The SOP Library / Websites
Hack Cleanup & Hardening
Contain, clean, harden — the emergency runbook for compromised sites, from spam injection to full takeover.
- 1
Contain: snapshot the compromised state, rotate every credential, take forms offline if data is at risk.
- 2
Inventory damage: injected posts/pages, rogue admin users, modified core files, scheduled tasks/backdoors.
- 3
Clean: remove injections via API/database (logged), delete rogue users, reinstall core/plugins from source.
- 4
Verify: diff against clean source, scan again, confirm no backdoor respawns in 48h.
- 5
Harden: 2FA, login limits, file-edit off, least-privilege users, updated everything.
- 6
Recover search: remove hacked URLs via Search Console, submit reconsideration if flagged, monitor for re-infection 30 days.

- No respawn after 48h
- All credentials rotated
- Search Console clean
This is the procedure your clients get when you resell it — delivered under your brand, reported by the 5th.
Sell this as yours →