Synthetic Industry

Job wp-restore-clean-backup-after-hack · revised 11 October 2026

Restore a hacked WordPress site from a clean backup and verify it

Rebuild one compromised WordPress site from fresh core files and a backup dated before the earliest evidence we find, check it against official checksums, and give you a credential reset list.

You might be seeing

  • Visitors are sent to pages you did not create, or the site shows a defaced or spam page
  • The host has emailed about malware or suspended the account
  • New administrator users or unfamiliar PHP files have appeared
  • You have backups but do not know which one is safe to restore

No passwords, keys, card details or admin invites needed to start.

What usually happened

After a WordPress compromise the quickest safe route is often to rebuild from official files and a backup taken before the problem began, rather than hunting through infected files. But a restore alone does not close the hole the attacker used, can bring a backdoor back if the backup was already infected, and leaves the old passwords working. It helps only if the backup is older than the earliest sign of the compromise we can find and the result is checked. Even then we cannot rule out that the compromise began before that sign, so a dated backup is not proof that it is clean.

Who it’s for: Owner of a small business whose WordPress site was defaced, redirects visitors, sends spam or was flagged by the host, and who has at least one backup from before it happened.

Usually starts when: Your host suspended the site, a browser or search engine shows a warning, customers report odd redirects, or you found files and users you did not create.

The result: The site runs from a backup dated before the earliest evidence of compromise we can find, on fresh core files that match WordPress.org checksums, with plugins hosted on WordPress.org checked the same way, unexplained files and users removed or explained, and a credential reset list completed by you. This is not a statement that the site is free of malware.

Check whether this job fits

Four questions, about two minutes. Your answers stay on this page unless you choose to email them.

Do you know when you first noticed a problem?
Do you have a backup from before then?
Does the site take payments or hold customer accounts?
Has the host said other sites on the account are affected, or suspended the account?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Send an enquiry about this outcome

Checks you can run yourself

  1. Record what you see without changing anything

    Note the date and time you first noticed the problem, take screenshots of anything odd, and list the backups you have. Do not delete files yet.

    Look for: Dates matter most. They decide which backup we can choose. Send them with your enquiry.

What you get

  • A timeline note and the reason the chosen backup was picked
  • A verification report: checksum results for core and for plugins hosted on WordPress.org, unexplained files, and plugins and themes that could not be checked
  • The administrator list marked by you as expected or removed
  • A credential reset list for you to complete: host, database, file transfer, every WordPress user and the site's secret keys

Included

  • One single-site WordPress installation on one host, with up to 10 GB of files and a 2 GB database
  • Building a timeline from the host's notices, file dates and your reports, and choosing the newest backup that predates the earliest evidence we can find
  • Restoring to a clean, non-public location first, replacing wp-admin, wp-includes and the core files in the site root with fresh files of the same version (the old copies of the two folders removed first), and re-installing plugins and themes from their original sources, using any premium packages you supply
  • Checking core files with wp core verify-checksums and plugins hosted on WordPress.org with wp plugin verify-checksums --all against their official checksums, and listing every plugin or theme that cannot be checked, including themes and plugins from elsewhere
  • Listing PHP files that do not belong in the uploads folder or the site root, and files in wp-admin or wp-includes that are not in the official package for that version, because the checksum commands are not documented to report extra files; reviewing administrator users with you, and updating everything after the restore

Not included

  • Forensic investigation of how the attacker got in, or any promise that it cannot happen again
  • A guarantee that the site is free of malware
  • Legal, regulatory or customer-notification advice if personal data may have been taken: that is for you and your adviser
  • Search-engine or browser warning reviews, which only the site owner can request
  • Cleaning other sites on the same hosting account or fixing the host's server
  • Buying premium plugin or theme licences, which you hold: a premium plugin or theme for which you supply no package is listed as not re-installed

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. The chosen backup is dated before the earliest evidence of compromise we can find, and the timeline note names that evidence and its source. This dates the backup against the evidence we have; it does not show that the backup is clean.

    Evidence: The timeline note and the backup date

  2. Run on the restored copy, wp core verify-checksums reports success for the installed version and language, and wp plugin verify-checksums --all reports each plugin hosted on WordPress.org as verified. Every plugin or theme that cannot be checked, including themes and plugins not hosted on WordPress.org, is listed with its source. These commands cover only files WordPress.org publishes checksums for: they say nothing about the database or about files they do not list, and they do not show that the site is free of malware.

    Evidence: The output of both commands and the list of unchecked items

    wp core verify-checksums; wp plugin verify-checksums --all
  3. Every PHP file in the uploads folder or the site root that is not part of WordPress, a plugin or the theme, and every file in wp-admin or wp-includes that is not in the official package for that version, is removed or explained, and every administrator is marked by you as expected or removed.

    Evidence: The file list and your marked administrator list

  4. The ten agreed pages, one form submission and one staff login pass on the restored copy before it goes live.

    Evidence: The test sheet with a result and screenshot for each item

Sign-off. You sign off after reading the verification report, completing the credential reset list and seeing the agreed tests pass. Sign-off is not a statement that the site is free of malware.

If it fails. If no clean backup can be found or the verification shows the compromise reaches beyond this site, we stop, tell you why and what the host or an investigator must do, and you do not pay for a restore that did not pass its agreed checks. There is no separate diagnosis or investigation charge in this job.

When it fits, and when we stop

It fits when

  • At least one backup exists that predates the first symptoms, held by you or your host
  • You can rotate the host, database, file-transfer and WordPress passwords yourself, or will follow our list
  • Only this site is affected, or other sites on the account are confirmed clean by their owners

We stop and tell you if

  • No backup predates the first symptoms, so any restore would carry the problem
  • The compromise reaches the hosting account or server, which the host must deal with
  • Customer or payment data may have been taken: pause and take advice before restoring
  • The site is a shop with live orders or a Multisite network

What could go wrong

The snapshot of the compromised site is kept in a private, non-public location until you sign off, so a restore can be undone, and is deleted then. Nothing goes live until you approve. We suggest you also keep your host's own copy of the previous files, outside the public web folder, for 14 days before deleting it yourself.

Scroll the table sideways to read it all.

RiskHow we handle it
The chosen backup already contains a backdoor.The backup is chosen only if it predates the earliest evidence we can find, core is replaced with fresh files, and every file we cannot verify is listed for you. We cannot rule out that the compromise began before that evidence, so we say plainly that a dated backup is not proof that it is clean.
The attacker returns through the same weakness or stolen password.You rotate every credential from a written list and update every component; we say plainly that we have not investigated the entry point.
Content added since the backup is lost.The list of changes since the backup date is produced from the snapshot so you can decide what to re-enter.

A second reviewer, separate from the work that produced the change, checks it against the evidence before you are asked to apply or approve it. No human supervisor is included unless your proposal names one. At launch much of the preparation is automated, and we say so.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Preserve a snapshot of the current site and build a timeline from the host's notice, file dates and your reports
  • Choose the newest backup that predates the earliest evidence we can find, and record why
  • Restore it to a non-public copy, replace wp-admin, wp-includes and the core files with fresh files of the same version (removing the old copies of the two folders first), and re-install plugins and themes from their original sources
  • Verify core with wp core verify-checksums and plugins hosted on WordPress.org with wp plugin verify-checksums --all; list what cannot be checked; list unexplained PHP files and any extra file in wp-admin or wp-includes
  • Review administrator users with you, update everything, switch off the dashboard file editor, and test pages, form and login
  • Hand over the report and the credential reset list; you reset every credential and approve the switch to live

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

To keep backups tested and updates applied, ask about the standing WordPress responsibility.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • WordPress's own guidance for a hacked site covers documenting the problem, resetting every password, replacing core files with fresh ones of the same version and scanning. A site owner comfortable with file transfer can follow it. wordpress.org
  • Your host may restore a backup in its panel for free. That is a good first step, provided the backup is older than the problem and you still rotate every credential afterwards.

Questions

Can you promise the site is clean afterwards?

No. We verify what can be verified, list what cannot, and rebuild from files and a backup dated before the earliest sign we can find. We cannot rule out that the compromise began earlier, and we do not claim the site is free of malware.

What do the checksum checks prove?

That core files, and the files of plugins hosted on WordPress.org, match what WordPress.org publishes for that version. They do not cover themes or plugins from elsewhere, the database or files they do not list, and a match is not a statement that the site is clean.

Will it happen again?

It can. A restore does not by itself close the weakness that was used. Updating everything, removing what you do not use and resetting passwords reduces the risk, and the hardening job is a natural follow-on.

What if customer data was taken?

That may bring legal duties, which are yours to decide with an adviser. We stop and wait for you before restoring.

Send an enquiry

Send us

  • The site address, the host and what you noticed first, with dates
  • Any message from the host, with personal details removed
  • A list of the backups that exist and their dates, and where they are stored
  • Whether the site takes orders or holds customer data

Later, once you agree

  • The selected backup and a copy of the current site, handed over only by a secure route agreed with you first; the work cannot start until that route is agreed, and no site copy is requested in the first enquiry
  • Premium plugin and theme packages or licences you hold, for anything not available from WordPress.org
  • Access to the host panel or secure file transfer scoped to this site, or a person who will apply our steps
  • The ten pages, one form and one login to test
  • No live passwords or customer records by ordinary email

The site, host and every account stay in your name. We work on a copy first, keep no copy after sign-off, and you reset every credential yourself, so we never hold the new ones.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “wp-restore-clean-backup-after-hack” as the subject.