If your site shows spam redirects, locked files or a Google/host notice that it is infected, do not randomly change plugins to make it work. First assess damage and isolate — without panic and without deleting evidence needed for diagnosis.
Seven practical steps: (1) put the site in maintenance or isolate it from the public, (2) notify hosting/security, (3) change all passwords (admin, FTP/SFTP, DB, email), (4) check backups from before the incident, (5) clean malware/suspicious files with a professional audit, (6) update CMS/plugins and close unused accounts, (7) test restore on staging before production.
After cleanup you need prevention: least-privilege, updates, WAF where it helps, monitoring and backups with a tested restore. Without a restore test, a backup is theoretical.
Bytesoft in Patras helps with incident response, hardening and stable hosting after compromise — without unhackable claims. Contact: /en/contact/.
Service: /en/services/cybersecurity/ · hosting: /en/services/hosting/ · guides: /en/blog/cybersecurity-greece/ · /en/blog/business-security-anti-hacking/.
Check Search Console for security issues, confirm SSL and headers, and close open host tickets. Ask for a short report: what got in, how, what was fixed.
For audit/pentest and hardening: /en/services/cybersecurity/. For managed backups/monitoring: /en/services/hosting/ · /en/blog/managed-hosting-backups-monitoring/.