Preventing a WordPress crisis
What to do before something goes wrong with your site, and what to do when it already has.
Most WordPress problems come from a few causes. An update breaks a page, a login is compromised, or an edit removes something it should not have. All of them are recoverable if you can get back to a known good copy of the site.
Your site is already backed up
We take a snapshot of your whole site every day, and you can restore one yourself from the Pendeo plugin in your WordPress admin. You do not need a separate backup plugin to be covered.
Take a snapshot of your own before any change you would not want to undo by hand. A major plugin update or a change of theme both qualify.
Reducing the chance of trouble
Keep WordPress, your plugins and your themes updated. Most compromises exploit a known flaw that an update had already fixed.
Use a long, unique password on every account that can reach the site, and delete accounts nobody uses. Give each person the lowest role that still lets them do their job.
Change the default administrator username if it is still in place. Leaving it saves an attacker half the work of guessing a login.
Sign in every so often and look at the site as a visitor would. Google Search Console will also email you when it finds a problem, which is often how owners hear about one first.
If something has already gone wrong
Start by restoring the most recent snapshot from before the problem appeared. That is usually quicker than diagnosing the fault, and it puts the site back in front of visitors while you work out what happened.
Contact support when the restore does not fix it, or when you are unsure which snapshot to pick. Telling us what changed, and roughly when, is the most useful thing you can bring.
A compromised site needs more than a restore, because whatever allowed the compromise is usually still there. Change every password, update everything, and consider a specialist such as Sucuri to clean and monitor the site.