Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Advanced · half a day, done right

How to Clean Up a Hacked Website

A proper recovery after a break-in, not just the visible mess swept away — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

The job: a proper recovery after a break-in, not just the visible mess swept away. Time to allow: half a day, done right. Skill needed: advanced.

The walkthrough below covers every step, the mistake most people make, and the shortcut worth keeping. On Hosting Seller plans several of these steps are already done for you, and we say where.

Written by the Hosting Seller staff · Checked 1 August 2026

Advanced

Difficulty level

Quick

Time to allow

5

Stages

24/7

Help at any hour

You do not need to be technical for this. The walkthrough is written for first-timers, tested on our own platform, and honest about which parts are genuinely fiddly and which are merely unfamiliar.

Rule of the road: read the snag section before you begin rather than after. It is harvested from the tickets of people who did it the other way round.

The whole job at a glance

The job breaks into a few clear stages: shut the door first, go back to before the break-in, close the way they came in, hunt for the way back in and repair the outside picture.

Each stage is a few minutes of steady clicking — the time it takes depends mostly on how familiar the control panel already feels. The detailed steps sit further down this page; skim the whole route once before you begin.

The classic snag

Restoring the newest backup — the one taken after the break-in, which puts the infection back with perfect accuracy. The restore point has to predate the breach, even when that means losing more content than you would like.

Forewarned really is forearmed here. This one mistake accounts for most of the frustration the subject produces, and it is entirely avoidable once somebody names it.

The tip we hand out to everybody

Zip the infected site and download it before you clean anything. When the questions come later — how they got in, what they touched — the evidence still exists instead of having been helpfully destroyed.

It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.

What runs by itself here

Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.

Stuck halfway through at an odd hour? That is exactly what round-the-clock human support is for — tell us where you are in this guide and we will pick it up from there.

A shield icon standing in for site security and DDoS filtering

The hosting this guide is written against

Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.

NVMe disks and LiteSpeed caching sit on the shelf at every price point, not behind a premium tier.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

The snag, named early

The classic mistake for this exact job is flagged before step one, so half a day, done right stays half a day, done right.

Scoped honestly

A proper recovery after a break-in, not just the visible mess swept away is a advanced-level task — this guide budgets half a day, done right and says which steps the platform absorbs.

No jargon toll

Terms are explained where they appear or linked to the glossary — nothing assumes you already know.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

Help on the counter

Stuck on step three at midnight? Support answers at any hour, mid-guide included.

The undo is always named

Where a step could bite, the guide says so and tells you how to put it back again.

First Steps

From choosing to live

  1. 1

    Shut the door first

    Put the site in maintenance mode and change the hosting, database and admin passwords straight away. Cleaning while the attacker still has access is bailing out a boat with the tap running.

  2. 2

    Go back to before the break-in

    The cleanest recovery is a backup taken before the breach. File timestamps and logs give you the window; restore to a point safely behind it.

  3. 3

    Close the way they came in

    The vulnerable plugin, the stolen password or the outdated component has to be updated or removed. Restoring without this simply books the next incident in advance.

  4. 4

    Hunt for the way back in

    Unfamiliar admin users, stray files in uploads, an edited .htaccess, mail forwarders you never set. Attackers leave routes home, and finding them is what actually ends the incident.

  5. 5

    Repair the outside picture

    Request a review in Search Console if you were flagged, resubmit the sitemap, and keep watching for a fortnight. Reputation recovers after the technical work, not at the same time.

In the Box

Packed with every plan

  • A 99.9% uptime commitment, watched by monitoring day and night
  • NVMe SSD storage on every shelf, not just the top one
  • Mailboxes that carry your own domain name
  • One-click installs for WordPress and 400+ other applications
  • DDoS filtering handled out at the network edge
  • Webmail in the browser plus IMAP, POP and SMTP for your own client
  • Staging copies so changes get tested before they go live
  • The renewal price printed on the tag matches the order price
  • A domain free for year one when you order annually
  • A 30-day money-back guarantee on every hosting plan

Across the Counter

The questions we get asked most

Can a clean-up plugin do this instead?

Cleaning in place is possible, but it takes real experience. Malware hides in the database and inside files that look entirely legitimate, and one missed backdoor brings it all back. Restore-and-patch is the reliable route for most owners; in-place cleaning is a specialist's job.

How do I work out how they got in?

File modification times bracket the intrusion, access logs from that window show the requests, and the address they hammered usually names the component that let them through. It is straightforward detective work, and support can help you read the logs.

Does the price climb when the term is up?

No. What you pay to order is what you pay to renew, year after year. We do not run teaser rates, so there is no year-two ambush waiting in the calendar, and your bookkeeping can treat the hosting line as a fixed number.

Does hosting come with mailboxes?

It does — mailboxes on your own domain ship with every hosting plan, with webmail, IMAP, POP and SMTP access and spam filtering fitted as standard. There is also standalone email hosting for domains whose website lives somewhere else entirely.

Can I bring a domain I already own?

Yes, and transfers in are routine. Unlock the name at your present registrar, collect the auth code, then start the transfer from your client area. Whatever registration time is left comes across with it, and DNS keeps answering the whole way through.

Can I test changes somewhere safe first?

Yes — plans with staging let you clone the live site, work on the copy, then push it across when you are satisfied. It is the difference between hoping an update behaves and knowing that it does before any customer meets it.

How do I pay, and does it bill again on its own?

Orders go through a secure checkout by credit or debit card, and the renewal is taken at the same price you first paid. Every invoice sits in the client area for you to read, and switching auto-renewal off is a toggle in your account rather than a phone call.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Start on a plan with a plain price tag.

From a first website to a rack of servers, moving up is a change to your account rather than a migration.

See the plans