If you see strange redirects, unknown administrator users, a hosting alert or a malware warning in the browser, treat the incident as a priority. The first minutes are not the time for random changes: they are for containing the problem, documenting it and recovering control with as little damage as possible.
This guide is not a diagnosis. It helps you organise the response while you decide whether you can review the site internally or need professional help.
Minutes 0–5: confirm the symptoms and document them
Write down when you noticed the issue and the timezone. Save screenshots of affected pages, redirects, browser messages, provider alerts and related emails. Record recent changes: plugins, themes, users, passwords, integrations or server files.
Not every error is malware. A server outage, expired certificate or configuration problem can also make a site look broken. Unexpected users, unauthorised content, redirects to unknown domains or an explicit hosting alert still justify a security review.
The official WordPress guidance for compromised sites recommends starting by describing the symptoms and when they appeared. That record helps whether you investigate yourself or hand the case to someone else.
Minutes 5–10: reduce exposure
Contact your hosting provider and ask whether it can place the site into maintenance mode, isolate it temporarily or check whether other accounts in the same environment are affected. If the site handles payments, forms or customer data, consider pausing those functions until the scope is clear.
Do not delete suspicious files or restore a backup as your first reaction. You may destroy evidence, lose legitimate changes or reinstall the same vulnerability if the original access remains open.
Minutes 10–15: protect access from a trusted device
If possible, use an updated device and a trusted connection. Change passwords for WordPress, hosting, SFTP or SSH, the database, administrative email and connected services. Use unique passwords and enable two-factor authentication where available.
Review administrator users and active sessions. If you cannot access the dashboard, do not keep forcing changes: ask the hosting provider for a secure recovery path and keep the error message as part of your record.
Review the computer used to administer the site as well. A password exposed in a browser or on an infected computer can reopen the incident after the server is cleaned.
Minutes 15–20: preserve the affected state and available backups
Before cleaning, preserve a copy of the current files and database if you have a safe way to do so. This is not a copy to publish without review; it is a reference for understanding what changed and recovering legitimate content missing from an older backup.
Ask the provider which backups exist, their dates and whether they include both files and database. A recent backup is not automatically a clean backup. Record which restore point you would use and why instead of overwriting the current state without a trace.
Minutes 20–30: decide whether to escalate
Request a specialist review if any of these apply:
- The hosting provider blocked the account or reported malware.
- Customer data, payments or email accounts may be involved.
- You lost administrator access or new users keep appearing.
- The issue returns after restoring a backup.
- You cannot explain what changed or which component may have opened the door.
WordPress malware cleanup should start with diagnosis and scope, not a promise that one plugin can solve every infection.
What not to do during the emergency
- Reinstall everything without preserving the affected state.
- Delete files, users or plugins without recording what you found.
- Restore the newest backup without checking its date and origin.
- Install several cleanup plugins and change their settings at once.
- Keep administering the site from a computer that may be compromised.
- Close the incident because the homepage looks normal again.
Once the situation is contained, continue with how to recover a hacked WordPress site and how to disinfect WordPress from malware. For a general guide to the full incident, read what to do when a WordPress website has been hacked.
