Cleaned a hacked WordPress site? Quarantine it for 48 hours.
Malware that has been cleaned often comes back within hours. Quarantine mode watches the places it returns to and tells you the moment something changes — what changed, when, and how Relvato saw it.
A clean-up removes what you found — not what put it there
Self-healing malware keeps a way back in. These are the usual ones.
A loader you missed
A small file in uploads, a must-use plugin or a drop-in that writes the malware back as soon as it's deleted.
A copy in the database
Code stored in an option or a post, put back on the next page load or background task.
A scheduled task
A WordPress cron job that reinstalls the infection an hour or a day after the clean-up.
An admin you don't know
The attacker's own login — or a changed email on yours — to walk back in and do it again.
48 hours of watching, from the moment the site is clean
Start it yourself after a clean-up, or let Relvato start it when an integrity check comes back clean.
Clean the site
Remove the malware — yourself, with your host, or with a clean-up service. Relvato doesn't clean; it tells you whether the clean-up held.
Quarantine starts
Click Start quarantine on the site's Security page — or it starts on its own when File integrity, Theme integrity, Admin roster or Third-party scripts comes back clean after finding something.
Relvato watches
The integrity checks run every hour. The WordPress plugin reports users, key settings, scheduled tasks, uploads and editor saves as they happen, and fingerprints the risky places every ten minutes.
You hear at once
Anything unexpected goes to your email and Slack straight away — even if you normally get a digest — and lands in the change log with its time and how it was seen.
The places malware comes back to
Only what matters after a hack: sizes, dates and names — never the contents of your files.
Files in the risky places
The site root and wp-config.php, drop-ins, must-use plugins, PHP in uploads, themes, plugins and WordPress core — new and changed files, within ten minutes.
Administrators and users
New admins, raised roles, an admin's email or password changed — including accounts added straight into the database.
Key settings
The site address, open registration, the role new users get and the active theme: the settings attackers flip to get back in or redirect visitors.
Scheduled tasks
A new WordPress cron job is how deleted malware reinstalls itself. Each new one is logged the first time it appears.
Third-party scripts
A new script or data destination on your pages — the shape of a card skimmer or a spam redirect.
Plugins and themes
Installed, switched on or off, or a security plugin quietly deactivated — the classic first move.
Every change, with when and how it was seen
Updates you made through WordPress are marked expected, so the changes nobody planned stand out.
Pause plugin updates — keep WordPress's security updates on
Auto-updates change files on their own schedule, which muddies a log that should show only what you did. During quarantine, update plugins and themes by hand, one at a time. Relvato can pause plugin and theme auto-updates for you with one click, and they resume on their own when quarantine ends.
Don't switch off WordPress's own security releases: a site that was just hacked needs them most. Updates made through WordPress are marked expected, and File integrity checks their files against wordpress.org.
On Pro, Business and Agency
Quarantine mode is part of every paid plan. Its hourly checks count toward your monthly runs — about 192 for a 48-hour quarantine with all four checks on. On the Free plan you'll see it on the Security page, and starting it asks you to upgrade.
Clean it up, then keep it clean
Questions about quarantine mode
Does quarantine mode block attacks?
No. It watches and tells you — it doesn't block traffic or delete files. Pair it with a firewall (your host's, Cloudflare, or a security plugin). What it adds is knowing within minutes that a clean-up didn't hold, and exactly what changed.
Why 48 hours?
Self-healing malware usually comes back within hours of a clean-up, from a loader or a scheduled task. 48 hours covers that window, and you can extend it 48 hours at a time, up to a week.
Should I turn off WordPress auto-updates?
Pause plugin and theme auto-updates and update by hand, so every change in the log is one you know about — Relvato can pause them for you. Keep WordPress's own security updates on.
Does Relvato read my files?
No. The fingerprint compares file sizes and modification dates and reports paths — never contents. User changes are reported by login, and an email only as its domain.
What does it need on my site?
The Relvato WordPress plugin (version 1.21.0 or later for the instant reports, the fingerprint and the auto-update pause) and at least one of File integrity, Theme integrity, Admin roster or Third-party scripts turned on.
Does it clean the site for me?
No — Relvato verifies, it doesn't clean. Remove the malware with your host, a clean-up service or your security plugin, then quarantine the site to make sure it stays gone.
Make sure it stays clean
Connect your WordPress site, turn on the integrity checks, and start quarantine the moment you're done cleaning.