My Wordpress Sites Are Getting Hacked very Often Hosted on Namecheap

You might have some plugin or theme which has a backdoor.... Remove all themes and plugins... only install official themes and plugins...

Optimize your database... Change Username and password for your WordPress and database including Cpanel/hosting logins...
 
Beware if you use elementor, got some of my websites hacked this week because of it...

What plugins did you use?
 
Setup wordfence
I assume you're on shared hosting. Not many choices in that case.
 
My clients website got hacked previously mainly redirecting issue, so I fixed it by adjusting the database malicious code has been added to the database and I fixed by changing the URL inside WP_option file I think.
 
Beware if you use elementor, got some of my websites hacked this week because of it...

What plugins did you use?

What happened to Elementor? Millions of us use it. Is it the premium version? Nulled?
 
Last edited:
I guess it must be a script (plugin/theme), WordPress has a history of being exploited.
 
Wordfence is great of you want a slow site.
Have you got 2fa enabled?
 
My Wordpress Sites Are Getting Hacked very Often Hosted on Namecheap


Can Anyone help

Make sure to scan your files using Cleantalk and replace your passwords with strong ones.
 
I don't think Namecheap as a host has any role here. There are thousands of other sites they are hosting without any issue. The issue must be your local. May be a set of plugins or a nulled theme or cracked plugin - you have to figure it out yourself.
 
Because it is vulnerable af. Nulled or paid version alike. There were two in last few weeks alone and millions of sites got hacked. Doesn’t matter namecheap or wherever you host it, Wordpress in general is full of such vulnerabilities just waiting to be discovered.
 
Probably it's some plugin you have that opens the back door to your site getting hacked.
 
I'm not accusing Namecheap though, but one of my sites was recently hacked.
 
Make sure you are not using any nulled scripts, they have back doors most of the time.

Use 2FA for login.
 
Install security plugins, Backup your site regularly, Try removing unused themes & plugins, limit the logins attempts, Secure your hosting environment, monitor the site activity regularly.
 
WordPress is one of the most popular free CMS out there, so it's clearly a target.

We are seeing tens of thousands of hacking attempts every single day for plugins and themes. WordPress itself is pretty safe, but people's websites get hacked because they don't update their WordPress installation or plugins, or themes. Also, installing nulled scripts is a very bad idea. Another thing that we often see is that people install and keep many unused plugins/themes, and fairly often, websites get hacked through there. Disabling the plugin/theme doesn't mean the attacker can't directly access PHP files from the server.

Keep your site up to date, remove all unnecessary plugins/themes, and the chance of something happening with your site is very small. It would be a good idea to use some kind of firewall in front of your site as well.. if you are super worried. Most shared hosts use ModSecurity rules, and it has a rule set for WordPress as well. Also, it's reasonable to learn a bit about security and how to keep your site safe.. No hosting company can keep your site safe if you are not doing basic safety checks yourself (we are not talking about managed WordPress hosting services).
 
Back
Top