Two colleagues working late together to recover a hacked WordPress site
|

How to Recover a Hacked WordPress Site in Kenya

Confirming a compromise is unpleasant, although the work to recover a hacked WordPress site is more orderly than people expect. The good news is that recovery follows a fixed sequence, and most sites come back cleanly.

To recover a hacked WordPress site properly you work through four stages in order: contain, preserve, clean, and harden. Skipping straight to cleaning is the mistake that causes reinfection a fortnight later.

Where the site handles customer data or payments, involve a professional early rather than late.

Stage One: Contain

Put the site into maintenance mode or take it offline. This protects visitors and stops further damage while you work.

Change every password from a device you trust. Hosting control panel, registrar, WordPress administrator accounts, database user, FTP, and any email account on the domain.

Tell your hosting provider. Kenyan hosts deal with this regularly and can often see activity from the server side that you cannot.

Disable anything non essential temporarily, including scheduled tasks and integrations that connect to other systems.

Stage Two: Preserve Before You Delete

Take a full copy of the site as it currently stands, files and database together, and store it somewhere separate.

This feels counterintuitive when your instinct is to erase everything. However, deleting first destroys the only record of how somebody got in, and without that you will rebuild the same weakness.

Note the dates on modified files as well, since they narrow down when the compromise began and therefore which backup is safe to use.

Stage Three: Clean the Hacked WordPress Site

Two routes exist, and the better one is usually the simpler one.

Restore from a clean backup. Where you hold a backup from before the compromise, this is the fastest and most reliable path. Restore it, then immediately update everything before reconnecting.

Clean in place where no clean backup exists. Replace WordPress core files with a fresh download of the same version. Reinstall themes and plugins from official sources rather than repairing them. Review your user list and remove accounts nobody recognises. Check the site’s configuration and root files for entries nobody added.

Whichever route you take, update WordPress core, every theme, and every plugin afterwards, and delete anything you are not actively using. Unused plugins are the most common entry point on Kenyan business sites.

Run a reputable security scanner as a check rather than as the whole solution, since scanners miss things.

Stage Four: Harden

You have not fully managed to recover a hacked WordPress site until the original weakness is closed.

Enable two factor authentication on administrator accounts.

Use strong unique passwords, stored in a password manager rather than reused.

Remove unused plugins, themes, and user accounts entirely rather than deactivating them.

Set updates to apply automatically where your setup allows it.

Establish offsite backups running on a schedule, stored somewhere other than the same server.

Limit administrator accounts to people who genuinely need them. Our post on who should have website admin access covers the arrangement.

Clear the Warnings

Efforts to recover a hacked WordPress site do not clear a security warning automatically.

Open Search Console, check the security issues section, and request a review once you are confident the site is clean. Reviews typically take a few days. Requesting one before the site is genuinely clean restarts the clock, so verify first.

Our post on what to do when Google flags your site as unsafe covers that process.

Check What Was Exposed

Where your site held customer information, a compromise may carry obligations beyond the technical cleanup.

Under Kenya’s Data Protection Act 2019, a breach posing a risk to people’s rights must be notified to the ODPC within seventy two hours, and in serious cases the affected individuals must be told directly. Establish what data the site held and take advice promptly. Our guide to data protection for websites in Kenya covers the duty.

Watch for Three Weeks

Reinfection is common, because people recover a hacked WordPress site without closing the entry point.

Monitor for a few weeks. Search your own domain in Google, check your user list, watch Search Console, and confirm nothing unexpected reappears in your files.

Frequently Asked Questions

How long does it take to recover a hacked WordPress site? Hours with a clean backup. Days without one, depending on the extent.

Can I recover it myself? Often yes, with a clean backup and some patience. Where payments or customer data are involved, get professional help.

Should I just rebuild from scratch? Sometimes faster than cleaning, particularly on an old neglected site. Preserve a copy first and rebuild on updated software.

Will I lose my Google rankings? Short compromises resolved quickly usually recover. Warnings left in place for weeks cause lasting damage.

How did they get in? Usually an outdated plugin, a weak password, or an abandoned theme rather than anybody targeting you.

Do I need a security plugin? Helpful, though updates, strong passwords and fewer plugins matter more.

Contain, Preserve, Clean, Harden

To recover a hacked WordPress site you follow the sequence rather than rushing it, and you finish by closing the door that was left open.

At Africa Web Experts we build with updates, offsite backups and access controls from day one, so recovery is a restore rather than a rescue. From KES 65,000, live in seventy two hours.

👉 Request a quote from Africa Web Experts

This article is general guidance. Where customer data, payments, or regulatory obligations are involved, engage a qualified professional and take legal advice on your notification duties.

Similar Posts