The first 24 hours of a WordPress security incident determine how much evidence survives, how quickly damage is contained, and whether the same attacker returns. Random cleanup can make the site look better while destroying the information needed to find the entry point. Use a written sequence: confirm, preserve, contain, investigate, eradicate, recover, and monitor.
First 15 minutes: establish control
Record who discovered the problem, the exact time, affected URLs, screenshots, alerts, unusual accounts, redirects, browser warnings, and recent changes. Assign one incident lead and a private communication channel. Freeze routine deployments so normal work does not overwrite evidence.
Book a free, no-obligation strategy call and we'll map out your next move.
For expert containment and investigation, contact our hacked WordPress recovery service before making irreversible cleanup changes.
Preserve evidence
Copy web server, PHP, authentication, firewall, CDN, hosting, database, deployment, and application logs. Capture suspicious files with timestamps and hashes. Record active users, scheduled tasks, plugins, themes, administrator accounts, file changes, and external connections. Store evidence outside the affected hosting account with restricted access.
Contain without losing visibility
Restrict administrative access, isolate affected services, block confirmed malicious sources, and temporarily disable risky functions. For an e-commerce or lead site, decide whether to place checkout or forms into a controlled maintenance state. Do not announce full recovery before payment destinations, forms, emails, and integrations are verified.
Our WordPress backup and recovery guide explains how recovery objectives and isolated restore testing support safer containment.
Scope the incident
Identify the earliest reliable indicator, affected accounts, altered files, database changes, injected scripts, new administrators, modified DNS, payment settings, API keys, emails, and connected services. Compare the site with trusted source code and known-good backups. A visible malware file may be only one part of persistence.
Use a complete WordPress security audit checklist to examine users, code, hosting, configuration, integrations, and evidence of compromise.
Eradicate the cause and persistence
Replace compromised core and vendor code from verified sources, remove malicious files and database records, patch vulnerable components, close exposed accounts, and correct permissions. Rotate WordPress, hosting, database, SFTP, email, registrar, CDN, repository, deployment, and API credentials according to the incident scope.
Review our guide to rogue WordPress administrator accounts so hidden or unauthorized privileged access is not left behind.
Recover using explicit criteria
Restore or rebuild in an isolated environment, verify integrity, update every supported component, test critical user journeys, scan externally, and confirm logs reach a protected destination. Reopen only when the entry point is addressed, persistence checks are clean, credentials are rotated, backups work, and monitoring is active.
Our documented WordPress security recovery case study shows how investigation, cleanup, hardening, and verification fit together.

