Comparisons & Alternatives

My Site Was Hacked on Shared Hosting: What to Do Now

If your site was hacked on shared hosting, act immediately: change all passwords, scan for malware, and restore from a clean backup.

Three professionals discussing strategies at a whiteboard in an office setting.

If your site was hacked on shared hosting, your first move is to lock down access and change every password before touching a single file. Then follow a structured cleanup and hardening sequence so it doesn't happen again.

This guide walks you through exactly what to do, in what order, and which mistakes to avoid so your site doesn't get reinfected within days.

Why Sites Get Hacked on Shared Hosting

Shared hosting puts multiple accounts on the same server. When folder isolation isn't airtight, a compromised account can leak malware to its neighbors. The most common entry points are:

  • Outdated plugins or themes in WordPress, Joomla, or Drupal.
  • Weak passwords on cPanel, FTP, or the CMS admin panel.
  • Unvalidated upload forms that allow malicious PHP files to be uploaded.
  • Abandoned scripts — test pages, installers — left in place and never removed.

Identifying the entry point helps you close the right door once cleanup is done.

Step 1 — Contain the Damage Immediately

Before touching any file, shrink the active attack surface:

  1. Change your cPanel password via your hosting provider's dashboard — not from the compromised site.
  2. Change all FTP passwords, including any sub-accounts linked to the plan.
  3. Change database passwords and update the CMS config file (wp-config.php, configuration.php, etc.).
  4. Revoke active sessions: in WordPress, go to Users → Your Profile and click "Log Out Everywhere Else."
  5. If your site is actively serving pharma spam, phishing pages, or malware downloads, put it in maintenance mode while you clean.

Step 2 — Find the Infected Files

Using cPanel's File Manager or SSH (if your plan includes it), look for the classic signs:

  • .php files inside folders that should only hold images (/uploads/).
  • Files with random names like xzr4b.php or tmp.php.
  • Obfuscated code with base64_decode, eval, or gzinflate at the top of legitimate files.
  • Recently modified core files: sort by modification date and review everything that changed in the past few days.

Many hosts include a built-in malware scanner (Imunify360, SiteLock). Use it if available — it gives you a full list without having to inspect files one by one.

Step 3 — Restore from a Clean Backup

The safest path to a clean site is restoring from a backup that predates the infection. In cPanel, look for Backups or JetBackup:

  1. Find the most recent backup before the hack date. Check access logs to pinpoint when the breach occurred.
  2. Restore your site files and, if the database was also altered, restore it too.
  3. After restoring, don't stop there: apply all pending updates before bringing the site back online.

If you have no backup, you'll need to clean manually. Reinstall the CMS core from scratch, delete and reinstall plugins from official repositories, and review every theme file line by line.

Step 4 — Harden Your Setup So It Doesn't Come Back

Cleaning without hardening almost guarantees reinfection. The minimum hardening steps for shared hosting:

  • Update everything: CMS, plugins, themes. If a plugin can't be updated, uninstall it.
  • Set correct permissions: directories to 755, files to 644. Never 777.
  • Protect wp-config.php / configuration.php with an .htaccess rule that denies direct access.
  • Enable two-factor authentication on the CMS admin panel.
  • Install a security plugin (Wordfence, Sucuri, iThemes Security) with automatic scanning and IP blocking.
  • Limit login attempts to 3–5 before a temporary lockout.

If your current host doesn't offer account isolation, malware scanning, or daily backups, now is the right time to look at a more secure hosting provider.

Key Takeaways

  • Act fast: change all passwords before touching any files.
  • Restoring from a clean backup is safer than manual cleanup.
  • Cleaning without hardening almost always leads to reinfection.
  • Outdated plugins and weak passwords are the most common attack vectors.
  • A good hosting provider offers malware scanning, account isolation, and daily backups.

If your site is still giving you trouble after following these steps, or you want a professional security review, the team at elenlace.com can audit it and lock it down before you suffer another attack.

FAQ

How long does it take to clean a hacked site?

With a clean backup available, the process takes one to three hours. Without a backup and with a deep infection, a full day of manual work is realistic.

Is my hosting provider responsible for the hack?

It depends. If the vulnerability was an outdated plugin on your end, the responsibility is yours. If the host failed to properly isolate accounts and a neighboring site infected yours, the provider shares responsibility. Either way, you'll need to fix it.

Should I notify Google if my site was hacked?

Yes. If Google detects malware before you do, it will flag your site with a red warning in search results. After cleanup, go to Google Search Console → Security & Manual Actions and request a review to have the warning removed.

Is it worth hiring a professional cleanup service?

If you lack technical experience, yes. Services like Sucuri or a specialized agency can complete the cleanup in a few hours and guarantee results. The cost is almost always less than the reputational damage of leaving your site infected another day.

Prefer it done for you? El Enlace handles hosting and professional web development.

Compare providers

Other providers and guides worth comparing:

← All