· updated 2026-10-07
If malicious code returns, it does not mean the site is under constant attack. It almost always means the original route stayed open.
Five typical causes
- The vector was never found. The code was removed but not the hole it came through. The next automated scan finds the same hole.
- Credentials were not rotated. If the attacker had FTP or database access, clean files are no obstacle.
- A persistence mechanism remained. A cron job or a
wp_optionsrow that restores the code automatically. - Restored from an infected backup. If the infection went unnoticed for a month, a month-old backup is infected too.
- A neighbour on the same server. In shared hosting another client’s site can be the source — one argument for an isolated environment.
The correct sequence
Preserve evidence → identify the vector → clean → rotate credentials → harden → monitor. Swap the first two steps or skip them, and everything after becomes temporary.
That is exactly why cleanup is the fourth stage, not the first, in our incident response process.