If your site is defaced, redirecting elsewhere, sending spam or flagged with a warning by a browser, act quickly. The longer a compromised site stays online, the more damage is done to your search rankings and email reputation.
What to do first:
- Do not just delete the defacement. The way in is still open and the site will be reinfected.
- Change your WordPress admin, cPanel and database passwords
- Open a support ticket and tell us what you are seeing
We clean up compromised WordPress sites as a service. That means removing the malicious code, finding and closing the hole that allowed it in - usually an outdated plugin, theme or a weak password - and getting the site back online.
Cleaning without closing the entry point is why sites get hacked repeatedly, so we always do both.
