Initial assessment without passwords Quote before intervention One accountable specialist from start to finish

Visible Symptoms Initial Triage

A Hosting Provider Suspended WordPress for Malware

Respond to a WordPress malware suspension by preserving provider evidence, obtaining safe access, cleaning all account paths and proving remediation.

The host replaces the site with a suspension page or disables PHP after detecting malicious files, phishing or outbound abuse. Restoring service quickly matters, but asking for reactivation before removing persistence can lead to another suspension and lost evidence.

Work with the provider’s incident process and treat the whole hosting account as in scope until isolation is proven.

Preserve the provider’s report

Save the ticket, detection time, named paths, malware signatures, outbound activity and required remediation steps. Ask whether the account is read-only, fully disabled or accessible through a recovery environment.

Do not publish the report. Paths, usernames and IP information can expose the account structure.

A provider scanner’s file list is a starting point. It may omit database injections, stolen credentials and loaders that regenerate the files.

Request a safe working method

Ask the host for SFTP/SSH recovery access, a quarantined copy or backup export according to its policy. Avoid re-enabling the public site merely so a cleaner can log into WordPress.

If the dashboard is unavailable, cleanup can proceed from filesystem, database and hosting evidence. Use individual temporary access and revoke it after the work.

Never send the hosting password through an ordinary contact form.

Take a forensic working copy

Preserve the current files, database and relevant logs before changing them, including timestamps and provider quarantine information. Calculate hashes for named samples where appropriate.

Store the copy outside public web roots with restricted access. Do not restore it into another internet-facing server.

Keep a separate clean working copy for edits so original evidence remains unchanged.

Inspect the entire account

Review every WordPress installation, staging site, subdomain and forgotten directory. Check users, FTP/SFTP accounts, cron jobs, email accounts, DNS and panel redirects.

Attackers frequently move laterally across sites sharing permissions. Cleaning only the suspended domain can leave a reinfection source beside it.

Identify which directories belong to active applications before deleting anything. A scanner can label legitimate obfuscated commercial code incorrectly.

Rebuild trusted components

Replace WordPress core, plugins and themes from verified sources at the correct versions where practical. Preserve custom code for manual review rather than overwriting it.

Remove confirmed backdoors, injected database content and malicious scheduled tasks. Patch vulnerable components and retire abandoned installations.

Rotate WordPress, hosting, database, SFTP and related deployment credentials after checking the devices and accounts that use them. Update configuration safely so the site can reconnect.

Satisfy the host’s validation process

Prepare a concise remediation record: affected paths, removed/replaced components, vulnerability or credential route, account-wide checks, versions updated and verification performed.

Use the provider’s rescan or review process. Do not claim “all clean” based only on a plugin scanner run inside the previously compromised site.

If the provider requires deletion of a legitimate file, ask for the exact signature and review it before complying.

Verify after reactivation

Bring the site back through a controlled maintenance state. Test public pages, forms, email and authorised checkout, then inspect logs and file changes.

Purge CDN caches only after clean origin responses are confirmed. Monitor for the provider’s original signature and the route that created it.

Keep the recovery backup according to an agreed retention policy; it may contain personal or malicious data.

Confirm scheduled backups now capture the repaired account rather than the quarantined copy.

Request professional cleanup

Urgent help is appropriate when the host suspends several sites, identifies phishing/outbound mail or offers only a short remediation window. Send the ticket summary with sensitive paths redacted.

The goal is not simply reactivation. It is an account-wide cleanup with evidence strong enough for the host and protection against immediate reinfection.

BEFORE YOU SEND THE REQUEST

Frequently asked questions.

Do you ask for passwords in the form?+

No. The public form never requests access. Secure credentials are requested only after the scope and quote are approved.

Who reviews the incident?+

The request goes to Jordi Ensenyat, founder of Code Barcelona and a WordPress specialist with more than 15 years of experience.

Is anything changed before the quote?+

No. Visible symptoms and scope are reviewed first. Intervention begins after approval and with a rollback path prepared.

Do you work internationally?+

Yes. WP Repair handles WordPress and WooCommerce incidents in English and Spanish through a remote service.

Assess my incident