The SOP Library / Websites

WEB-006Urgent: response inside 4 business hours

Hack Cleanup & Hardening

Contain, clean, harden — the emergency runbook for compromised sites, from spam injection to full takeover.

Server accessScannerSearch Console
The procedure
  1. 1

    Contain: snapshot the compromised state, rotate every credential, take forms offline if data is at risk.

  2. 2

    Inventory damage: injected posts/pages, rogue admin users, modified core files, scheduled tasks/backdoors.

  3. 3

    Clean: remove injections via API/database (logged), delete rogue users, reinstall core/plugins from source.

  4. 4

    Verify: diff against clean source, scan again, confirm no backdoor respawns in 48h.

  5. 5

    Harden: 2FA, login limits, file-edit off, least-privilege users, updated everything.

  6. 6

    Recover search: remove hacked URLs via Search Console, submit reconsideration if flagged, monitor for re-infection 30 days.

QA gates — nothing ships without
  • No respawn after 48h
  • All credentials rotated
  • Search Console clean

This is the procedure your clients get when you resell it — delivered under your brand, reported by the 5th.

Sell this as yours →
See PricingApply to Partner