WordPress Was Hacked: The First 30 Minutes Without Destroying Evidence
Contain a hacked WordPress site in the first 30 minutes while preserving logs, backups, access evidence, customer safety and a recoverable copy.
SPECIALIST DIAGNOSTIC GUIDES
Incident-response guides for malicious redirects, unknown accounts, injected scripts, spam pages, suspensions and stolen credentials.
START WITH THE VISIBLE SYMPTOM
Choose the symptom closest to what you see, collect the evidence and follow a controlled route to verification.
Preserve evidence and locate conditional redirects across files, data, scripts, DNS and edge rules.
Explore the guides 02Map staff, administrator, hosting and integration access before rotating exposed credentials.
Explore the guides 03Separate indexed payloads, persistence and the original entry point before requesting removal.
Explore the guides 04Find scheduled tasks, data injections and stolen credentials that survive a superficial cleanup.
Explore the guides 05Contain abusive sending or hosted content while preserving logs needed to define the scope.
Explore the guides 06Restore from trusted sources, close the evidenced entry point and verify integrity over time.
Explore the guidesContain a hacked WordPress site in the first 30 minutes while preserving logs, backups, access evidence, customer safety and a recoverable copy.