Hacked site

Hi, I just thought I would post this and see if I could get some recommendations. I am developing a site for a client, the site has been migrated to our development server.

When I switch themes to Pro I see a white page with this little message:
“hacked by MRX(team_cc)”

I realize this is not a Pro Issue, I think the old admin had hidden this message somehow, or the theme they were using was somehow setup to bypass this.

Any good recommendations on how to move forward? We have this setup on our development server.

Hello Andrew,

Thanks for writing in!

Website and server security is a continuous process. Few things that I can suggest you:

  1. Use latest version of WordPress, Pro Theme, Plugins: We always recommend our customers to always run latest version of WordPress, Pro Theme and the plugins that they are using. Latest packages comes with host of security and bug fixes at the same time new features.
  2. Reputable hosting provider: It’s crucial give some thought on the hosting provider as that’s the base platform on which website is running. It’s not a good idea to use Shared hosting as resources are shared and usually cause security issues. You can take a look at Digital Ocean, Linode, Cloudways, WP Engine etc got hosting requirement.

You can take a look at following resource to learn more about security:

Following video by Matt Cutts is also a great resource about security. Video is a bit dated but the suggestion made by Matt Cutts is still relevant today:

Thanks.

Thanks!

Yes, I keep all my sites pretty secure. I use Securi free on some sites but when I can convince the site owner, I use the Securi WAF, and also have most of my sites on my server at InMotion Hosting. In any case, this new site has certainly been hacked. I just need to clean it up before moving forward.

Hey Andrew,

You might also want to check out the Wordfence plugin as it could help to improve the security of your website and scan the entire website files for any malicious codes.

Hope this helps.

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.