WordPress troubleshooting

How to clean a hacked WordPress site without wp-admin

Losing wp-admin does not necessarily mean losing access to the site. With FTP/SFTP or Web FTP access, you can upload Free or Saver to hosting and work from an engine separate from WordPress.

Do not share your credentials.
wpsuite never asks for your WordPress password or FTP/SFTP access. Keep them with you and change them if you think they were exposed.

Safe first actions

  1. Keep a copy of files and database, even if the site is inaccessible.
  2. Find FTP/SFTP or Web FTP access at your host, then open the folder containing wp-config.php.
  3. Use Free to confirm detections, or choose Saver if you need to begin recovery.
  4. Follow backup, quarantine, component check and hardening steps; check the site and wp-admin before returning it to service.

Why Saver can remain usable

Saver does not depend on wp-admin: it has its own address on your hosting. It can therefore remain available when WordPress does not start, provided the engine, access and hosting are not compromised themselves.

Saver can restore official components from their source and handle preserved files. It cannot invent a custom file, image or data that was permanently deleted without a usable backup.

Frequently asked questions

Does Free clean a hacked WordPress site?

No. Free detects and creates a read-only report. Saver is the recovery and hardening product.

Can I upload Saver when the site shows an error?

Yes, if you still have server access and compatible PHP hosting. Its engine is separate from WordPress.

Do I need Full to clean?

No. Full includes Saver and adds continuous protection: rolling backups, WAF, login monitoring and a WordPress plugin.

Free

Get a report before choosing recovery.

Free

Saver

Clean, restore service and harden.

Saver