Quarantine a site after a hack
Updated September 2026
Quarantine mode watches a WordPress site that was just cleaned for 48 hours and tells you the moment something changes. This page starts it, explains the change log and the alerts, and covers auto-updates. For why malware comes back at all, see Why WordPress malware keeps coming back.
What you need first
Quarantine mode is on the Pro, Business and Agency plans. The site needs at least one of File integrity, Theme integrity, Admin roster or Third-party scripts turned on — those are the checks it runs every hour.
For changes reported as they happen, the ten-minute fingerprint and the auto-update pause, the site needs the Relvato WordPress plugin 1.21.0 or later. With an older plugin, quarantine still runs the hourly checks.
Step 1 — Start quarantine
Open the site in Relvato and go to Security. The Quarantine mode card has a red border. Click Start quarantine (48 h). The card shows about how many runs it will use and how many you have left this month.
Relvato also starts it on its own when one of those checks comes back clean right after finding something — usually the moment you've just cleaned the site. You get an email either way.
Step 2 — Pause auto-updates (optional)
Once quarantine is on, click Pause plugin & theme auto-updates. The plugin stops WordPress from updating plugins and themes by itself until quarantine ends, then lets it again — there's nothing to undo. WordPress's own security updates stay on.
Update by hand while it runs, one plugin at a time, so every change in the log is one you know about.
Step 3 — Read the change log
Every change Relvato sees during quarantine is listed under Change log, newest first, with its time and how it was seen: Full check (an hourly integrity check found it), Reported by the plugin (as it happened), or Fingerprint check (the ten-minute scan of the risky places).
Each entry is tagged High (act on it — a new admin, PHP in uploads, wp-config changing), Review (worth a look — a new plugin, a new scheduled task), Expected (an update you made through WordPress) or Info. Choose Unexpected to see only what needs attention.
Alerts
Unexpected changes are sent at once by email, and to Slack on Business and Agency — even if you normally get a daily or weekly digest. Changes found in the same few minutes arrive as one message.
You also get an email when quarantine starts and a summary when it ends.
When something unexpected shows up
If you didn't make the change, the infection is probably back. Look at what the entry names, then for what put it there: a scheduled task, an administrator you don't know, or a plugin you didn't install. Clean it, then click Extend 48 h to keep watching.
Extend or stop
Extend 48 h adds 48 hours to the end, up to a week in total. Stop quarantine ends it now; its log stays under Past quarantines.
FAQ
How many runs does it use?
Each watched check runs once an hour: about 192 runs for 48 hours with all four checks on. The fingerprint and the plugin's reports aren't runs and don't count.
What if my runs run out during quarantine?
The hourly checks pause until your runs reset or you upgrade. The plugin's reports and the fingerprint keep going.
Does the fingerprint read my files?
No. It compares sizes and modification dates and reports paths — never contents.
Can I quarantine a site that isn't on WordPress?
Not yet: quarantine is built on the WordPress integrity checks and the Relvato plugin.