Quote from: cwork at Apr 30, 2017, 04:42 AMQuote from: BobRay at Apr 29, 2017, 10:54 PM
If you're on a shared server, it's possible that some other user there (or a hacker of another site there) has gained general access to your server. In that case, it's likely that nothing you do will help, short of starting over at another host.
We're being hosted now on GoDaddy, do you mean we should leave GoDaddy?
From what I've seen, GoDaddy doesn't have the best reputation for hosting MODX sites, and I've seen a number of complaints about their support. If the hacker has penetrated the server you are on at GoDaddy (and they may not have), the hacking will almost certainly continue.
If you can find and remove all the points of access for the hacker, you may want to stay there, but if another hack occurs after that, I'd move.
FYI:
https://bobsguides.com/modx-friendly-hosts.html
With respect to SSL, both Firefox and Chrome are pushing people toward SSL by issuing security warnings on any page with a form (e.g., a contact form). Using https no longer slows down sites as it once did (in fact some reports suggest that https sites are now faster than http), so using https site-wide is what I'd recommend (notice that modx.com and all it's sub-sites are now fully secure).