Post-hack recovery
One-click actions for the day after a clean-up, clearing credentials a password reset never touches.
2 checks in this group, 2 with a full write-up.
Joomla
Revoke Every API Token After a Hack
After a hack: remove every Joomla API token, rotate the automated updates key, and optionally switch the Joomla API off and log everyone out.
WordPress
Revoke Every Application Password After a Hack
Revokes every WordPress Application Password on the site in one go, and can log every user out. Run it after a hack, because a password reset leaves Application Passwords working.
Find out which of these your sites fail
Connect a site and every check in this group runs against it automatically, with the result and the fix in one place. Open it from the tool finder after a clean-up, one site at a time.
Run a free audit