Active incident or hacked WordPress? Ransomware Hacked WordPress 423-888-0252 · 828-484-1257

Do not wipe yet

WordPress hacked? Do not wipe the site yet.

Casino titles, a host malware flag, an unknown admin, or a Google warning — the panic move is to wipe the account or restore last night’s backup. That often destroys evidence and puts the injector right back. Avery Parker / Diversified Tech Solutions: calm first-hour steps, then professional cleanup when you need it.

Request cleanup See packages 423-888-0252

What this usually is

A blind wipe or a dirty restore feels decisive. It usually is not. The malware is often in a must-use plugin, a modified theme file, a wp-config.php include, or a database option that regenerates spam. Deleting the visible mess without a clean off-server backup leaves you with no forensic copy and no proof for a board, insurer, or Google review. Host “malware cleanup” that deletes three files and leaves the dropper is not the same as a written incident report.

What you are probably seeing

  • You are about to wipe, restore, or “start over” because Search looks wrong or the host flagged malware
  • Someone already ran a one-click host cleanup and the spam or redirect returned
  • You have no off-server backup from before the changes
  • Staff want to delete unknown admins, odd plugins, or spam posts immediately
  • Ads are still sending traffic onto junk or redirected pages

What not to do

  • Do not wipe the hosting account, rebuild from a blank theme, or restore yesterday’s backup until you have a full files+database copy stored off the server.
  • Do not delete logs, odd users, or mystery files “to clean up” before someone documents them — you are erasing the trail.
  • Do not install three security plugins on a still-compromised site, or click update-all as the cleanup.
  • Do not treat a host one-click malware tool as a finished incident report. Ask them not to wipe until you have a backup you control.
  • Do not request a Google Safe Browsing or Search Console review while the injector is still live.

What we actually do

First hour for owners: confirm symptoms, screenshot alerts and odd URLs, list who has admin/hosting/DNS/email access, take a full backup off-server, then decide DIY vs professional IR. If visitors are being harmed, maintenance mode can wait — but only if you can still reach admin or hosting afterward. Active fire? Call 423-888-0252 or 828-484-1257. Published cleanup packages with a written report live on the WordPress IR hub — see current IR package on site (no DIY full-clean promise on this page).

Published rates live on the WordPress incident-response packages page: Phase A from $2,500, Phase B from $2,000, combined from $4,200. Remote nationwide. Onsite in the Tri-Cities and Western North Carolina if you want someone in the room. If the WordPress site is the front door to a larger business compromise, start at emergency incident response instead.

WordPress incident response on a Linux shell

If this is your WordPress site

Why not wipe and rebuild?

You lose evidence, SEO history, and often the only copy of what was planted. Rebuilds also skip finding the door — so the next theme gets reinfected. Cleanup with a backup first is usually the sane order.

The host already offered a free malware cleanup.

Take the backup first. Host tools can help, but they are not a substitute for finding the injector and writing down what changed. If the spam returns in two days, you still need a real pass.

Should I put the site in maintenance mode?

Only if visitors are being actively harmed and you can still reach admin or hosting afterward. A store with spam on an inner page does not always need the whole cart offline — see the hacked WooCommerce page.

Where is the full printable checklist?

Free printable owner triage checklist: /wordpress-compromise-checklist/ (direct PDF download). Active fire: 423-888-0252 or 828-484-1257.

Need the site cleaned without taking the store down?

Tri-Cities 423-888-0252 · Western NC 828-484-1257