Learning Hub · Advanced · half a day, done right
How to Clean Up a Hacked Website
Full recovery — not just symptom removal — after a compromise — a practical, no-jargon walkthrough with the classic mistake flagged before you make it.
The short answer
Goal: full recovery — not just symptom removal — after a compromise. Time needed: half a day, done right. Difficulty: advanced.
The walkthrough below covers each step, the mistake most people make, and the shortcut worth knowing. On HostingAlly plans, several of the steps are handled for you — we note where.
Advanced
Difficulty
Quick
Time needed
5
Steps
24/7
Help if you're stuck
You don't need to be technical for this — the walkthrough is written for first-timers, tested against our own platform, and honest about which parts are genuinely fiddly versus merely unfamiliar.
Rule of the road: read the gotcha section before you begin, not after — it's harvested from the support tickets of people who didn't.
What you'll do, at a glance
The whole job breaks into clear stages: contain first, restore to a pre-compromise point, close the entry hole, sweep for persistence and rehabilitate externally.
Each stage is a few minutes of focused clicking — the elapsed time mostly depends on how familiar the control panel already feels. The detailed steps are listed further down this page; skim the whole route once before starting.
The classic gotcha
Restoring the newest backup — which was taken after the compromise and restores the infection with archival fidelity; the restore point must predate the breach, even at the cost of more lost content.
Forewarned is genuinely forearmed here — this exact mistake accounts for most of the frustration this topic produces, and it's entirely avoidable once named.
The tip we give everyone
Preserve a copy of the infected state before cleaning (zip it, download it) — if questions arise later (how they got in, what they touched), the evidence exists instead of having been helpfully destroyed.
It costs a minute now and repays it every time this task comes around again — which, like most hosting tasks, it will.
What's automated here
Several steps in this guide exist because hosting historically made you do them — on our plans, SSL issues itself, backups run daily without being asked, and one-click installers replace manual setup entirely. What remains is the genuinely-yours part of the task.
Stuck mid-task at an odd hour? That's what 24/7 human support is for — describe where you are in this guide and we'll take it from there.

The platform this guide assumes
Tutorials age badly when they're written against imaginary hosting. These are written against ours — the same panel, installer and defaults you'll actually see.
NVMe storage and LiteSpeed caching are standard here, not premium-tier extras.
- Step-by-step, tested as written
- The gotcha flagged before you hit it
- Automation covers the boring steps
- 24/7 support if you get stuck
Why HostingAlly
What you get with every plan
No jargon tax
Terms are explained in place or linked to the glossary — nothing assumes you already know.
Help on standby
Stuck at step three at midnight? Support answers around the clock, mid-guide included.
Automation where it belongs
SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.
Written from real tickets
Our guides come from the support desk — the gotchas are the ones people actually hit.
The undo is always named
Where a step could bite, the guide says so and gives the reversal.
Works as written
Every step tested on our own platform — no 'your host may vary' hand-waving.
Getting Started
How to get going
- 1
Contain first
Maintenance-mode the site and change hosting, database and admin passwords immediately — cleanup during active attacker access is bailing with the tap running.
- 2
Restore to a pre-compromise point
The cleanest recovery is a backup that predates the breach — identify the intrusion window from file timestamps and logs, and restore behind it.
- 3
Close the entry hole
The vulnerable plugin, stolen credential or outdated component that admitted the attacker must be updated or removed — restoring without this schedules the sequel.
- 4
Sweep for persistence
Rogue admin users, unfamiliar files in uploads, modified .htaccess, planted forwarders — attackers leave return routes; the audit is what actually ends the incident.
- 5
Rehabilitate externally
Request review in Search Console if flagged, resubmit sitemaps, monitor for a fortnight — reputation recovery follows technical recovery.
Included
What's covered on our plans
- Email accounts on your own domain
- Free website migration handled by our team
- Daily automatic backups with self-service restores
- 24/7 support from real people
- 99.9% uptime commitment, monitored around the clock
- Per-site PHP version selection
- SSH, Git and Composer access on developer-friendly plans
- One-click installer for WordPress and 400+ apps
- LiteSpeed server-level caching
- No setup fees, ever
FAQ
Your questions, answered
Can I just run a cleaner plugin instead of restoring?
In-place cleaning is possible but demands expertise — malware hides in databases and legitimate-looking files, and missed persistence means recurrence. Restore-plus-patch is the reliable civilian path; in-place is for practitioners.
How do I find out how the site was hacked?
File modification times bracket the intrusion; access logs around that window show the requests; the targeted URL usually names the vulnerable component. It's honest detective work — and support can help read the logs.
Is SSL really included at no cost?
On every plan, with no exceptions — certificates are issued automatically when your domain points to us and renew themselves before expiry. The encryption is identical to paid DV certificates; paid tiers exist only for wildcard convenience or organisation-level validation.
Are backups included, and can I restore them myself?
Daily automatic backups are standard, restorable from the panel in minutes — files, databases or both, at 3am without a ticket if that's when you need it. For extra cover, you're welcome to run your own offsite copies alongside.
Do you include email with hosting?
Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.
Which control panel do you provide?
cPanel — the industry standard, which means every tutorial on the internet matches your screen, your backups restore anywhere cPanel runs, and skills learned here transfer for life. Plesk and DirectAdmin options exist on specific plans for those who prefer them.
Is there a money-back guarantee?
Yes — try the hosting properly and if it doesn't fit, the refund process is a request, not a retention gauntlet. Domain registrations are the one standard carve-out, since registries make those non-refundable the moment they're placed.
Keep exploring
How to Enable WHOIS Privacy
Keep your personal details out of the public domain record — beginner level, 2 minutes.
How to Set Custom Error Pages
Turn dead ends into branded, useful detours — beginner level, 30 minutes.
Domain Names
Search, register and transfer domains — first year free on annual hosting.
Web Hosting
NVMe cPanel hosting with free SSL, migration and a free first-year domain.
Launch it properly this time.
From your first site to a fleet of servers, the upgrade path is an account change, not a migration.
See Hosting Plans