You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GoDaddy托管WordPress网站遭恶意软件侵扰,求防护解决方案

Hey there, sorry to hear you're stuck with this persistent malware issue on your GoDaddy-hosted WordPress site—those random top-of-page links are such a headache, especially since they keep popping back after clearing your Comet Cache. Let’s walk through how to fix this for good, step by step:

First, let’s get those links off your site temporarily while we dig into the root cause:

  • Purge all caches thoroughly: Don’t just clear Comet Cache—head to your GoDaddy hosting panel and clear any server-side caching they offer too (many GoDaddy plans have built-in caching layers). Also, force-refresh your browser with Ctrl+Shift+R to make sure you’re not seeing cached content.
  • Temporarily disable Comet Cache: Go to your WordPress dashboard > Plugins, deactivate Comet Cache, and check if the links disappear. This will confirm if the issue is being injected directly into cached content, or if the malicious code is running elsewhere on your site.

Since clearing cache only fixes it temporarily, the malware is actively generating those links and getting them cached. Here’s where to look:

  • Check WordPress core file integrity: Go to Tools > Site Health > Info > File Integrity. If any core files show as modified, reinstall the WordPress core (Dashboard > Updates > Reinstall Now)—this replaces core files without touching your content or settings.
  • Audit plugins and themes: Outdated or poorly maintained plugins/themes are the most common entry points for malware. Disable all plugins, then re-enable them one by one to see which one triggers the links. Do the same with your theme: switch to a default theme like TwentyTwentyFour to rule out theme-related issues.
  • Inspect wp-config.php and .htaccess: These files are frequent targets for malware. Open wp-config.php and look for suspicious code (like eval(base64_decode(...)) or random strings at the top/bottom). For .htaccess, check for unfamiliar RewriteRules or Redirect directives. Always back up these files before editing, then delete any suspicious lines.
  • Scan your database: Use phpMyAdmin (via GoDaddy’s hosting panel) to check your WordPress database. Look at the wp_options table for altered home or siteurl values, or any strange new options. Also, check the wp_posts table for injected content in posts/pages, and clean out any spam comments that might carry malicious code.
3. Patch Vulnerabilities (Block Future Injections)

Once you’ve found the source, lock down those gaps:

  • Update everything: Make sure WordPress core, all plugins, and your theme are on the latest versions. Outdated software is the #1 reason sites get hacked.
  • Replace risky plugins/themes: If a specific plugin/theme is the culprit, either update it to the latest secure version or replace it with a well-maintained alternative (stick to plugins from the official WordPress repo to avoid malicious copies).
  • Strengthen user accounts: Delete any unused admin accounts, change all admin passwords to complex, unique ones, and enable two-factor authentication (2FA) for all user accounts—WordPress has built-in 2FA support now, or you can use a plugin like Google Authenticator.
  • Enable GoDaddy’s security tools: Turn on GoDaddy’s built-in malware scanner and web application firewall (WAF) in your hosting panel. These tools block malicious requests before they reach your site.
4. Long-Term Security Habits (Keep Your Site Safe)

To prevent this from happening again, build these habits:

  • Regular scans: Install a reputable security plugin like Wordfence or Sucuri (stick to one to avoid conflicts) and run weekly malware scans.
  • Auto-updates: Enable automatic security updates for WordPress core, plugins, and themes. You can set this in Dashboard > Updates > Enable auto-updates for all plugins/themes.
  • Backups: Schedule regular full backups (files + database) using GoDaddy’s backup tool or a plugin like UpdraftPlus. Store backups off-site if possible, so you can restore quickly if something goes wrong.
  • Disable file editing: Add define('DISALLOW_FILE_EDIT', true); to your wp-config.php file. This blocks anyone (including malware) from editing files directly through the WordPress dashboard.

If you’ve gone through all these steps and the links still return, reach out to GoDaddy’s support team—they can check server-level logs to trace where the malicious requests are originating from.

内容的提问来源于stack exchange,提问作者Dev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:02:05