My site was recently hacked by wp2shell so I decided to delete whole site directory and restore an older backup as it was the most safest approach rather than manually checking for malicious files. Is there anything else I need to check outside the wordpress directory if they injected anything maliciously? would they even be able to access outside the defined wordpress directory remotely if using the default wordops configuration