My site keeps getting hacked after I clean it
Cleaning a site and watching it get reinfected a few days later is demoralizing, and it isn't a sign that you did something stupid. It's the normal outcome of removing what you can see without finding how they got in. Malware is the symptom. Until the entry point is closed and every piece of persistence is removed, the same attacker walks back in through the same door.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- You deleted the bad files, and the same infection is back a few days later
- Your scanner goes clean, then flags the same kind of file again the following week
- Spam pages or redirects return after you restore a backup
- Admin users you deleted reappear
- Your host has suspended the account more than once for the same reason
- Each round of cleaning takes less time to come undone than the last
Why it happens
A backdoor that was never found
Attackers almost always leave a small file that lets them back in without a password. It's usually not where the visible malware was: it can be in an uploads folder, a theme you don't use, or disguised as a legitimate WordPress file. Remove the malware and leave the backdoor, and reinfection is a matter of days.
Persistence you can't see from the dashboard
A hidden administrator account, a must-use plugin that never appears in the plugin list, or a scheduled task (WP-Cron or a server cron job) that quietly downloads the malware again on a timer.
The original vulnerability is still there
If the way in was an outdated plugin or theme, cleaning the files changes nothing about the hole. Deactivating a plugin isn't enough either, because vulnerable code left on disk can often still be reached directly.
The backup you restored is infected
Infections often sit quietly for weeks before doing anything visible. Restoring last month's backup frequently restores the compromise along with the content.
A neighboring site, or a credential they still hold
On shared hosting, several sites often live under one account and can read each other's files, so an infection next door reinfects yours within days. Hosting or SFTP passwords captured in the first compromise do the same job, with no vulnerability needed at all.
What to do right now
Do this
- Write down the dates: when you cleaned it, when it came back, and what came back. The pattern narrows down where the persistence lives
- Ask your host for access logs and file change timestamps covering the reinfection. They often show the exact request and file involved
- Change hosting, SFTP, database, and WordPress passwords, and list every other site on the same hosting account
- Check scheduled tasks and the must-use plugins folder, and list all administrator accounts
Don't do this
- Don't keep restoring backups. If the backup is infected, you're repeating the infection rather than fixing it
- Don't assume a clean scan means it's over. Scanners match known patterns, and a fresh backdoor is not a known pattern
- Don't delete the site and rebuild without finding out how they got in. A rebuild with the same plugin and the same passwords is hacked the same way
How we fix it
- 1Start with the timeline and the logs, so we're working from evidence of how the site was re-entered rather than guessing
- 2Sweep the whole install for persistence: backdoors, uploaders, rogue admin users, must-use plugins, scheduled tasks, and injected database entries
- 3Find and close the entry point itself, whether that's a vulnerable plugin, a stolen credential, or a neighboring site on the account
- 4Rotate passwords and security keys so every existing session and saved credential stops working
- 5Harden the site, then watch it after the cleanup. Every cleanup includes reinfection coverage, so if it does come back in that window we deal with it
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
I removed the malware myself and it came back. What did I miss?
Nearly always the backdoor and the entry point. Removing the files that were doing something visible is the right instinct, but the attacker's access usually survives in a separate, unremarkable-looking file, plus whatever hole let them upload it in the first place. That's why the second infection often looks identical to the first.
Should I just rebuild the site from scratch?
Sometimes a rebuild is the right call, especially if the site is old and the content is small. But it only helps if the cause is understood first. If the way in was a vulnerable plugin you reinstall, or a hosting password the attacker already has, a fresh site gets compromised the same way. We tell you honestly when rebuilding is the better option.
How do you know it won't come back after you clean it?
We can't promise any site will never be attacked again, and anyone who does is overselling. What we can do is find how it happened, close that route, remove every piece of persistence we find, and harden the site afterwards. Cleanups include a reinfection coverage window, and the ongoing plans include re-cleanups while you're subscribed.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)