Hosting support may detect files, suspend the account or restore a backup, but the provider and WordPress cleaner see different layers. Clear questions preserve evidence and avoid a cycle of “scanner clean” followed by reinfection.
Open one incident ticket through the provider’s verified channel and keep timestamps/timezones.
Ask what triggered the alert
Request exact paths, detection names, first/last seen times, hashes and whether the provider observed phishing, downloads, spam email, resource abuse or outbound connections.
Ask whether files were deleted, quarantined or only reported. Preserve the original report.
Do not request malicious samples by email; use the provider’s secure quarantine/recovery process.
Clarify account and server scope
Ask which subscription/system user/sites are affected and whether similar indicators appear elsewhere on the server. Confirm whether filesystem isolation worked.
Request review of panel, FTP/SFTP/SSH, file-manager and API access. Ask whether privileged/server cron or PHP prepend settings are suspicious.
Shared hosting customers may not have access to evidence the provider can see.
Request log preservation
Ask the host to retain web access/error, PHP, authentication, file-change, mail and control-panel logs for the incident window.
Confirm retention duration, timezone and secure export method. Logs may contain personal data or tokens, so request only relevant fields and protect the copy.
Do not enable verbose request-body logging retroactively on a live store.
Agree containment and recovery access
Clarify whether the account is suspended, read-only or available through SFTP/SSH/quarantine. Ask how to serve a clean maintenance response without executing infected PHP.
Request snapshots/files/database before remediation. Ensure recovery access is individual and temporary.
Do not ask for full public reactivation just to reach wp-admin.
Understand the provider’s remediation criteria
Ask what evidence is needed for rescan/reactivation: removed paths, updated components, credential rotation, account-wide checks and verification period.
Clarify false-positive appeal procedure for legitimate custom/commercial code.
A provider scanner pass does not replace database/user/cron and entry-route investigation.
Ask what the provider cannot verify
Clarify whether its scanner inspects database rows, WordPress users, cron, application passwords, CDN/Workers, DNS, mail accounts and third-party tag managers. Ask whether it can attribute file writes or only detect content after the fact.
Record unavailable evidence and retention gaps. This prevents a “clean” ticket closure from being misread as proof across layers the host never examined.
Ask who remains responsible for OS, web server and shared-account isolation, and how to escalate if different system users show the same indicator.
Ask about backups carefully
Request backup dates, creation source, integrity and whether they include all document roots/databases. Ask whether older backups have been scanned or might contain the same indicator.
Do not overwrite the incident state before taking a current snapshot. Restore into isolation first, not straight to production.
Confirm backups are outside public web directories.
Coordinate email, DNS and CDN
Ask whether unknown mailboxes/forwarders, DNS changes or outbound spam occurred. For provider-managed DNS/CDN, request audit logs and current configuration exports.
Check whether cache still serves infected HTML after origin cleanup.
Protect the owner email used for hosting resets.
Close with a written handoff
Provide the host a remediation summary: cause/evidence, cleaned sites, replaced packages, credential actions, isolation and verification. Ask for final rescan results and remaining limitations.
Request specialist assistance when the host cannot provide recovery access, several users/subscriptions are involved or privileged compromise is possible.
Ask for a named incident/reference number and retain the final provider response with the cleanup manifest. Future suspension or reinfection reports can then be compared against the same evidence.
Good coordination produces a shared timeline and verified clean boundary—not duplicated scans with no explanation.