Find out how far the compromise goes
The first malicious file discovered may not be the only one.
Attackers can modify legitimate files, create new files, inject database content, add users or leave mechanisms designed to restore access after an incomplete cleanup.
We investigate beyond the first visible symptom to understand which parts of the WordPress environment may have been affected.
That scope determines how the recovery should proceed.