Walkthrough · Advanced · half a day, done properly
How to Clean Up a Hacked Website
How to a real recovery from a break-in rather than the visible damage tidied away, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.
The short answer
The job: a real recovery from a break-in rather than the visible damage tidied away. Time to set aside: half a day, done properly. Skill needed: advanced.
Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.
By the Hosting & Domains team · Reviewed 18 August 2026
Advanced
Experience required
5
Stages, start to finish
Free
Support included
Proven
On the platform itself
No technical background needed. This walkthrough was written for first-timers, proven on our own hardware, and honest about which parts are genuinely tricky rather than merely unfamiliar.
First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.
The whole job in one view
The work falls into a few clean stages: shut the intruder out, roll back past the intrusion, close the way in, hunt down the planted back doors and rebuild the public standing.
Every stage is a few minutes of unhurried clicking — the total depends mostly on how well you already know the control panel. The detailed instructions are further down; read the whole path once before you begin.
The well-worn snag
Restoring the newest backup, taken after the break-in, so it reinstates the infection with perfect fidelity. The restore point has to come before the breach, even when that means giving up more content than you would like.
Forewarned is genuinely forearmed here. This one mistake accounts for most of the frustration the topic ever causes — and it disappears entirely once somebody points it out.
What we tell every customer
Zip and download the infected site before you touch anything. When the questions come later, about the route in and the extent of the damage, the evidence still exists instead of having been helpfully erased.
A minute spent now repays itself every time this job comes round again — and like almost every hosting job, come round it will.
The parts that look after themselves here
Some steps in this guide exist only because hosting traditionally forced them on you. Here the SSL issues itself, the copy is taken daily without being asked, and one-click installers remove the manual setup. What is left is the part that was always genuinely yours.
Stopped mid-guide at an awkward hour? That is exactly what round-the-clock support is for — say which step you are on and we take it from there.

The hosting these steps were tested on
Every walkthrough in this library is run on the platform we actually operate — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen rather than gesturing at it from a distance.
Hosted somewhere else already? We move the whole site at no charge, usually within 24 hours, and it goes on answering visitors throughout.
- Every step checked exactly as published
- The snag named before it arrives
- The dull steps taken out of your way
- People reachable at any hour you stall
Why Hosting & Domains
Standard on every plan
The snag, flagged up front
The classic error for this particular task is named before step one, which is how half a day, done properly stays half a day, done properly.
Honest about how big it is
A real recovery from a break-in rather than the visible damage tidied away is a advanced-level job — set aside half a day, done properly, with the platform-absorbed steps marked.
Jargon never charges you
Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.
Works exactly as printed
Every step is proven on the platform we run — none of the 'your host may vary' hedging.
Help that keeps your hours, not ours
Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.
Every undo written out
Any step that could bite is marked, together with the exact way to wind it back.
Quick Start
Order placed to site online
- 1
Shut the intruder out
Put the site into maintenance mode and change the hosting, database and admin passwords at once. Cleaning while the intruder still has access is mopping a floor under a running tap.
- 2
Roll back past the intrusion
The cleanest recovery starts from a backup taken before the breach. Timestamps and logs mark out the window, so restore to a point well before it.
- 3
Close the way in
The vulnerable plugin, the harvested password or the stale component has to be patched or removed. Restoring without doing that simply books the next incident.
- 4
Hunt down the planted back doors
Admin accounts you do not recognise, odd files under uploads, a modified .htaccess, mail forwarders you never set up. Intruders leave themselves ways back, and removing those is what genuinely closes the incident.
- 5
Rebuild the public standing
File a Search Console review if you were flagged, resubmit the sitemap, and keep watching for a couple of weeks. Reputation returns after the technical repair, never at the same time.
Built In
Fitted to every plan
- A renewal figure identical to the one you registered at
- cPanel, which is what most of the industry already runs
- WordPress and 400+ further applications installed in one click
- 99.9% uptime as the target, watched around the clock
- Your existing site brought across by our engineers, at no charge
- People on the support desk every hour of every day
- Mailboxes that answer at the name you hold
- Staging copies for trying a change before it goes live
- Spam and virus screening on every mailbox by default
- WordPress Toolkit, with the updates seen to for you
Frequently Asked
The questions that come up most
Could a cleanup plugin do this for me?
Cleaning in place does work, but it takes real expertise. Malware nests in the database and inside files that look entirely plausible, and one missed backdoor brings all of it back. Restore-and-patch is the dependable route for most owners; removal in place is specialist work.
How do I find out how they got in?
Begin with file timestamps, which give you roughly when it happened. Then pull the access logs for that window: the endpoint being hammered repeatedly usually names the component that gave way. Ordinary detective work, and support will happily read the logs with you.
Will the renewal cost more than the first term?
No. The rate you order at is the rate you renew at, year after year. There is no introductory teaser here, so no second-year jump is waiting — the hosting line stays a fixed figure your accounts can plan around.
Does hosting include mail?
Yes — every hosting plan includes mailboxes at your own name, with webmail, IMAP, POP and SMTP plus spam filtering on from the start. There is standalone email hosting too, for a name whose website lives somewhere else.
Keep reading
How to Put WordPress in Maintenance Mode
Screen off work in progress until it's actually ready for an audience — beginner level, about 5 minutes.
How to Reduce Server Response Time
Shrink the pause before the very first byte departs the server — intermediate level, about an afternoon.
DNS (Domain Name System) (Glossary)
The full definition, along with the practical consequence nobody bothers to mention.
Web Hosting
cPanel hosting on NVMe drives — SSL, the migration and year one of the name all included.
WHMCS License
Automate billing, provisioning and support for hosting clients of your own.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Register it, then build on it.
Free SSL, a free migration, renewals billed at the original rate, and people on support around the clock. That is the whole of it.
View Web Hosting plans