Do not keep editing or repeatedly restoring at random
Each change can overwrite evidence or the last usable copy. Record what happened, when it began and the last known-good time before attempting recovery.
Immediate response
Contain the problem safely
- Take screenshots and record the exact error, suspicious URL or unwanted redirect.
- Do not delete suspicious files until a copy and relevant logs are preserved.
- If the site is actively harming visitors, suspend or password-protect it without deleting content.
- Change compromised administrator credentials from a clean device, but keep a record of what was changed.
- Do not announce that the site is clean until files, database, users and scheduled tasks have been checked.
Choose a recovery route
Restore or investigate?
- Known accidental change
- Restore the smallest affected item from a backup made before the change.
- Failed update
- Use the application's recovery process or a verified pre-update backup, then update safely.
- Suspected malware or hack
- Do not merely restore: identify the entry point, remove persistence, rotate credentials and patch the cause.
- No usable backup
- Request recovery assistance. Some content may be recoverable from server data, caches or intact database tables, but it cannot be guaranteed.
UKC assisted recovery
Priority Security Recovery
The current service covers malware and hack cleanup, malicious-file removal, access resets, theme and plugin updates, hardening and testing before reactivation. The current price and service terms are shown securely in the cart.
View Priority Security RecoveryA backup is a recovery source, not proof the site is safe
A restored copy may contain the original vulnerability or dormant malicious code. Update the application, remove abandoned components, rotate credentials and scan again before reopening it.
Help us act quickly
Include useful evidence in the request
- Domain, hosting service and affected application.
- Exact symptoms, first observed time and last known-good time.
- Recent updates, uploads, administrator changes or security alerts.
- Known backup dates and whether any restore has already been attempted.
- URLs, screenshots and relevant scanner output without exposing passwords or secret keys.
Need urgent recovery guidance?
Open one ticket with the evidence above and avoid making parallel changes while it is investigated. Never paste passwords, private keys or full database exports into a ticket.
Contact the Security team