Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Learn when a WordPress problem needs emergency support, what to preserve, how incidents are triaged and which details help an engineer respond safely.
You need emergency WordPress support when a fault materially affects trading, customer trust, data or administrator control and the normal maintenance route cannot contain it safely. Examples include a checkout outage, malicious redirect, widespread error, locked-out administrators or a failed update that cannot be rolled back.
Reviewed: 9 September 2026
| Impact | Example | First objective |
|---|---|---|
| Critical | Checkout unavailable, active compromise, unsafe data exposure | Contain harm and preserve evidence |
| High | Whole site down, malicious redirect, administrators locked out | Restore a safe service or holding page |
| Medium | Important form or page failing | Provide a workaround and diagnose |
| Routine | Minor styling issue or non-critical plugin warning | Schedule a controlled fix |
Priority follows business impact, not how alarming an error message looks. A broken button on a low-traffic page may wait; a normal-looking checkout that does not create orders may be urgent.
Do not repeatedly clear data, reinstall components or restore over the live site without understanding the effect. Those actions can remove evidence, overwrite recent orders or make rollback harder.
Provide the domain, hosting provider, WordPress and PHP versions if known, recent changes, screenshots, exact times, affected user journeys and available backups. Identify the business impact and the person authorised to approve containment, rollback or downtime.
Share access through a controlled password manager or named temporary account. Do not paste production credentials into an ordinary email thread. If an account may be compromised, create or rotate access through a trusted route.
Check DNS, certificate, hosting status, resource exhaustion, web-server and PHP errors, database connectivity and recent deployments. A generic 500 error can have many causes. Use logs and a minimal reproduction rather than disabling every component at once.
If a holding page is appropriate, ensure it does not claim orders or forms work when they do not. Keep stakeholders updated with known impact, current action and the next review time.
Confirm what changed and whether the deployment completed. WordPress provides documented troubleshooting routes for failed upgrades and plugin issues, including filesystem access where the administration screen is unavailable. Follow the current WordPress update guidance and validate against the real hosting setup.
Use staging or an isolated copy to identify the conflict where time and data allow. Restore only from a known recovery point and account for orders, form submissions and content created after that point.
Contain affected access, preserve logs, rotate exposed credentials through clean devices and identify persistence before declaring the site clean. Review administrators, plugins, themes, scheduled tasks, files, database content, DNS, hosting and connected services. A visible malicious file may be one symptom rather than the entry route.
If personal data may be involved, involve the organisation’s responsible decision-makers and advisers promptly. Technical repair alone does not decide notification or legal obligations.
Check the complete route: product, basket, shipping, tax, payment, webhook, order creation, stock and confirmation. Determine whether customers were charged without an order or whether duplicate attempts are possible. Coordinate with the payment provider and preserve transaction identifiers without exposing full payment data.
Use ACA’s e-commerce readiness check for a public first look, but do not use a surface scan as proof that a checkout is safe or processing correctly.
Confirm domain ownership, nameservers, DNS answers, certificate hostname and expiry, and recent changes. Avoid changing several DNS records at once. Keep the previous values and TTL, assign one change owner and validate from more than one resolver or network where appropriate.
The DNS propagation viewer and TLS certificate checker can provide external evidence for a controlled investigation.
Build a short first-response route with ACA’s incident response card builder and estimate the operational impact with the downtime cost calculator.
Maintain named ownership, monitored backups, update and staging procedures, uptime and certificate alerts, least-privilege administrator access, strong authentication, change records and a tested supplier escalation route. Remove unsupported or unused extensions and keep domain, hosting and source ownership clear.
ACA provides on-demand website and WordPress support for defined urgent issues, alongside ongoing website care where continuous ownership is the better fit.
Not until you understand its date, integrity and effect on recent data. Preserve the current state and plan how orders, forms or content created after the backup will be handled.
No. It can provide useful signals, but investigation must consider accounts, hosting, files, data, scheduled tasks, DNS and the original entry route.
Use named, time-limited access with the minimum privileges needed. Record changes and remove or rotate access when the incident closes.