Skip to content
July 11, 2026·5 min read

How to Restore a Hacked or Accidentally Deleted WordPress Site From a Backup — Without Making It Worse

A step-by-step guide to putting your backup back cleanly, without reintroducing malware or losing even more of your site.

A WordPress site that's down means customers you're losing right now, as you read this. Whether it was hacked, or someone deleted pages by accident, or a plugin broke everything, the first instinct is to hit "restore" on the first backup you find. That's where the trouble starts: many people restore the exact infected files that caused the hack, and within hours the site is compromised again.

A proper restore isn't just pressing a button. It means picking the right backup, cleaning up before you put anything back, not reintroducing the same malware, and verifying the site actually works afterward. In this guide we walk you through the real steps, in order, so you don't turn a one-day problem into a one-month one.

Don't rush: first figure out what actually happened

Before you restore anything, slow down and assess. An accidentally deleted site and a hacked site are fixed differently, and if you treat a hack like a simple deletion, you'll bring the malware right back.

Ask yourself:

  • Did content disappear (pages, posts, products) or did strange content appear (weird redirects, ads, pages in another language)?
  • When did it last work correctly? That decides which backup you choose.
  • Do you have access to the admin panel, the hosting (cPanel/SFTP), and the database?

If you see redirects, spam, or unknown files, it's almost certainly a hack, not a deletion. In that case, yesterday's backup may already be infected, because attackers sometimes hide for days before striking visibly.

Put the site in maintenance mode and back up its current state

It feels counterintuitive to back up a broken site, but it's essential. You need a copy of the current state so you can compare, recover recent content, and have something to fall back to if the restore goes wrong.

Concretely:

  • Enable a maintenance mode or take the site offline temporarily, so visitors don't land on an infected site and Google doesn't flag it as dangerous.
  • Download the entire folder over SFTP and export the database, even if they're compromised. Keep them separate, clearly labeled "possibly infected".
  • Don't permanently delete anything yet. The golden rule: until you have a confirmed working site, don't throw away any copy.

That way, whatever you do next, you have a safety net.

Choose the right backup, not the most recent one

Instinct says "the newest backup". With a hack, though, the newest may already contain the malicious code. The right choice is the last backup from before the problem appeared.

How to decide:

  • Check logs or the change history for when the first signs appeared (modified files, unknown admin users, redirects).
  • Pick a backup dated before that moment, even if it means losing a few days of content.
  • Recover recent content (orders, comments, posts) separately from the infected copy, by hand, after the base site is clean.

If it was just an accidental deletion with no signs of a hack, then yes, the most recent clean backup is the right one. The point is not to assume: first verify what happened.

Clean the ground before you restore

Restoring over infected files leaves leftovers: one hidden file in an uploads folder is enough for the site to be re-compromised. That's why, after a hack, a clean restore means emptying first.

The steps, via SFTP or File Manager:

  • Fully delete the old WordPress files (wp-admin, wp-includes, and the root files), keeping only what you need to inspect separately.
  • Pay attention to wp-content, where themes, plugins, and uploads live. Malicious files hide there most often.
  • Check the admin users: delete accounts you don't recognize and change all passwords.

Once the ground is clean, restore the files and database from your chosen backup. Then change every password: admin, database, hosting, FTP. If you don't rotate the keys, the attacker can walk back in through the same door.

Verify, update, and close the door they came through

The restore isn't done until you confirm the site works and the hole is patched. Otherwise you repeat all of this in a week.

After restoring:

  • Test the important pages: home, contact, forms, shop. Check on your phone and in an incognito browser.
  • Update WordPress, the theme, and all plugins to the latest version. Most hacks get in through an outdated plugin.
  • Delete plugins and themes you don't use, especially nulled (pirated) ones — they're a classic malware source.
  • Scan with a reputable security plugin and ask your host to run a server-side scan.

If you can't tell a good file from an infected one, get help before you put the site back online. It's cheaper than cleaning up a second compromise.

When it's worth rebuilding instead of restoring

Sometimes a site is so infected, or the backups so old, that cleaning takes longer than a clean rebuild. If you spend days chasing hidden files and they keep coming back, that's a sign a different approach is worth it.

At MPO Web Studio we work remotely, across the whole country, and our approach helps exactly in these moments: we start from a clean, known structure instead of inheriting the garbage of a compromised install. We show you a pre-built demo first, with transparent pricing, so you see exactly what you get before paying anything.

If you're stuck with a hacked or deleted site and don't know whether to restore or rebuild, message us on WhatsApp. We'll look at the situation together and tell you honestly which route costs you less time and money.

Frequently asked questions

How old can a backup be and still be useful?+

A backup is useful as long as it predates the problem and contains a working version of the site. Even a month-old one is better than a recent but infected one. Content created in the meantime you recover separately, by hand.

Does restoring from a backup automatically remove malware?+

Not necessarily. If the backup was made after the site was already compromised, you're restoring the exact infected files. That's why you must choose a backup from before the hack and clean the ground before restoring.

I only have my host's backup. Is that enough?+

It depends how often your host makes it and how many versions it keeps. Many hosts keep only a few days back, which for a hack discovered late can mean every copy is already infected. Ideally you also have backups elsewhere, independent of the host.

After restoring, how do I make sure it doesn't happen again?+

Keep everything updated, delete unused and especially pirated plugins and themes, use strong unique passwords, enable two-factor authentication for admin, and keep automatic backups independent of your host.

Can a hack lose me customers in Google?+

Yes. If Google detects malware or redirects, it can flag the site as dangerous, and visitors see a red warning. That's why it's important to put the site in maintenance quickly, clean it thoroughly, and request a review in Google Search Console once it's clean.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
MThe MPO teamWe reply personally

Want to see what your business's website could look like?

Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.

Ask for a free demo websiteWe usually reply within a few minutes