PageSourceSearch

https://webfootprint.co.za/_app/immutable/nodes/22.cGz1mSmn.js

js webfootprint.co.za collected 2026-09-24 13:27:29 UTC 16,667 bytes, 1 lines download raw bytes

1import{m as a}from"../chunks/2OoLQr3B.js";import{f as B,a as d,c as ie,s as r}from"../chunks/BmSKQWIQ.js";import{B as le,T as ne,F as J,G as C,D as re,J as l,O as s,c as pe,U as ce,P as e,a as p}from"../chunks/DstTTDS_.js";import{e as N,i as X,s as ve}from"../chunks/psxyvfJL.js";import{h as de}from"../chunks/Bt2foGWB.js";import{h as me}from"../chunks/C44bSdLX.js";import{a as m,g as he,s as h}from"../chunks/CDwLwWFQ.js";import{s as c}from"../chunks/noctlh8y.js";import{S as ke}from"../chunks/uo3g6jz9.js";import"../chunks/CaRaVpeL.js";function ge(){return{metadata:a}}const Ie=Object.freeze(Object.defineProperty({__proto__:null,load:ge},Symbol.toStringTag,{value:"Module"}));var ue=B('<a class="tag svelte-pokmzj"> </a>'),je=B('<li class="svelte-pokmzj"><a> </a></li>'),we=B(`<!> <article class="blog-post"><header class="post-header svelte-pokmzj"><div class="header-bg svelte-pokmzj"><div class="glow glow-1 svelte-pokmzj"></div> <div class="glow glow-2 svelte-pokmzj"></div></div> <div class="container"><div class="header-content svelte-pokmzj"><div class="meta-top svelte-pokmzj"><a href="/blog" class="back-link svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="m15 18-6-6 6-6"></path></svg> Back to Blog</a> <div class="tags svelte-pokmzj"></div></div> <h1 class="svelte-pokmzj"> </h1> <p class="subtitle svelte-pokmzj"> </p> <div class="meta-bottom svelte-pokmzj"><span class="author"> </span> <span class="separator svelte-pokmzj">•</span> <time> </time> <span class="separator svelte-pokmzj">•</span> <span class="reading-time"> </span></div></div></div></header> <div class="featured-image-wrapper svelte-pokmzj"><div class="container"><div class="featured-image svelte-pokmzj"><img class="svelte-pokmzj"/></div></div></div> <div class="post-content-wrapper svelte-pokmzj"><div class="container"><div class="content-grid svelte-pokmzj"><aside class="toc-sidebar svelte-pokmzj"><nav class="toc svelte-pokmzj"><h3 class="svelte-pokmzj">Contents</h3> <ul class="svelte-pokmzj"></ul></nav></aside> <div class="post-content svelte-pokmzj"><p class="lead svelte-pokmzj">Getting hacked can be a frustrating, stressful experience, especially when your website is central to your business. The good news is that there are things you can do to regain control. The bad news? Once a website has been compromised, there's always the possibility that hidden backdoors have been planted in places no scanner will ever find. Here's what you need to know.</p> <section id="security-audit" class="svelte-pokmzj"><h2 class="svelte-pokmzj">Step 1: Run a Full Security Audit</h2> <p class="svelte-pokmzj">If you're using a platform like WordPress, your first response should be to scan your website for vulnerabilities and malware. This includes:</p> <div class="checklist svelte-pokmzj"><div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj">Running malware scans using tools like <strong class="svelte-pokmzj">iThemes Security Pro</strong></span></div> <div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj">Checking your <strong class="svelte-pokmzj">uploads folder</strong>, where malicious files often hide</span></div> <div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj"><strong class="svelte-pokmzj">Updating all plugins, themes, and core files</strong> to the latest version</span></div> <div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj">Changing all <strong class="svelte-pokmzj">admin-level passwords</strong> (and making them strong)</span></div> <div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj">Removing any <strong class="svelte-pokmzj">outdated or unused plugins</strong>, especially ones that haven't been updated in months</span></div> <div class="checklist-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M22 11.08V12a10 10 0 1 1-5.93-9.14"></path><polyline points="22 4 12 14.01 9 11.01"></polyline></svg> <span class="svelte-pokmzj">Enabling <strong class="svelte-pokmzj">automatic updates</strong> for WordPress and plugins to keep things secure long-term</span></div></div> <div class="callout callout-info svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><circle cx="12" cy="12" r="10"></circle><path d="M12 16v-4"></path><path d="M12 8h.01"></path></svg> <div><strong class="svelte-pokmzj">Xneelo Users:</strong> <p class="svelte-pokmzj">If you're hosted on Xneelo, you can activate <strong class="svelte-pokmzj">Cloudbric</strong>, a firewall that monitors your traffic and blocks suspicious activity. This is a great line of defense against ongoing attacks and automated bots.</p></div></div></section> <section id="backdoor-risk" class="svelte-pokmzj"><h2 class="svelte-pokmzj">Step 2: Understand the Risk of Backdoors</h2> <p class="svelte-pokmzj">Here's the unfortunate truth: <strong class="svelte-pokmzj">once a site has been hacked, there's no guaranteed way to know how deep the compromise goes.</strong></p> <p class="svelte-pokmzj">Even if you've removed malicious files and patched obvious vulnerabilities, there's always a risk that the hacker planted a <strong class="svelte-pokmzj">backdoor</strong>
1, a hidden way for them to re-enter your site later. These backdoors can be buried in:</p> <ul class="svelte-pokmzj"><li class="svelte-pokmzj">Theme files</li> <li class="svelte-pokmzj">Custom plugins</li> <li class="svelte-pokmzj">The database itself</li></ul> <p class="svelte-pokmzj">Many of them are designed to evade scanners entirely.</p> <div class="callout callout-warning svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3Z"></path><path d="M12 9v4"></path><path d="M12 17h.01"></path></svg> <div><strong class="svelte-pokmzj">Important:</strong> <p class="svelte-pokmzj">While scans and firewall protections are useful and should stabilize things in the short term, they don't offer complete peace of mind. The risk of reinfection remains.</p></div></div></section> <section id="path-forward" class="svelte-pokmzj"><h2 class="svelte-pokmzj">Step 3: Decide on Your Path Forward</h2> <p class="svelte-pokmzj">There are two main options when recovering from a hack:</p> <div class="option-cards svelte-pokmzj"><div class="option-card svelte-pokmzj"><div class="option-header svelte-pokmzj"><span class="option-icon svelte-pokmzj">🛠️</span> <h3 class="svelte-pokmzj">Option 1: Clean and Harden the Current Site</h3></div> <p class="svelte-pokmzj">This is often the first step, especially if you want to avoid downtime or the cost of a rebuild. Here's what that process usually includes:</p> <ul class="svelte-pokmzj"><li class="svelte-pokmzj">Full scan and cleanup of files</li> <li class="svelte-pokmzj">Password resets for all users</li> <li class="svelte-pokmzj">Locking down admin access</li> <li class="svelte-pokmzj">Setting up two-factor authentication</li> <li class="svelte-pokmzj">Installing firewall and brute-force protection</li> <li class="svelte-pokmzj">Monitoring file changes and login attempts</li> <li class="svelte-pokmzj">Reviewing user roles and permissions</li></ul> <p class="option-outcome svelte-pokmzj"><strong class="svelte-pokmzj">If things stay stable, great.</strong> But if suspicious behavior pops up again, with strange redirects, injected content, or broken logins, it's time to move to the next option.</p></div> <div class="option-card option-recommended svelte-pokmzj"><div class="option-header svelte-pokmzj"><span class="option-icon svelte-pokmzj">🔒</span> <h3 class="svelte-pokmzj">Option 2: Rebuild From Scratch</h3></div> <p class="svelte-pokmzj">If a site keeps getting reinfected, the safest and most future-proof option is to <strong class="svelte-pokmzj">rebuild it from the ground up</strong>.</p> <p class="svelte-pokmzj">This means:</p> <ul class="svelte-pokmzj"><li class="svelte-pokmzj">Starting with a <strong class="svelte-pokmzj">clean WordPress install</strong></li> <li class="svelte-pokmzj">Installing only <strong class="svelte-pokmzj">trusted, well-maintained plugins</strong></li> <li class="svelte-pokmzj">Copying over content <strong class="svelte-pokmzj">manually</strong> (never full folders)</li> <li class="svelte-pokmzj">Avoiding copying over theme or plugin files that could be compromised</li> <li class="svelte-pokmzj">Automating updates and setting up <strong class="svelte-pokmzj">strong security from day one</strong></li></ul> <p class="option-outcome svelte-pokmzj"><strong class="svelte-pokmzj">While this is more work upfront, it gives you peace of mind</strong> that the site is truly clean, and not secretly under someone else's control.</p></div></div></section> <section id="final-thoughts" class="svelte-pokmzj"><h2 class="svelte-pokmzj">Final Thoughts</h2> <p class="svelte-pokmzj">Hackers are always finding new ways in. Even major companies like LinkedIn have fallen victim to cyber attacks. But you can reduce your risk dramatically by:</p> <div class="best-practices svelte-pokmzj"><div class="practice-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10"></path></svg> <span class="svelte-pokmzj">Keeping everything updated</span></div> <div class="practice-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10"></path></svg> <span class="svelte-pokmzj">Using only reputable themes/plugins</span></div> <div class="practice-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10"></path></svg> <span class="svelte-pokmzj">Limiting user permissions</span></div> <div class="practice-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10"></path></svg> <span class="svelte-pokmzj">Running regular security scans</span></div> <div class="practice-item svelte-pokmzj"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="svelte-pokmzj"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10"></path></svg> <span class="svelte-pokmzj">Investing in tools like Cloudbric or iThemes Security Pro</span></div></div> <p class="svelte-pokmzj">If your website has already been compromised, cleaning it up is a great first step, but don't rule out a rebuild if problems persist. <strong class="svelte-pokmzj">A secure website is a living system, not a one-time setup.</strong></p></section> <div class="cta-box svelte-pokmzj"><h3 class="svelte-pokmzj">Need Help Recovering From a Hack?</h3> <p class="svelte-pokmzj">Our team can help you assess the damage, clean up your site, or rebuild it from scratch with security best practices built in from day one.</p> <div class="cta-buttons svelte-pokmzj"><a href="/contact" class="btn btn-primary svelte-pokmzj">Get in Touch</a> <a target="_blank" rel="noopener" class="btn btn-secondary svelte-pokmzj">WhatsApp Us</a></div></div></div></div></div></div></article>`,1);function Te(Y,Z){le(Z,!0);const S=[{id:"security-audit",label:"Step 1: Run a Security Audit"},{id:"backdoor-risk",label:"Step 2: Understand Backdoor Risks"},{id:"path-forward",label:"Step 3: Decide Your Path Forward"},{id:"final-thoughts",label:"Final Thoughts"}];let M=ce("security-audit");function K(o){return new Date(o).toLocaleDateString("en-ZA",{year:"numeric",month:"long",day:"numeric"})}ne(()=>{const o=S.map(i=>
1document.getElementById(i.id)).filter(Boolean),t=new IntersectionObserver(i=>{i.forEach(n=>{n.isIntersecting&&pe(M,n.target.id,!0)})},{rootMargin:"-20% 0px -60% 0px",threshold:0});return o.forEach(i=>t.observe(i)),()=>t.disconnect()});var I=we();me("pokmzj",o=>{var t=ie(),i=J(t);de(i,()=>`<script type="application/ld+json">${JSON.stringify({"@context":"https://schema.org","@type":"Article",headline:a.title,description:a.description,image:a.featuredImage,datePublished:a.publishedAt,author:{"@type":"Organization",name:a.author},publisher:{"@type":"Organization",name:"WebFootprint",logo:{"@type":"ImageObject",url:"https://webfootprint.co.za/images/webfootprint-logo-svg.svg"}},mainEntityOfPage:{"@type":"WebPage","@id":"https://webfootprint.co.za/blog/${metadata.slug}"}})}<\/script>`),d(o,t)});var T=J(I);ke(T,{get title(){return a.title},get description(){return a.description},canonical:"/blog/website-hacked-guide",get image(){return a.featuredImage},type:"article"});var O=l(T,2),k=s(O),A=l(s(k),2),g=s(A),u=s(g),P=l(s(u),2);N(P,21,()=>a.tags,X,(o,t)=>{var i=ue(),n=s(i,!0);e(i),C(()=>{c(i,"href",`/blog?tag=${p(t)??""}`),r(n,p(t))}),d(o,i)}),e(P),e(u);var j=l(u,2),q=s(j,!0);e(j);var w=l(j,2),Q=s(w,!0);e(w);var R=l(w,2),z=s(R),ee=s(z,!0);e(z);var v=l(z,4),se=s(v,!0);e(v);var V=l(v,4),te=s(V);e(V),e(R),e(g),m(g,(o,t)=>h?.(o,t),()=>({direction:"up"})),e(A),e(k);var f=l(k,2),F=s(f),b=s(F),W=s(b);e(b),m(b,(o,t)=>h?.(o,t),()=>({direction:"up",delay:100})),e(F),e(f);var E=l(f,2),H=s(E),U=s(H),y=s(U),x=s(y),D=l(s(x),2);N(D,21,()=>S,X,(o,t)=>{var i=je(),n=s(i);let G;var ae=s(n,!0);e(n),e(i),C(()=>{c(n,"href",`#${p(t).id??""}`),G=ve(n,1,"svelte-pokmzj",null,G,{active:p(M)===p(t).id}),r(ae,p(t).label)}),d(o,i)}),e(D),e(x),m(x,(o,t)=>h?.(o,t),()=>({direction:"left"})),e(y);var _=l(y,2),$=l(s(_),10),L=l(s($),4),oe=l(s(L),2);e(L),e($),e(_),m(_,(o,t)=>h?.(o,t),()=>({direction:"up",delay:150})),e(U),e(H),e(E),e(O),C((o,t)=>{r(q,a.title),r(Q,a.description),r(ee,a.author),c(v,"datetime",a.publishedAt),r(se,o),r(te,`${a.readingTime??""} min read`),c(W,"src",a.featuredImage),c(W,"alt",a.featuredImageAlt||a.title),c(oe,"href",t)},[()=>K(a.publishedAt),()=>he("Hi, my website has been hacked and I need help")]),d(Y,I),re()}export{Te as component,Ie as universal};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.