<\/li>\n\n\n\n<li>Document all findings<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">What to Look For<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Modified core WordPress files<\/li>\n\n\n\n<li>Unknown files, especially PHP files in \/wp-content\/uploads\/<\/li>\n\n\n\n<li>Suspicious code in theme files<\/li>\n\n\n\n<li>Strange database entries<\/li>\n\n\n\n<li>Unknown administrator accounts<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 5: Identify the Entry Point<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Understanding how hackers got in prevents reinfection. Common entry points include:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Weak Passwords<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check your user list. Was anyone using a simple password? Was the &#8220;admin&#8221; username in use?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Outdated Software<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check when WordPress, themes, and plugins were last updated. Outdated software with known vulnerabilities is the most common entry point.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Vulnerable Plugins<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Search for your plugins at wpscan.com\/plugins to see if any have known security issues. Pay special attention to plugins that haven&#8217;t been updated in over a year.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Compromised Theme<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you&#8217;re using a &#8220;nulled&#8221; (pirated) premium theme, that&#8217;s likely your entry point. Nulled themes frequently contain backdoors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hosting-Level Breach<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes the vulnerability is on your hosting provider&#8217;s end, especially with cheap shared hosting. Contact your host to ask if other sites on your server were affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check File Modification Dates<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In your file manager or FTP client, sort files by modification date. Files changed around the time of the hack (that you didn&#8217;t change) are likely infected or the entry point. This helps narrow down when the attack occurred.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 6: Clean Your Site (Two Methods)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You have two options for cleaning: restore from backup (faster) or manual cleaning (necessary if no clean backup exists).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Method A: Restore from Backup (Recommended)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you have a backup from before the hack, this is the fastest and most reliable method:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Identify a clean backup:<\/strong> Choose a backup from before you noticed any symptoms (add a few days buffer)<\/li>\n\n\n\n<li><strong>Export current content (optional):<\/strong> If you&#8217;ve added content since the backup, export posts and pages to avoid losing them<\/li>\n\n\n\n<li><strong>Restore the backup:<\/strong> Use your backup plugin or hosting provider&#8217;s restore feature<\/li>\n\n\n\n<li><strong>Immediately update everything:<\/strong> Update WordPress, all themes, and all plugins before the site goes live<\/li>\n\n\n\n<li><strong>Change all passwords again:<\/strong> The restored site has old passwords<\/li>\n\n\n\n<li><strong>Scan the restored site:<\/strong> Verify the backup was actually clean<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Method B: Manual Cleaning<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you don&#8217;t have a clean backup, you&#8217;ll need to remove the malware manually:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-1: Replace WordPress Core Files<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Download a fresh copy of WordPress from wordpress.org<\/li>\n\n\n\n<li>Delete your existing \/wp-admin\/ and \/wp-includes\/ folders<\/li>\n\n\n\n<li>Upload the fresh \/wp-admin\/ and \/wp-includes\/ folders<\/li>\n\n\n\n<li>Replace all files in the root directory EXCEPT wp-config.php and .htaccess<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-2: Clean wp-config.php<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open wp-config.php and look for any code that doesn&#8217;t belong<\/li>\n\n\n\n<li>Compare against a fresh wp-config-sample.php from WordPress<\/li>\n\n\n\n<li>Remove any suspicious code (often at the very beginning or end of the file)<\/li>\n\n\n\n<li>Generate new security keys at api.wordpress.org\/secret-key\/1.1\/salt\/ and replace the old ones<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-3: Clean .htaccess<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Download a backup of your current .htaccess<\/li>\n\n\n\n<li>Delete it and let WordPress regenerate it (Settings \u2192 Permalinks \u2192 Save)<\/li>\n\n\n\n<li>Or replace with default WordPress .htaccess code<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-4: Reinstall Themes and Plugins<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Document which themes and plugins you&#8217;re using<\/li>\n\n\n\n<li>Delete all themes except a default theme (like Twenty Twenty-Four)<\/li>\n\n\n\n<li>Delete all plugins<\/li>\n\n\n\n<li>Reinstall themes and plugins from fresh sources (WordPress.org or original vendor)<\/li>\n\n\n\n<li>Don&#8217;t restore from your backup copies, as they may be infected<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-5: Clean the Uploads Folder<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Navigate to \/wp-content\/uploads\/<\/li>\n\n\n\n<li>Search for any PHP files (there shouldn&#8217;t be any)<\/li>\n\n\n\n<li>Delete any PHP files you find<\/li>\n\n\n\n<li>Check for files with strange names or recent modification dates<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Step 6B-6: Clean the Database<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open phpMyAdmin<\/li>\n\n\n\n<li>Check wp_users for unknown administrator accounts and delete them<\/li>\n\n\n\n<li>Check wp_options for suspicious entries (especially &#8220;siteurl&#8221; and &#8220;home&#8221;)<\/li>\n\n\n\n<li>Search for common malware indicators: base64_decode, eval(, gzinflate<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Step 7: Verify the Cleanup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After cleaning, verify that your site is actually clean:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Run malware scans again with multiple tools<\/li>\n\n\n\n<li>Check Google Search Console for security warnings<\/li>\n\n\n\n<li>Test your site from multiple devices and networks<\/li>\n\n\n\n<li>Ask someone else to visit your site and report what they see<\/li>\n\n\n\n<li>Monitor your site closely for the next few days<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If malware persists or returns quickly, you may have missed a backdoor. Consider professional help at this point.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 8: Request Google Review (If Flagged)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If Google was showing warnings about your site:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log into Google Search Console<\/li>\n\n\n\n<li>Go to Security &amp; Manual Actions \u2192 Security Issues<\/li>\n\n\n\n<li>Review the issues Google found<\/li>\n\n\n\n<li>Click &#8220;Request Review&#8221;<\/li>\n\n\n\n<li>Describe what you found and how you fixed it<\/li>\n\n\n\n<li>Submit the request<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Google typically reviews within 72 hours, but it can take up to two weeks. Be patient, and don&#8217;t submit multiple requests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 9: Strengthen Your Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once recovered, implement protections to prevent future attacks:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Immediate Actions<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Install a security plugin:<\/strong> Get real-time protection and monitoring<\/li>\n\n\n\n<li><strong>Enable two-factor authentication:<\/strong> For all admin accounts<\/li>\n\n\n\n<li><strong>Set up automatic backups:<\/strong> To cloud storage, running daily<\/li>\n\n\n\n<li><strong>Update everything:<\/strong> Keep WordPress, themes, and plugins current<\/li>\n\n\n\n<li><strong>Delete unused plugins and themes:<\/strong> Reduce your attack surface<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Prevent the Next Attack<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stack Guard provides the security features that would have prevented this hack: login protection, two-factor authentication, security hardening, and malware scanning. Set it up now so you never face this situation again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Download Stack Guard Free<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ongoing Maintenance<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Check for updates weekly<\/li>\n\n\n\n<li>Review security logs monthly<\/li>\n\n\n\n<li>Test backup restoration quarterly<\/li>\n\n\n\n<li>Audit user accounts periodically<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">When to Hire a Professional<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Consider professional malware removal if:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You&#8217;ve tried cleaning but the malware keeps returning<\/li>\n\n\n\n<li>You don&#8217;t have the technical comfort to follow these steps<\/li>\n\n\n\n<li>Your site handles sensitive customer data<\/li>\n\n\n\n<li>Time is critical and you can&#8217;t afford extended downtime<\/li>\n\n\n\n<li>Multiple sites are affected<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Professional cleanup typically costs $150-500 depending on severity. Reputable services include Sucuri, Wordfence, and your hosting provider&#8217;s security team.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">How long does recovery take?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With a clean backup, you can recover in 1-2 hours. Manual cleaning takes 3-6 hours for a straightforward infection, longer for complex ones. Google warning removal adds another few days to two weeks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Will I lose my content?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If restoring from backup, you&#8217;ll lose content added after the backup date. With manual cleaning, you shouldn&#8217;t lose any content, but always export a backup of your posts and pages before starting, just in case.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I rebuild from scratch instead?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For severely compromised sites or if you&#8217;re unsure about the cleanup, starting fresh can be faster and more reliable. Export your content, build a new WordPress installation, import your content, and implement strong security from day one.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can my hosting provider help?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Many hosting providers offer malware removal services or can assist with recovery. Some include this in their support, while others charge a fee. Contact them early in the process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How do I know if it&#8217;s really fixed?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Run multiple scans with different tools, monitor your site for a few weeks, check Google Search Console regularly, and watch for the warning signs that indicated the original hack. If symptoms return, you missed something.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recovering from a WordPress hack is a methodical process: document, contain, clean, verify, and prevent. Follow each step in order, don&#8217;t take shortcuts, and your site will be back to normal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The silver lining is that this experience teaches you exactly why security matters. Use it as motivation to implement the protections that prevent future attacks. Most site owners who recover from a hack never get hacked again, because they finally take security seriously.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ve got this. One step at a time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t Let It Happen Again<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you&#8217;ve recovered, protect your site with Stack Guard. Login protection, two-factor authentication, brute force blocking, and security hardening, all free. Make this the last time you deal with a hacked site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Get Stack Guard Free<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your WordPress site has been hacked. Take a breath and follow this step-by-step guide to recover your website, remove the infection, and make sure it doesn&#8217;t happen again.<\/p>\n","protected":false},"author":1,"featured_media":307,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"WordPress Hacked? Step-by-Step Recovery Guide (2025)","_seopress_titles_desc":"WordPress hacked? Don't panic. Follow this step-by-step recovery guide to clean your site, remove malware, and prevent future attacks.","_seopress_robots_index":"","_surecart_dashboard_logo_width":"180px","_surecart_dashboard_show_logo":true,"_surecart_dashboard_navigation_orders":true,"_surecart_dashboard_navigation_invoices":true,"_surecart_dashboard_navigation_subscriptions":true,"_surecart_dashboard_navigation_downloads":true,"_surecart_dashboard_navigation_billing":true,"_surecart_dashboard_navigation_account":true,"footnotes":""},"categories":[181],"tags":[],"class_list":["post-365","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-recovery"],"acf":[],"meta_box":{"article_faq":[{"article_faq_question":"What's the first thing I should do if my WordPress site is hacked?","article_faq_answer":"<p><strong>Don't panic, but act fast.<\/strong> First, change all passwords immediately, WordPress admin, hosting, FTP, and database. Then take your site offline if possible (maintenance mode or ask your host) to prevent further damage and protect visitors. Document everything you see before making changes. Having a backup from before the hack is invaluable, but don't restore it until you understand how the hackers got in.<\/p>"},{"article_faq_question":"How do I find where hackers got into my WordPress site?","article_faq_answer":"<p>Common entry points include outdated plugins (the #1 cause), weak passwords, compromised themes, and vulnerable hosting. Check your server access logs for unusual activity, look for requests to files you don't recognize. Review recently modified files (anything changed around when you noticed the hack). A malware scanner can help identify injected code, but manual review is often necessary too.<\/p>"},{"article_faq_question":"Should I restore from backup or clean the hacked site?","article_faq_answer":"<p>If you have a clean backup from before the hack, restoring is usually faster and more reliable, malware can hide in unexpected places. However, you must fix the vulnerability first, or you'll just get hacked again. If your backup is old and you'd lose significant content, cleaning might be worth the effort. Either way, update everything (WordPress, plugins, themes) and add proper security measures afterward.<\/p>"},{"article_faq_question":"How do I remove malware from my WordPress site?","article_faq_answer":"<p>Start by replacing WordPress core files with fresh copies from wordpress.org. Then examine wp-content, compare your plugins and themes against clean versions. Look for suspicious files (random names, recently modified dates, encoded PHP). Check wp-config.php for injected code. Remove any admin users you didn't create. Finally, scan your database for malicious scripts injected into posts or options. It's tedious but thorough.<\/p>"},{"article_faq_question":"How do I prevent my WordPress site from getting hacked again?","article_faq_answer":"<p>Prevention is about layers. Enable <a href=\"http:\/\/stackguard.demoavatar.top\/index.php\/feature\/wordpress-two-factor-authentication-totp\/\" target=\"_blank\" rel=\"noopener\">two-factor authentication<\/a> on all admin accounts. Use a <a href=\"http:\/\/stackguard.demoavatar.top\/index.php\/feature\/wordpress-custom-login-url\/\" target=\"_blank\" rel=\"noopener\">custom login URL<\/a> to hide your login page from scanners. Set up <a href=\"http:\/\/stackguard.demoavatar.top\/index.php\/feature\/wordpress-local-brute-force-protection\/\" target=\"_blank\" rel=\"noopener\">brute force protection<\/a> to block password guessing attacks. Keep WordPress, plugins, and themes updated. Use strong, unique passwords. Remove unused plugins and themes. Consider a Web Application Firewall for extra protection. Most hacks are preventable with basic security hygiene.<\/p>"}],"article_key_points":[{"article_key_point":"Change all passwords immediately: WordPress, hosting, FTP, and database. Before anything else."},{"article_key_point":"Find how hackers got in before restoring from backup, or you'll just get hacked again."}]},"_links":{"self":[{"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/posts\/365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/comments?post=365"}],"version-history":[{"count":2,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/posts\/365\/revisions"}],"predecessor-version":[{"id":370,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/posts\/365\/revisions\/370"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/media\/307"}],"wp:attachment":[{"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/media?parent=365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/categories?post=365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stackguard.demoavatar.top\/index.php\/wp-json\/wp\/v2\/tags?post=365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}