01Do these in order
Take the site offline
A site serving spam harms you every hour it stays up. Maintenance mode or a host-level suspension is fine.
Rotate every credential
Hosting panel, database, admin login, SFTP, API keys, from a device you trust.
Snapshot before cleaning
Files and database. Your host, developer or insurer may want proof of what happened.
Restore or engage a cleaner
A trusted pre-infection backup if you have one. Otherwise a specialist service, asked to state the entry point.
Patch everything before relaunch
Core, plugins, themes. Then watch: a re-infection within weeks means a backdoor survived.
02What a cleanup actually buys
03Do these in order
New here? Start at the pillar page for the full picture.
Take the site offline. A site serving spam harms you every hour it stays up, and maintenance mode is fine. Rotate every credential from a device you trust: hosting panel, database, admin login, SFTP, any API keys. Snapshot the files and database before anything gets cleaned, because your host, developer or insurer may want proof. Restore from a backup made before the infection if you have one you trust. Otherwise pay a cleaning service, and ask them to state whether they found the entry point. Patch core, plugins and themes before coming back online. Then watch, because a re-infection within weeks means a backdoor survived.
04What a cleanup actually buys
A good service removes injected files, database spam and known backdoors, and tells you what they found. That is worth a few hundred dollars and we recommend it over DIY for anyone who has never read WordPress malware. What it is not: a guarantee. Without the entry point identified, "cleaned" means clean until the next scripted scan finds the same hole. The hole was nearly always a plugin, a nulled theme or an old core version, which means the hole comes back with the next update cycle.
05When to stop cleaning and rebuild
First infection on a site you keep current: clean it, harden it, move on. Second or third infection, or a site that is mostly static pages anyway: the maths changes. Every cleanup ends with advice to update fewer plugins and lock things down, and every month after brings the same obligation back. If your content is pages people read, rebuilding the same site as static files takes the whole category away: no PHP to inject into, no database to dump, no admin screen to brute force. What that rebuild involves is smaller than the cleanup you just paid for, and why the infections repeat is worth understanding either way.
06Frequently Asked Questions
Will Google punish my site?
Google flags sites serving spam or malware with a warning in results and a ranking hit until you clean it and request a review in Search Console. Fast, complete cleanup shortens that window. Slow, partial cleanup extends it.
Can I find out how they got in?
Sometimes. Access logs, file modification timestamps and the plugin list narrow it down. The honest common answer is a vulnerable plugin found by a scripted scan, which means any site on the same stack was a candidate.
Is my host at fault?
Hosts patch the server. The WordPress application is the tenant's responsibility, and that is where nearly all compromises land. It is a property of the model, not of your host in particular.
Will my content survive a rebuild instead of a cleanup?
Posts, pages and images export out of WordPress. The migration guide covers what carries over, what needs rebuilding and how to keep old URLs working.
Build it with your AI. Host it here.
Deploys on every push, from Australia, with nothing to maintain.