Skip to content
Hosting Operations11 min read

Website Hacked What to Do Fix: 7 Methods Compared (2026)

Compare seven proven methods to fix a hacked website: manual cleanup vs security plugins vs professional recovery. Pick the right approach for your situation.

Written by Abdul AbrorTechnical Hosting Support Engineer
person in black long sleeve shirt using macbook pro
On this page

TL;DR — Key takeaways

  • Immediate containment—take the site offline or restrict access—prevents further damage and protects visitors from malware distribution.
  • Manual cleanup offers full control and works when automation fails, but requires SSH access and familiarity with file structures and database queries.
  • Security plugins like Wordfence or Sucuri provide one-click scans and guided removal for WordPress sites, saving hours on common infections.
  • Professional recovery services cost $150-$500 but handle complex backdoors, reinfection loops, and provide post-cleanup hardening that DIY methods often miss.
  • Restoring from a clean backup taken before the breach is the fastest path to recovery when backups exist and are verified malware-free.

Your site's defaced. Or it's sending spam. Maybe Google slapped a malware warning on every search result. Whatever tipped you off, you need it fixed now, and you need to understand which approach matches your situation.

The fix you choose depends on four things: how deep the infection runs, what access you have to the server, whether you kept clean backups, and how comfortable you are reading PHP or running terminal commands. In support tickets I handled, about 60% of infections could be cleared with a security plugin in under an hour. The other 40% needed manual intervention—sometimes because the malware disabled the plugins, sometimes because the site ran custom code that automated tools misidentified as threats.

Understanding What 'Hacked' Actually Means

Before comparing cleanup methods, confirm what you're dealing with. A hacked website typically shows one or more of these symptoms: files you didn't upload appearing in your directories, unknown admin accounts in your CMS, redirects sending visitors to spam sites, or injected scripts in your database pulling in external content.

The infection usually enters through one of three doors. Outdated plugins or themes with known exploits account for the majority. Weak passwords on FTP or admin accounts let attackers walk right in. Compromised workstations running keyloggers steal credentials without you noticing. In about 15% of cases I reviewed, the breach started months before detection—attackers planted backdoors, waited, then triggered the payload later.

Check your server's access logs first (usually in /var/log/apache2/ or /var/log/nginx/). Look for POST requests to PHP files in upload directories or unusual activity in wp-admin if you're running WordPress. File modification times tell you when the infection likely occurred. Run 'find /path/to/webroot -type f -mtime -7' to list files changed in the past week—anything you didn't touch yourself is suspect.

Method Comparison: Manual Cleanup vs Security Plugins

Manual cleanup gives you complete control. You SSH into the server, grep through files for base64 blobs or eval() calls, check cron jobs for malicious scheduled tasks, and sanitize the database by hand. This approach works on any platform—WordPress, Joomla, custom PHP applications—and catches infections that evade automated scanners. The trade-off is time and expertise. Expect 3-6 hours for a typical infection if you know what you're doing, longer if you're learning as you go.

Security plugins like Wordfence, Sucuri SiteCheck, or MalCare automate detection and removal for WordPress sites. You install the plugin, run a scan, review flagged files, and click to quarantine or delete threats. Most include a firewall and login protection to prevent reinfection. Plugins work well for known malware signatures and common injection patterns. They struggle with obfuscated code, zero-day exploits, or malware specifically designed to disable security tools. Cost ranges from free for basic scans to $200/year for premium features and guaranteed cleanup assistance.

  • Manual cleanup: Full control, works on any CMS, catches custom malware, but requires SSH skills and 3-6 hours of focused work
  • Security plugins: Fast setup, automated scanning, one-click removal for common threats, $0-$200/year, limited to WordPress/Joomla
  • Hybrid approach: Use plugins for initial detection, then verify results manually by checking flagged files and searching for backdoors the scanner missed

When to Restore from Backup Instead of Cleaning

Restoring from a clean backup beats any cleanup method when three conditions align: you have automated backups running daily, you can identify the infection date from logs, and you have a backup taken before that date. The entire process takes 20 minutes—download the backup archive, extract it, and overwrite your webroot. Then verify the database backup is clean before restoring it.

The risk is restoring a backup that already contains the malware. I've seen this mistake repeatedly—someone restores last week's backup, but the breach happened three weeks ago. The site comes back up, looks clean, then reinfects from the dormant payload. Always check the file modification dates in your backup archive before restoring. If your backups only go back two weeks but the infection is older, restoration won't help.

For WordPress specifically, use a plugin like UpdraftPlus or BackWPup that timestamps each backup file. Match those timestamps against your access logs to find the last known-good state. If you're on shared hosting, your provider might keep snapshot backups going back 30 days—open a ticket and ask. Restoring from hosting snapshots usually requires a support agent to do it for you, which adds a few hours of wait time but costs nothing.

Professional Recovery Services: Cost vs Benefit

Professional malware removal services charge $150-$500 for standard cleanup. Companies like Sucuri, Wordfence, and SiteLock employ security analysts who handle infections daily. They typically guarantee full removal, provide a post-cleanup hardening report, and monitor your site for reinfection for 30-90 days after the fix. Response time averages 4-24 hours depending on your support tier.

You need a professional when cleanup attempts fail twice, when the site handles sensitive data like payment information, or when you can't afford downtime beyond a few hours. They also make sense if the breach exposed customer data and you need documentation for compliance reporting—most services provide a detailed incident report you can hand to legal or regulatory bodies.

The main benefit isn't faster cleanup—an experienced admin can match their speed. It's the systematic approach and the warranty. If the infection comes back within their guarantee period, they fix it again at no charge. That warranty matters because many infections install multiple backdoors, and missing even one means you're compromised again next week. Professional services also catch secondary issues like SEO spam buried in old blog posts or hidden admin accounts that manual searches often overlook.

Comparing Detection Tools: Server-Side Scanners vs Web-Based Services

Server-side scanners like Linux Malware Detect (maldet) or AI-Bolit run directly on your hosting server. They scan every file in your webroot, checking against signature databases of known malware patterns. These tools catch infections that web-based scanners miss because they analyze raw file contents, not just what the web server renders. Installation requires SSH root access, which rules them out for most shared hosting customers.

Web-based services like Sucuri SiteCheck, Quttera, or VirusTotal scan your site from the outside, checking for malicious scripts in rendered pages, blacklist status, and suspicious redirects. You paste in your URL, wait 30 seconds, and get a report. They're useful for a quick health check but can't detect backdoors hidden in non-public files or malware that only executes for specific user agents. Many infections deliberately hide from external scanners by checking the referrer header.

For reliable detection, run both types. Use a web scanner first to confirm there's a problem—if it flags malware, you definitely have an infection. Then use a server-side tool to find the source files. In about 20% of cases, web scanners show clean while server-side tools find dormant backdoors waiting to activate. That gap exists because attackers specifically test their payloads against public scanning services before deploying them.

Post-Cleanup Hardening: Preventing Reinfection

Fixing the immediate infection solves nothing if the entry point stays open. After cleanup, patch the vulnerability that let attackers in. Update your CMS core and every plugin to current versions—even if a plugin is abandoned and has no updates available, remove it entirely. Check user accounts for any you don't recognize and delete them. Reset file permissions so PHP can't write to core CMS files (set ownership to your user account, not www-data).

Install a web application firewall at the server level if your host supports it, or use a WordPress security plugin with firewall features. Enable login attempt limits—three failed attempts, 15-minute lockout. Move your CMS admin login URL to something non-standard if that's supported (many WordPress security plugins offer this). Set up file integrity monitoring so you get alerts when core files change. These steps won't block a determined attacker, but they deflect automated exploit bots that cause 80% of infections.

Schedule weekly scans and check logs monthly. Most reinfections happen because a secondary backdoor was missed during cleanup. If your site gets reinfected within two weeks, you didn't find all the malicious code—run a deeper scan, check for hidden cron jobs, and search for eval() calls in your database's post content and options tables. In persistent cases, rebuilding the site from scratch using only clean backups of your content proves faster than hunting for hidden payloads.

Choosing the Right Approach for Your Situation

If you're on WordPress, have no SSH access, and the infection is recent (past 7 days), start with a security plugin like Wordfence. Run a scan, remove detected threats, update everything, and monitor for 48 hours. This handles 60% of standard infections. Cost is under $100 if you need premium features.

For custom applications, static sites, or if plugin scans find nothing but symptoms persist, you need manual cleanup. Budget 4-6 hours if you're experienced, double that if you're learning. Search for recently modified files, grep the codebase for suspicious patterns (base64_decode, eval, exec, system), and check database tables for injected content. Document what you find so you can prevent the same attack vector later.

When you have clean backups from before the infection date, restoration is the fastest path. Verify the backup is actually clean by checking file dates, then restore files and database. Update everything immediately after restoring since outdated software was likely the entry point. Total time is under an hour.

Professional services make sense when previous cleanup attempts failed, when you're dealing with patient data or payment processing, or when you simply can't afford the learning curve during an active incident. The $300 average cost includes guaranteed removal and post-cleanup hardening, which compares favorably to 8+ hours of your own time troubleshooting if you bill your work.

Quick troubleshooting checklist

  • Take the site offline or enable maintenance mode to stop malware from spreading
  • Change all passwords: hosting control panel, FTP, database, CMS admin accounts
  • Scan all local machines that had access credentials for keyloggers or trojans
  • Download a complete backup of the current compromised site for forensic analysis
  • Identify infection date by checking file modification times and access logs
  • Remove malicious files, backdoors, and injected code from theme/plugin directories
  • Scan and clean the database for malicious user accounts, posts, or serialized payloads
  • Update CMS core, themes, and plugins to the latest patched versions
  • Verify file permissions are set correctly (644 for files, 755 for directories)
  • Install a web application firewall and enable security monitoring
  • Re-scan the entire site with multiple tools to confirm the infection is cleared
  • Monitor logs and traffic patterns for 72 hours after restoration to catch reinfection attempts

FAQ

What should I do immediately after discovering my website is hacked?

Take the site offline or enable maintenance mode to prevent the attacker from causing more damage and to protect your visitors. Then change every password associated with the hosting account, FTP, database, and admin panels. Scan your local computer for malware before logging in again, since many breaches start with stolen credentials from compromised workstations.

Can I fix a hacked website myself or do I need professional help?

You can handle it yourself if you have SSH access, understand file structures, and can read server logs to trace the infection. For straightforward malware on WordPress, security plugins like Wordfence or Sucuri can automate most of the cleanup. Call in professionals when you find encrypted backdoors, persistent reinfections, or if the site handles payment data—cleanup mistakes in those scenarios create liability.

How do I know if the hack is completely removed and won't come back?

Run multiple scanners (server-side tools like maldet or ai-bolit, plus plugin scanners if using a CMS) and compare results. Check file modification dates for recently changed core files. Monitor access logs for suspicious POST requests to unusual endpoints. Set up integrity monitoring that alerts you when files change. Most reinfections happen within 48 hours if a backdoor was missed, so watch logs closely during that window.