When you discover a hacked site, the first impulse is often to delete everything suspicious as fast as possible. The problem: a lot of malware hides in or next to legitimate files, and a hasty removal can take content, configuration or the whole site with it. The backup-first method solves that — and makes the whole cleanup less stressful.
Always a backup before every change
Take a full backup of files and database before touching anything — and a fresh one before each major step. If a removal goes wrong, you always have a point to return to. An infected backup can be cleaned; a lost site can’t be recreated. That one simple rule is the difference between a cleanup and a disaster.
Clean in a copy, not in production
Do the cleanup in an isolated environment or staging, not directly on the live site your visitors see. Then you can verify everything still works before switching over — no half-cleaned site showing errors to customers, no risk that a wrong removal takes down production in the middle of the day.
Be careful with old backups
Just restoring an old backup feels tempting, but it’s a trap in two ways. If the backup is from after the infection, it’s infected too. If it’s from long before, you lose all the content added since. So the backup-first method isn’t about rolling back blindly — it’s about always having a clean restore point while you clean forward.
Nothing is cleaned without a backup. That’s the rule that separates a cleanup from a disaster.
— Kepler Security Scan
How we build it in
Our WordPress cleanup takes a backup before every change and runs in an isolated Kepler environment — your current site is untouched during the process. And on Managed WordPress hosting, daily backups and staging are built in, so you always have a clean point to fall back on — not just in an incident, but every time you make a risky change.
