What Pressable’s Malware Cleanup Covers

Last modified: September 12, 2026

Ask Your Favorite AI

Copy the link to a markdown format of this article for ChatGPT, Claude, Gemini, or your favorite AI.

If your WordPress site has been compromised, our Customer Support team can help you clean it up. That’s included with every Pressable plan at no extra cost.

Below is what our cleanup involves, how we’ll work through it with you, and where to turn if your situation calls for more than we can offer.

How Malware Gets Found

Every Pressable plan includes a free Jetpack Security license, and malware scanning is part of it. Site-level scanning on Pressable runs through Jetpack, which means the scan results live in your Jetpack dashboard and the alerts come to you. Activating and connecting it is the single most useful thing you can do to find out early that something is wrong.

Our platform team keeps an eye out for malicious behavior at the network level too, like outbound spam or unusual resource use, and we’ll always reach out if a site trips those signals. That watches the platform as a whole rather than the files and database of any one site, so Jetpack is still what’s most likely to spot an infection on yours first.

If Jetpack flags something, or you notice symptoms like unexpected admin users, injected content, or redirects to sites you don’t recognize, get in touch through chat or at help@pressable.com and we’ll take a look.

What Our Cleanup Includes

When you report a suspected infection, we:

  • Run our internal tooling against the site to identify known malicious files and database content.
  • Remove or neutralize what our tooling and the Jetpack scan flag.
  • Identify the specific items on your site that need your attention, such as vulnerable plugins or user accounts that shouldn’t exist.
  • Re-scan and confirm that both the Jetpack scan and our platform-level checks come back clean before closing the request.

That list is the full extent of the cleanup work we perform, and it’s the same on every plan. If your site turns out to need something beyond it, we’ll let you know at the time and help you work out where to take it next.

What We’ll Need From You

Removing malware clears out what’s on the site today. It doesn’t close the door that was used to get in. Closing it means making changes on the site itself, and we’ll flag the specific items we spot while we’re in there. A cleaned site without these tends to get compromised again:

  • Update every plugin and theme, and remove any that are unused, abandoned, or no longer getting updates from their developer.
  • Remove privileged user accounts you don’t recognize or no longer need. Check every role with edit access, not only administrators.
  • Set strong, unique passwords on all remaining privileged accounts. Change any password that’s been shared or reused elsewhere.
  • Enable two-factor authentication for wp-admin logins.
  • Keep Jetpack active and connected so you find out early next time.

Common Vectors for Malware and How to Mitigate Them covers how sites typically get compromised, and the Quick Start Guide: Secure Your Site is a fuller checklist.

If You Need An Independent Investigation

Some situations call for a formal forensic investigation: an insurance claim, a regulatory or contractual obligation, or just needing to know with confidence what was accessed and when. Our Customer Support team isn’t a security firm and doesn’t perform forensic analysis, so that work needs a specialist you bring in. We’re glad to tell them what our tooling flagged and what we removed, which is usually a helpful starting point for them.

You don’t have to choose between cleaning your site and preserving evidence for that specialist, and you should never leave an active infection running while you arrange one. We’d suggest capturing what you need first, and we’re happy to hold off on the cleanup while you do. It usually takes a few minutes:

  • Download a filesystem backup and a database backup covering the compromised state from the Backups & Restores tab of your site, and save them somewhere you control. See Accessing Backups.
  • Save local copies of anything else a security firm might want to review while it’s still available to you, including your Jetpack activity log, order or form data (included in your database backup), server logs, WordPress/PHP logs, and any screenshots or notes you’ve taken.
  • Write down when you first noticed something wrong, and what you saw.

Once you’ve got your copies, just let us know and we’ll get started.

Restoring From Backup

Rolling the site back to a point before the compromise is a reasonable option, especially if you know roughly when it happened and can afford to lose the changes made since. Weigh a few things first:

  • Whatever allowed the compromise is almost certainly present in the restored copy too. Same plugin version, same user account, same password. The site can be reinfected the same way within hours.
  • If a backdoor was planted before the backup you restore, you’ll bring the backdoor back along with everything else.
  • Anything created since that backup is gone, including orders, posts, comments, and form submissions. For this reason we do not recommend addressing malware with a restore for e-commerce sites.

If you do restore, work through the Quick Start Guide: Secure Your Site right away rather than waiting to see whether it happens again.

If Malware Comes Back

A site that’s cleaned and then reinfected usually has a persistence mechanism our tooling didn’t locate: a scheduled task, a modified core file, a credential that’s still valid somewhere, or another compromised site in the same account. Finding it takes the sort of manual code and log analysis a WordPress security specialist does.

We’ll keep running our cleanup process for you whenever you need it. We’d also encourage you to bring in a specialist at that point, since repeat cleanups won’t resolve something our tooling can’t see.