My Faaaster site has been hacked — what should I do?
Act in this order: isolate the site, restore a backup from before the compromise, then fix the vulnerability before putting it back online. Restoring without fixing the vulnerability means getting compromised again.
Contents
- 1. Isolate the site
- 2. Check integrity
- 3. Restore
- 4. Fix the vulnerability before reopening
- 5. Strengthen your protections
1. Isolate the site
Turn on the Private toggle in the site's header: the site is no longer publicly accessible, which stops malicious content from spreading.
2. Check integrity
The Security tab offers a Check integrity button as well as a Vulnerabilities section listing the vulnerabilities detected. The WordPress tab, Vulnerable filter, shows the plugins and themes with a known vulnerability.
3. Restore
From the Backups tab, restore a backup from before the compromise. Daily backups are included in every plan.
Choose a safe date. A backup taken after the intrusion contains the malicious code.
4. Fix the vulnerability before reopening
- Update WordPress, plugins and themes (WordPress tab, Needs update filter).
- Delete unused plugins and themes.
- Change the passwords of the WordPress accounts.
5. Strengthen your protections
In the Security tab:
- Nginx Hardening — notably blocks
xmlrpc,.htaccessand.gitfiles; - Read only — write-locks files, which prevents any change to the code;
- Global IP protection, "Under Attack" protection and AppSec — against malicious traffic, overloads and exploit attempts (on some sites, Crowdsec Security plays this role);
- Site IP rules and HTTP rules, in the Custom rules card — for targeted rules.

Faaaster can clean the site for you
Yes, and it's free — up to two cleanups per month.
It comes with one condition, and it's a logical one: the recommended fixes must have been applied between two interventions — plugin and core updates, changing compromised passwords, removing abandoned plugins.
A site that's cleaned but left as is will be reinfected. The attacker often got in through a known vulnerability: without the fix, they'll come back through the same door, sometimes within hours.
To make the request, contact support with the Support button, stating the site concerned and, if you have them, the date the problem appeared and the symptoms you've noticed: the AI assistant examines the site and passes your request on to the team if needed.
👉 What security protections does Faaaster offer? · How do I restore a backup?
Updated on: 10/03/2026
Thank you!
