See all checks
WordPress under attack?

Cleaned a hacked WordPress site? Quarantine it for 48 hours.

Malware that has been cleaned often comes back within hours. Quarantine mode watches the places it returns to and tells you the moment something changes — what changed, when, and how Relvato saw it.

Why it comes back

A clean-up removes what you found — not what put it there

Self-healing malware keeps a way back in. These are the usual ones.

A loader you missed

A small file in uploads, a must-use plugin or a drop-in that writes the malware back as soon as it's deleted.

A copy in the database

Code stored in an option or a post, put back on the next page load or background task.

A scheduled task

A WordPress cron job that reinstalls the infection an hour or a day after the clean-up.

An admin you don't know

The attacker's own login — or a changed email on yours — to walk back in and do it again.

How quarantine works

48 hours of watching, from the moment the site is clean

Start it yourself after a clean-up, or let Relvato start it when an integrity check comes back clean.

01

Clean the site

Remove the malware — yourself, with your host, or with a clean-up service. Relvato doesn't clean; it tells you whether the clean-up held.

02

Quarantine starts

Click Start quarantine on the site's Security page — or it starts on its own when File integrity, Theme integrity, Admin roster or Third-party scripts comes back clean after finding something.

03

Relvato watches

The integrity checks run every hour. The WordPress plugin reports users, key settings, scheduled tasks, uploads and editor saves as they happen, and fingerprints the risky places every ten minutes.

04

You hear at once

Anything unexpected goes to your email and Slack straight away — even if you normally get a digest — and lands in the change log with its time and how it was seen.

What it watches

The places malware comes back to

Only what matters after a hack: sizes, dates and names — never the contents of your files.

Files in the risky places

The site root and wp-config.php, drop-ins, must-use plugins, PHP in uploads, themes, plugins and WordPress core — new and changed files, within ten minutes.

Administrators and users

New admins, raised roles, an admin's email or password changed — including accounts added straight into the database.

Key settings

The site address, open registration, the role new users get and the active theme: the settings attackers flip to get back in or redirect visitors.

Scheduled tasks

A new WordPress cron job is how deleted malware reinstalls itself. Each new one is logged the first time it appears.

Third-party scripts

A new script or data destination on your pages — the shape of a card skimmer or a spam redirect.

Plugins and themes

Installed, switched on or off, or a security plugin quietly deactivated — the classic first move.

The change log

Every change, with when and how it was seen

Updates you made through WordPress are marked expected, so the changes nobody planned stand out.

10:05HighNew file in uploads: wp-content/uploads/2026/09/cache.phpFingerprint check
10:02ReviewNew scheduled task: wp_cache_restoreReported by the plugin
09:41ExpectedPlugin folder akismet: 30 files changed — follows the Akismet updateFingerprint check
09:00InfoFile integrity is clean againFull check
Example change log during a quarantine
About auto-updates

Pause plugin updates — keep WordPress's security updates on

Auto-updates change files on their own schedule, which muddies a log that should show only what you did. During quarantine, update plugins and themes by hand, one at a time. Relvato can pause plugin and theme auto-updates for you with one click, and they resume on their own when quarantine ends.

Don't switch off WordPress's own security releases: a site that was just hacked needs them most. Updates made through WordPress are marked expected, and File integrity checks their files against wordpress.org.

Plans

On Pro, Business and Agency

Quarantine mode is part of every paid plan. Its hourly checks count toward your monthly runs — about 192 for a 48-hour quarantine with all four checks on. On the Free plan you'll see it on the Security page, and starting it asks you to upgrade.

Go further

Clean it up, then keep it clean

FAQ

Questions about quarantine mode

Does quarantine mode block attacks?

No. It watches and tells you — it doesn't block traffic or delete files. Pair it with a firewall (your host's, Cloudflare, or a security plugin). What it adds is knowing within minutes that a clean-up didn't hold, and exactly what changed.

Why 48 hours?

Self-healing malware usually comes back within hours of a clean-up, from a loader or a scheduled task. 48 hours covers that window, and you can extend it 48 hours at a time, up to a week.

Should I turn off WordPress auto-updates?

Pause plugin and theme auto-updates and update by hand, so every change in the log is one you know about — Relvato can pause them for you. Keep WordPress's own security updates on.

Does Relvato read my files?

No. The fingerprint compares file sizes and modification dates and reports paths — never contents. User changes are reported by login, and an email only as its domain.

What does it need on my site?

The Relvato WordPress plugin (version 1.21.0 or later for the instant reports, the fingerprint and the auto-update pause) and at least one of File integrity, Theme integrity, Admin roster or Third-party scripts turned on.

Does it clean the site for me?

No — Relvato verifies, it doesn't clean. Remove the malware with your host, a clean-up service or your security plugin, then quarantine the site to make sure it stays gone.

After the clean-up

Make sure it stays clean

Connect your WordPress site, turn on the integrity checks, and start quarantine the moment you're done cleaning.