Suggestions in Case of Hacking
Updated 5 days ago
There are various methods hackers use to gain access to your site, whether to send spam or create pages with advertisements, but the most common are:
Using outdated WordPress, plugins, or themes. Many plugins or templates, especially those without a license, are not updated, making them vulnerable to security issues that have already been resolved. That is why we always recommend keeping everything 100% up to date.
An admin user or an easy-to-guess password. Brute-force attacks repeatedly attempt to access your site using different passwords, trying thousands of times automatically until the password is guessed.
If you detect a security issue on our site and cannot access it, we recommend the following:
Change the password for accessing your control panel and customer portal. Also consider enabling two-step verification.
Access your control panel and reinstall the default WordPress files from WordPress Management, Check WordPress integrity, and then click "Reinstall WordPress core".
Try accessing your site the traditional way, or by accessing it via Softaculous.
Make sure WordPress, plugins, and themes are 100% up to date.
Remove any unlicensed plugin or theme (these two things are the main causes of security issues).
Check the list of administrator users and reset the access credentials.
Install and configure the free version of Wordfence.
Perform a complete scan of our site, removing all files unrelated to WordPress.
Disable any plugin that Wordfence detects as abandoned, unsupported, or no longer receiving updates.
Finally, through Wordfence, we can increase the security of administrator access to our site by using two-factor authentication with an authentication app such as Google Authenticator or Authy, as explained in the guide on enabling two-step verification.
If Google has indexed a different version of our site, we must add it to Google Search Console to identify any issues, resolve them, and inform Google so that it can restore the correct version of our site.