> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.faaaster.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# My Faaaster site has been hacked — what should I do?

Act in this order: **isolate** the site, **restore** a backup from before the compromise, then **fix the vulnerability** before putting it back online. Restoring without fixing the vulnerability means getting compromised again.


## Contents

- [1. Isolate the site](#2-1-isolate-the-site)
- [2. Check integrity](#2-2-check-integrity)
- [3. Restore](#2-3-restore)
- [4. Fix the vulnerability before reopening](#2-4-fix-the-vulnerability-before-reopening)
- [5. Strengthen your protections](#2-5-strengthen-your-protections)

## 1. Isolate the site

Turn on the **Private** toggle in the site's header: the site is no longer publicly accessible, which stops malicious content from spreading.

## 2. Check integrity

The **Security** tab offers a **Check integrity** button as well as a **Vulnerabilities** section listing the vulnerabilities detected. The **WordPress** tab, **Vulnerable** filter, shows the plugins and themes with a known vulnerability.

## 3. Restore

From the **Backups** tab, restore a backup **from before the compromise**. Daily backups are included in every plan.

> **Choose a safe date.** A backup taken after the intrusion contains the malicious code.

## 4. Fix the vulnerability before reopening

- Update WordPress, plugins and themes (**WordPress** tab, **Needs update** filter).
- Delete unused plugins and themes.
- Change the passwords of the WordPress accounts.

## 5. Strengthen your protections

In the **Security** tab:

- **Nginx Hardening** — notably blocks `xmlrpc`, `.htaccess` and `.git` files;
- **Read only** — write-locks files, which prevents any change to the code;
- **Global IP protection**, **"Under Attack" protection** and **AppSec** — against malicious traffic, overloads and exploit attempts (on some sites, **Crowdsec Security** plays this role);
- **Site IP rules** and **HTTP rules**, in the **Custom rules** card — for targeted rules.

![The protections in the Security tab: IP blocking and firewall rules.](https://storage.crisp.chat/users/helpdesk/website/-/9/d/2/d/9d2d3e0b7134b800/act-securite-ip-en_1k6bfch.png)

## Faaaster can clean the site for you

**Yes, and it's free** — up to **two cleanups per month**.

It comes with one condition, and it's a logical one: the **recommended fixes must have been applied** between two interventions — plugin and core updates, changing compromised passwords, removing abandoned plugins.

> **A site that's cleaned but left as is will be reinfected.** The attacker often got in through a known vulnerability: without the fix, they'll come back through the same door, sometimes within hours.

To make the request, contact support with the **Support** button, stating the site concerned and, if you have them, the date the problem appeared and the symptoms you've noticed: the AI assistant examines the site and passes your request on to the team if needed.

👉 [What security protections does Faaaster offer?](https://help.faaaster.io/en-us/article/security-protections-114vcpv/) · [How do I restore a backup?](https://help.faaaster.io/en-us/article/backups-1j7rzgw/)