Securantis

WordPress & WooCommerce

Manage the Securantis quarantine on WordPress/WooCommerce: isolate, download, restore and delete without breaking the site

Comprehensive guide to isolating (quarantine), downloading, restoring and deleting files detected by Securantis on WordPress/WooCommerce while minimizing risk to your site.

← Back to help center

Securantis how-to guide

Objective

This guide explains how to use the quarantine feature of the Securantis plugin for WordPress/WooCommerce to isolate suspicious files, download a copy, restore a clean file or permanently delete a malicious file, while preserving your site’s integrity and availability.

Who this article is for

  • WordPress administrators and WooCommerce store owners.
  • Security officers who want to manually manage detections without the risk of automatic deletion.

Before you start — prerequisites and checks

  1. License and plugin: ensure the Securantis plugin is installed and activated on your site and that the license is active if required. Some synchronization and reporting features require a license.
  2. WordPress administrator account: you must have an account with administrative rights to access the security pages and perform quarantine actions.
  3. Full backup: before any restoration or deletion, make a full backup (files + database) stored off the production server. Never restore a file without a prior backup.
  4. Possible maintenance mode: for sensitive operations (restoring WordPress core, a critical plugin, etc.), prepare a maintenance mode or a low-traffic window.
  5. Check the site status: note the WordPress version, the list of active plugins and themes, and the WooCommerce configuration if applicable.

Where the controls are located (context)

The plugin exposes a dedicated page for file and quarantine management in the WordPress dashboard (plugin administration section). This interface allows you to view reported files, isolate a file, download its content, restore it from quarantine or permanently delete it. Actions are designed not to delete anything automatically without explicit confirmation.

Detailed steps

  1. Inspect the detection
  • Go to the plugin administration page and open the file/quarantine management section.
  • For each entry, read the report: type of detection, affected component (core, plugin, theme, media), risk level and any comments.
  • Look for clues: recent modifications, timestamp, file owner, presence in an official footprint.
  1. Isolate (quarantine)
  • If a file is suspicious and you do not want it active, use the isolation option provided in the interface.
  • Expected effect: the file is moved or rendered inactive atomically and traceably. The site should remain functional if the file was not required for public rendering (e.g. a media file); if it was an active component (plugin or theme), some dependent features may be temporarily altered.
  • Immediately check the front end and critical functions (WooCommerce checkout, contact form). If the site shows regression, restore quickly from quarantine (see below).
  1. Download a copy for analysis
  • Before any deletion or restoration, download the copy of the isolated file from the quarantine interface.
  • Use this file for local analysis (antivirus, manual review by an expert). Keep the downloaded copy in a secure, timestamped location.
  1. Restore a file from quarantine
  • If analysis shows it is a false positive or a required file, restore it using the restore option.
  • Expected effect: the file returns to its original location and permissions. After restoration, immediately test key site functions (checkout, login, administration).
  • If restoration reintroduces malicious behavior, re-isolate the file immediately and contact support.
  1. Permanently delete
  • If analysis confirms malicious code and deletion is preferable, choose permanent deletion. This operation is irreversible from the interface.
  • Before deletion, ensure you have downloaded a copy and have a full site backup.

Prudent settings and best practices

  • Proceed step by step: isolate → analyze → restore or delete. Do not apply automatic deletion.
  • Test in a staging environment: if in doubt, reproduce the quarantine and restorations on a preproduction site.
  • Logging: keep action logs (who isolated, restored, deleted, and when). This facilitates post-mortem and any claims.
  • Permissions: verify that restored files retain the recommended permissions for WordPress and your hosting.
  • Maintain access security: never share passwords or private keys by email or chat. Access for paid interventions is only provided via the secure client area after payment.

Common mistakes and how to avoid them

  • Immediate deletion without backup: consequence = data loss or functionality break. Always back up first.
  • Restoration without verifying the source: reintegrating a malicious file can trigger the attack again. Analyze locally before restoring.
  • Forgetting to test WooCommerce: some files affect order logic or webhooks — test order and refund scenarios.
  • Incorrect permissions after restoration: correct permissions (read/write) if the interface reports errors or if WordPress cannot access the files.

Troubleshooting

Symptom: the site loses functionality after quarantine

  • Check which component was isolated (plugin, theme, core).
  • If it’s a critical plugin, restore from quarantine and test immediately. If restoration is impossible, restore the file from the full backup.

Symptom: restoration reintroduces suspicious behavior

  • Re-isolate the file immediately.
  • Download the restored copy and have it analyzed by an antivirus/analyst.
  • Put the site into maintenance mode if the compromise affects active users.

Symptom: the quarantine interface returns an error on action

  • Check file system permissions and available disk space.
  • Enable WordPress and plugin logs to obtain error messages.
  • If the administration page is inaccessible, use FTP/SFTP access to manually check the state of the isolated file.

Legal and operational precautions

  • Do not automatically delete evidence: if an attack is confirmed and judicial investigation is possible, keep a timestamped copy and the logs.
  • Inform internal stakeholders (hosting provider, e-commerce manager) before deleting critical files that affect transactions.

When to contact Securantis support

Contact support if:

  • You observe a recurring active compromise after restoration.
  • You cannot restore a file that breaks essential functions.
  • The interface returns technical errors (permissions, file move failures) that you cannot fix.
  • You need assistance for in-depth analysis of a suspicious file.

Important reminder about quarantine and deletion

Securantis does not perform automatic deletion without human decision. Quarantine isolates and secures: permanent deletion must be decided after analysis. Any external intervention requiring privileged access is done via secure channels and, for paid interventions, after providing access in the secure client area.

Expected result after correct handling

  • Suspicious files isolated without major service interruption.
  • Copies downloaded and archived for future analysis.
  • Safe restorations after verification (false positives corrected).
  • Malicious files removed in a documented and irreversible manner when necessary.

If you need help analyzing a downloaded file or want an expert to intervene, contact Securantis support providing the detection ID and action logs (without passwords).

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active