Protecting Your Website from Malware

Protecting Your Website from Malware

Malware can compromise your website, steal visitor data, and damage your reputation. This guide covers how to protect your site from malware and what steps to take if your site becomes infected.

How to Prevent Malware

  1. Keep everything up to date — Ensure your CMS (WordPress, Joomla, Drupal), plugins, themes, and PHP version are always running the latest versions
  2. Use strong passwords — Set strong, unique passwords for your hosting account, Plesk, CMS admin, FTP, and database users
  3. Remove unused software — Delete any plugins, themes, or applications you're no longer using
  4. Only install trusted software — Only download plugins and themes from official sources. Avoid free or pirated versions of premium software, as they often contain malicious code
  5. Use FTPS for file transfers — Always connect using FTP-SSL to keep your login credentials encrypted during file transfers
  6. Restrict file permissions — Set appropriate file and folder permissions to prevent unauthorised modification
  7. Enable spam filtering — Use SpamAssassin to filter out malicious emails that could be used in phishing attacks
  8. Back up regularly — Keep regular backups of your website so you can quickly restore a clean version if needed

What to Do If Your Site is Infected

  1. Run a malware scan — Use ImunifyAV in Plesk to scan your website for malicious files
  2. Review scan results — Check the results and identify any infected files
  3. Restore from a clean backup — If you have a recent backup from before the infection, restore it using the WP Toolkit or Plesk backup tools
  4. Change all passwords — Update passwords for your Zeniar Portal, Plesk, CMS admin, FTP accounts, and database users
  5. Update all software — Ensure your CMS, plugins, and themes are fully up to date
  6. Contact support — If you need help cleaning up your site, reach out to our team at [email protected]