MB Bluejuice
Security

Why a cleaned site gets reinfected a week later

Reinfection almost always means the cleanup was done without an investigation.

· updated 2026-10-07

If malicious code returns, it does not mean the site is under constant attack. It almost always means the original route stayed open.

Five typical causes

  1. The vector was never found. The code was removed but not the hole it came through. The next automated scan finds the same hole.
  2. Credentials were not rotated. If the attacker had FTP or database access, clean files are no obstacle.
  3. A persistence mechanism remained. A cron job or a wp_options row that restores the code automatically.
  4. Restored from an infected backup. If the infection went unnoticed for a month, a month-old backup is infected too.
  5. A neighbour on the same server. In shared hosting another client’s site can be the source — one argument for an isolated environment.

The correct sequence

Preserve evidence → identify the vector → clean → rotate credentials → harden → monitor. Swap the first two steps or skip them, and everything after becomes temporary.

That is exactly why cleanup is the fourth stage, not the first, in our incident response process.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.