Your web host suspended your website: the possible causes

Where your website used to be, a page now says the account has been suspended. A suspension usually comes down to one of four causes, and each is resolved differently: a hacked site, resource usage over the limits, an unpaid invoice, or a complaint received by the host. Here is how to tell which one, and the steps to get the site back online.

Published on 28 September 2026 9 minute read

All guides

In short

  1. Find the host’s message: the account’s email inbox, spam folder included, the client area, the support tickets. It usually names the cause.
  2. Ask in writing for what is missing: the list of flagged files, the logs, the complaint and its reference.
  3. Get a copy of the files and the database, or ask the host for one, before doing anything else.
  4. Hack: clean up and close the attacker’s access before going back online. Infected files stay infected at another host.
  5. Resources: read the usage graphs, then look for bots, heavy plugins and backups stored on the account.
  6. Invoice or complaint: pay, or reply in writing quoting the case reference.

Find the cause

On hosting run with cPanel, a suspension replaces the site with a page stating that the account is suspended ("This Account has been suspended"). It also blocks the control panel login, FTP access and outgoing email from the account; incoming email depends on the server configuration. The files themselves stay in place.

The cause is usually spelled out in a message from the host: search the email inbox tied to the account, spam folder included, for "suspension", "abuse", "malware" or "invoice", then check the client area and its tickets.

CauseWhat the message usually saysWhat to ask for
Hacked siteMalware, phishing or outgoing spam detected, sometimes with file paths.The list of detected files, the detection date, the logs for that period.
ResourcesCPU, memory, simultaneous processes, inodes or disk space over the limit.The usage graphs and the access logs for that period.
Unpaid invoicePayment overdue, renewal unpaid, payment method declined.The amount due, and the date data would be deleted under the terms of service.
Complaint or termsCopyright complaint, abuse report, content against the terms of service.The complaint itself, the URL concerned, and the deadline to reply.

If the message gives no cause, ask for it in writing, along with the clause of the terms of service involved: a suspension is lifted faster when everyone is talking about the same problem.

First, save a copy of the site

The host’s terms of service set the period after which a suspended account’s data may be deleted. Before anything else, put a copy somewhere safe:

Keep that copy exactly as it is, even if the site is infected: it is what you clean from and compare against.

Cause 1: a hacked site

On a shared server, a site that spreads malware, hosts fake login pages or sends spam puts the other accounts and the reputation of the server’s IP addresses at risk. The host suspends the account, and reopens it once the problem is dealt with.

  1. Ask for the list of detected files, and whether the host can reopen file access while you clean up.
  2. Delete the flagged files, then look for whatever dropped them: PHP files in wp-content/uploads, unknown folders at the root, email-sending scripts, added administrator accounts.
  3. Change the hosting, FTP, database and administrator passwords, and replace the security keys in wp-config.php.
  4. Update WordPress, the theme and the plugins, and delete any that are no longer used.
  5. Write to the host describing what was found, removed and fixed, quoting the suspension reference.

Moving to another host with the same files takes the infection along, and with it the risk of another suspension. Cleaning happens before the site goes back online, wherever that is.

Cause 2: resource usage over the limits

Shared hosting caps what each account consumes. On servers running CloudLinux, the limits cover CPU, physical memory, disk input and output, the number of processes and entry processes, meaning simultaneous connections to dynamic scripts such as PHP. The number of files is counted in inodes: every file and every folder uses one.

When the entry process limit is reached, visitors get a 508 "Resource Limit Is Reached" error. Repeated overruns can lead to suspension. Your hosting panel shows usage over time: spot the peak hours, then read the access logs for those hours.

The most common causes

Terminal: the heaviest folders, and the number of files
du -sh wp-content/* | sort -h
find . -type f | wc -l
.htaccess (Apache 2.4): close off xmlrpc.php
<Files "xmlrpc.php">
Require all denied
</Files>

This block refuses every request to xmlrpc.php. First check that no tool relies on it: Jetpack, for instance, goes through XML-RPC. If the site then shows a 500 error, your host does not allow this directive in .htaccess: remove the block and ask them for the equivalent.

wp-config.php: stop running scheduled tasks on every visit
define( 'DISABLE_WP_CRON', true );

Scheduled tasks then need to be called by the server’s scheduler: in your hosting panel, create a cron job that calls https://www.your-site.com/wp-cron.php at a regular interval, every 15 minutes for example.

Cause 3: an unpaid invoice

Pay the invoice from the client area, and check that the saved card has not expired. Reactivation follows payment, automatically or on request depending on the host; if it takes a while, open a ticket quoting the payment reference.

The domain name is often renewed separately from the hosting. An expired domain also takes the site offline, but the page shown is then the registrar’s, not the host’s: two invoices, two checks.

Cause 4: a complaint or a breach of the terms

Reply in writing, within the stated deadline, describing what was done: that is the document the host files to lift the suspension.

Before the site goes back online

  1. The cause is identified and fixed, and the host has confirmed in writing what it expects.
  2. Passwords are changed and the site’s components are up to date.
  3. An automatic backup exists, stored outside the hosting account.
  4. Someone receives the host’s alerts: the account’s email address is read.

A site taken over and looked after

With the suspension lifted, one question remains: who looks after the site from now on? Simafri takes over your WordPress site, puts it back online on a base we host, secure and keep up to date, and looks after it month after month. You keep your domain name and your content.

Have my site taken over

Frequently asked questions

How long does a host keep the files of a suspended website?

It depends on each host’s terms of service. Ask for the planned deletion date in writing, and save a copy of the files and the database straight away, over SFTP or by asking for an archive.

Can I move my site to another host while it is suspended?

Yes, from a copy of the files and the database. If the suspension comes from a hack, clean the site first: infected files carry the infection to the new host. The domain name then needs to point to the new hosting.

Why was my site suspended when it gets few visitors?

Usage does not only come from visitors: bots trying logins on wp-login.php or xmlrpc.php, a heavy plugin, backups stored on the account or a hacked site sending spam all consume resources. The usage graphs and access logs show which.

The host’s message gives no cause. What should I do?

Ask for it in writing, along with the clause of the terms of service involved, the list of flagged files if there is one, and the logs for the period. Keep the exchanges: they form the case file for lifting the suspension.

Contact us