Incident, not a retainer

WordPress hacked? What to do in the first 24 hours.

A hacked WordPress site is first an incident: isolate, backup, passwords, then recovery. OmniTechs is a one-person studio without 24/7 availability and does not sell emergency response for arbitrary WordPress sites.

By Sina Esfahani · Checklist, not an emergency service. · Updated .

What do you do when WordPress is hacked?

Take the site offline or put up a maintenance screen, change passwords for hosting, WordPress, FTP and email, and check whether there is a backup from before the breach. Do not install extra security plugins in a panic on a compromised site.

OmniTechs responds on Dutch business days, within the Care-level response time if the site runs with OmniTechs. That is not a 24-hour SLA. For sites built elsewhere, this article is the checklist, not an engagement.

The first 24 hours

Order matters more than tools. Anyone who cleans first and only then closes access is sweeping while the door is open.

  • Put the site in maintenance mode or take it offline at the host so visitors are no longer served malware.
  • Change passwords for hosting, WordPress admin, database, FTP/SFTP and mailboxes tied to the site.
  • Find a backup from before the breach. A backup taken after the hack is a copy of the problem.
  • Check user accounts: remove unknown administrators; put remaining accounts on strong passwords.
  • Look in the files for recently changed PHP files you did not place yourself, especially in wp-content and the root.
  • Update WordPress, theme and plugins after isolation, not as the first action on a live hacked site.
  • Report it to your host. Some attacks sit at server level and are not visible from WordPress.

What most people do first — and should not

Installing a security plugin on an already hacked site rarely removes the back door. The same goes for "hack cleanup" plugins that create extra accounts. Isolate first, then restore from a clean backup or a clean reinstall with your content.

After the first day

The most common WordPress problems after a hack are: a back door that returns, SEO spam in invisible pages, and compromised mailboxes. Plan a check of search results, Google Search Console and cron jobs.

Prevention is updates, few plugins, strong accounts and backups with a restore test. Care at OmniTechs covers platform updates and backups on delivered work, with response on business days. It is not a WordPress helpdesk for every site.

Frequently asked questions after a WordPress hack

What are the most common WordPress problems?

Outdated plugins, weak accounts, no backup, and themes or plugins from unknown sources. Those four explain most publicly described incidents.

Can you recover my hacked WordPress site tonight?

No. OmniTechs has no 24/7 availability and no emergency service for arbitrary WordPress sites. If the site is under Care, we respond on business days within the published response time.

How do I maintain my WordPress website?

Updates, accounts, backups, remove unused plugins. That is basic operations, not a retainer promise.

Checklist first. Promises later.

If OmniTechs delivered the site, Care is the route for updates and backups on business days. For a hack tonight, the host or an incident partner is the right first call.