If your website shows warnings, redirects to spam sites, or Google flags it as unsafe, it may be infected. Act quickly on Ceyora shared hosting to limit damage.
Immediate steps
- Change all passwords: cPanel, FTP, WordPress admin, database
- Take the site offline temporarily (maintenance page) if actively spreading malware
- Scan files using cPanel Virus Scanner if available
- Check recently modified files in File Manager
WordPress malware cleanup
- Update WordPress core, themes, and plugins
- Remove unknown admin users from wp-admin
- Replace wp-admin and wp-includes with fresh copies from wordpress.org
- Scan wp-content/themes and plugins — remove unrecognised plugins
- Install Wordfence or similar and run a full scan
Restore from clean backup
If cleanup is overwhelming, restore from a known-clean backup taken before infection. Then patch vulnerabilities that allowed the hack.
Ceyora support can assist with server-level scans — open a ticket with your domain and symptoms.