Your website redirects to unfamiliar pages. How do you respond?
Unexpected redirects, pages you never created and unknown accounts warrant investigation into a possible compromise. Removing the visible symptom is not enough. Understand the scope, protect visitors and identify the entry point before considering recovery complete.
Record the signs and limit exposure
Save affected URLs, the time and observed behaviour. Ask your hosting provider about alerts or other affected applications on the same account. Depending on impact, temporarily suspending functions or displaying maintenance information may be appropriate. Avoid following suspicious destinations or downloading files simply to see what they contain.
Preserve evidence for diagnosis
WordPress guidance recommends investigation and recovery with attention to access and components. Collect available records before cleaning your own site. Keep an isolated copy of the compromised state for technical analysis without serving it publicly. Do not assume a recent backup is safe: it may already contain the malicious change.
- Inventory administrator accounts and hosting access.
- Record plugins, themes and recent updates.
- Investigate unexpected files and pages with technical support.
- Identify integrations and credentials that may have been exposed.
Recover from verifiable components
The intervention should distinguish application files, legitimate content and unauthorised changes. Restoring a known copy can help, but the cause and compromised access still need attention. Coordinate credential replacement in a sequence that avoids exposing new credentials to the affected environment. The scope of cleaning depends on diagnosis; a single automated check cannot cover every scenario.
Validate and monitor the return
Test pages, forms and administration after recovery. If search services show warnings, follow their review process after fixing the issue. Monitor unexpected file changes and accounts. The team should receive an incident record covering applied actions, reviewed access and the next maintenance plan.
Frequently asked questions
Can a security plugin clean everything?
It can help detect signs and support protection, but does not replace assessing the incident's scope, permissions and cause.
Should I send passwords with my support request?
No. Send the URL, symptoms and impact. Arrange required access through an appropriate channel with permissions limited to the intervention.
Reference documentation
A note from ArqWeb
This guide organises checks and decisions for a common situation. Implementation depends on the website, access and systems involved. We can assess your situation if you need help applying these steps.
Let's look at your situation.
Tell us what you need and what you have already. We will reply with next steps and a proposal suited to the work.
Discuss my requirements