WordPress Hacked: What to Do in the First 48 Hours

Google Search Console emails you at 7 AM. The homepage redirects to a casino site. Or a client forwards a screenshot: "is this your work?" Your stomach drops. WordPress got compromised.

The first 48 hours matter. Panic-posting on forums or clicking "remove malware" buttons in random plugins can make recovery harder. Here is a calm sequence that limits damage and gets you back to a known-good state.

Hour 0: contain, do not poke blindly

Take the site offline or maintenance-mode it if it is actively serving malware or phishing redirects. A simple maintenance plugin or web server block stops hurting visitors and protects your domain reputation.

Change passwords immediately for WordPress admins, hosting panel, FTP/SFTP, database, and DNS/registrar. Assume credentials leaked. Use a password manager and enable MFA everywhere it exists.

Do not delete files yet. You need evidence for forensics and for whoever helps with cleanup. Snapshot the server or download a copy of files and database if you can.

Hours 1-4: figure out what broke

Check recent changes: plugin updates, new admin users, theme edits, abandoned contractor accounts. Look at:

  • Unknown admin users in wp_users
  • Recently modified PHP in wp-content/themes and mu-plugins
  • Suspicious cron jobs in cPanel or wp-cron events
  • Google Safe Browsing and Search Console security issues
  • Mail provider bounce messages (compromised sites often send spam)

Scan with reputable tools (Wordfence, Sucuri, or your host's malware scanner). Automated scans find common patterns; they miss custom backdoors. Treat "clean" as provisional.

Hours 4-12: restore from trust, not hope

Best recovery path: restore files and database from a backup you know predates the compromise. "Last night's backup" fails if the hack started three weeks ago and slept quietly.

If no clean backup exists, professional malware removal or rebuild from scratch may be cheaper than whack-a-mole with infected files. We offer WordPress hacked site recovery for Canadian businesses in exactly this spot.

After restore:

  • Update WordPress core, themes, and plugins before going live
  • Remove unused plugins and old themes
  • Regenerate salts in wp-config if you suspect database tampering
  • Rotate API keys (payment gateways, SMTP, CRM integrations)

Hours 12-24: close the door they used

Common entry points:

  • Outdated plugins with known CVEs
  • Weak or reused admin passwords (no MFA)
  • Nulled premium themes/plugins from shady download sites
  • Compromised FTP or hosting panel credentials
  • Another site on shared hosting (less common on well-isolated hosts)

Fix the root cause or you will be back here next month. Patch PHP if you are past EOL. See PHP end of life and your live site.

Hours 24-48: reputation and monitoring

Request a Google review after cleanup if you were blacklisted. Check DNS has not been hijacked (rogue A records or nameserver changes). Monitor Search Console and uptime for redirect recurrence.

Set up file integrity monitoring or a security plugin that alerts on core file changes. Backups with off-site retention become non-negotiable after the first incident.

Review who has admin access. Remove old agency accounts. MFA on every admin, full stop. We covered account hygiene in MFA on hosting and DNS accounts.

What not to do

  • Install five "malware removal" plugins simultaneously
  • Pay ransomware without legal and IT guidance
  • Go live before you understand the entry vector
  • Assume hosting support will rewrite your custom theme for free
  • Hide the incident from clients who may have had data exposed

When to call for help

Call early if: you handle payments or personal health data, the site keeps re-infecting after restore, you lack clean backups, or Google has flagged the domain. Canadian businesses with compliance obligations need documented incident response, not a frantic Sunday night plugin purge.

Bottom line

First 48 hours after a WordPress hack: contain, preserve evidence, restore from a clean backup, patch and harden, then fix reputation and access. Speed helps, but reckless deletes and mystery plugins make recovery longer.

Dealing with an active compromise? Talk with Swift Host. We can isolate the site, assess backups, and walk through recovery without pretending one scan button fixes everything.

Tags:
  • WordPress
  • Security
  • Malware
  • Backups

Need Help With Your Hosting?

Tell us about your application — we respond within 1 hour with honest recommendations.