Where your website used to be, a page now says the account has been suspended. A suspension usually comes down to one of four causes, and each is resolved differently: a hacked site, resource usage over the limits, an unpaid invoice, or a complaint received by the host. Here is how to tell which one, and the steps to get the site back online.
On hosting run with cPanel, a suspension replaces the site with a page stating that the account is suspended ("This Account has been suspended"). It also blocks the control panel login, FTP access and outgoing email from the account; incoming email depends on the server configuration. The files themselves stay in place.
The cause is usually spelled out in a message from the host: search the email inbox tied to the account, spam folder included, for "suspension", "abuse", "malware" or "invoice", then check the client area and its tickets.
| Cause | What the message usually says | What to ask for |
|---|---|---|
| Hacked site | Malware, phishing or outgoing spam detected, sometimes with file paths. | The list of detected files, the detection date, the logs for that period. |
| Resources | CPU, memory, simultaneous processes, inodes or disk space over the limit. | The usage graphs and the access logs for that period. |
| Unpaid invoice | Payment overdue, renewal unpaid, payment method declined. | The amount due, and the date data would be deleted under the terms of service. |
| Complaint or terms | Copyright complaint, abuse report, content against the terms of service. | The complaint itself, the URL concerned, and the deadline to reply. |
If the message gives no cause, ask for it in writing, along with the clause of the terms of service involved: a suspension is lifted faster when everyone is talking about the same problem.
The host’s terms of service set the period after which a suspended account’s data may be deleted. Before anything else, put a copy somewhere safe:
wp db export, or in the same archive request.Keep that copy exactly as it is, even if the site is infected: it is what you clean from and compare against.
On a shared server, a site that spreads malware, hosts fake login pages or sends spam puts the other accounts and the reputation of the server’s IP addresses at risk. The host suspends the account, and reopens it once the problem is dealt with.
wp-content/uploads, unknown folders at the root, email-sending scripts, added administrator accounts.wp-config.php.Moving to another host with the same files takes the infection along, and with it the risk of another suspension. Cleaning happens before the site goes back online, wherever that is.
Shared hosting caps what each account consumes. On servers running CloudLinux, the limits cover CPU, physical memory, disk input and output, the number of processes and entry processes, meaning simultaneous connections to dynamic scripts such as PHP. The number of files is counted in inodes: every file and every folder uses one.
When the entry process limit is reached, visitors get a 508 "Resource Limit Is Reached" error. Repeated overruns can lead to suspension. Your hosting panel shows usage over time: spot the peak hours, then read the access logs for those hours.
wp-login.php or xmlrpc.php with login attempts.wp-content, filling disk space and inodes.du -sh wp-content/* | sort -h
find . -type f | wc -l
<Files "xmlrpc.php">
Require all denied
</Files>
This block refuses every request to xmlrpc.php. First check that no tool relies on it: Jetpack, for instance, goes through XML-RPC. If the site then shows a 500 error, your host does not allow this directive in .htaccess: remove the block and ask them for the equivalent.
define( 'DISABLE_WP_CRON', true );
Scheduled tasks then need to be called by the server’s scheduler: in your hosting panel, create a cron job that calls https://www.your-site.com/wp-cron.php at a regular interval, every 15 minutes for example.
Pay the invoice from the client area, and check that the saved card has not expired. Reactivation follows payment, automatically or on request depending on the host; if it takes a while, open a ticket quoting the payment reference.
The domain name is often renewed separately from the hosting. An expired domain also takes the site offline, but the page shown is then the registrar’s, not the host’s: two invoices, two checks.
Reply in writing, within the stated deadline, describing what was done: that is the document the host files to lift the suspension.
With the suspension lifted, one question remains: who looks after the site from now on? Simafri takes over your WordPress site, puts it back online on a base we host, secure and keep up to date, and looks after it month after month. You keep your domain name and your content.
It depends on each host’s terms of service. Ask for the planned deletion date in writing, and save a copy of the files and the database straight away, over SFTP or by asking for an archive.
Yes, from a copy of the files and the database. If the suspension comes from a hack, clean the site first: infected files carry the infection to the new host. The domain name then needs to point to the new hosting.
Usage does not only come from visitors: bots trying logins on wp-login.php or xmlrpc.php, a heavy plugin, backups stored on the account or a hacked site sending spam all consume resources. The usage graphs and access logs show which.
Ask for it in writing, along with the clause of the terms of service involved, the list of flagged files if there is one, and the logs for the period. Keep the exchanges: they form the case file for lifting the suspension.
Simafri
Let's talk about your website
Tell us about your project in a few words: we will get back to you quickly.
Thank you! Your request has been sent. We'll get back to you shortly.
Prefer email? Write to us at support@simafri.com.