CURRENT STATUS
The latest documented status of the Hostinger case as of September 15, 2026 at 14:48 CEST, including the recurrence, preservation-hold verification, source-custody questions and proposed whitelist review.
This page reflects the latest documented case state supported by the supplied archive as of September 15, 2026 at 14:48 CEST. Earlier statements remain in the timeline; this page records the current cutoff without silently rewriting the historical record.
What is established
Hostinger issued its final internal review on September 7. A new manager.php removal occurred on September 10. Hostinger confirmed on September 11 that the explicit preservation/retention-hold request had been recorded in complaint #137820. On September 15 the preservation request was expressly renewed and Hostinger acknowledged that renewal.
What Hostinger still could not verify at 14:48 CEST
Hostinger still could not provide a verified Yes-or-No answer on whether a preservation or retention hold had actually been applied to the September 10 event records or to any original or quarantined object. It also said it could not responsibly confirm the existence, expiry, deletion status or retention period of those records without completing internal verification. Hostinger stated that, under its current policy, a customer-initiated preservation request does not automatically trigger a hold; this case file records that as Hostinger’s policy statement, not as a legal conclusion adopted by this publication.
Source disclosure and whitelist review
At 13:33, Hostinger requested another complete copy of manager.php through pwpush.com for a formal whitelist review described as separate from the platform-wide Imunify policy.
At 14:39 the customer expressly stated that this was not a refusal of a properly scoped independent technical review, while requiring custody, purpose, recipients, access controls, retention and disposition to be defined before another complete-source disclosure. Hostinger said at 14:48 that no additional source-code disclosure was required while those questions remained unresolved.
File-version identity commitment
Hostinger said its written response would need to reconcile the category-based classification, the proposed whitelist review, the authority and possible outcome of that review, and the exact identity of any file version examined. It also said it would not characterize a later or current file as the September 10 incident-time object.
Current pending items
At the September 15, 14:48 CEST cutoff, the promised verified preservation answer and remaining point-by-point clarification were still pending. The source-custody questions around prior complete-file submissions to CloudLinux also remained unresolved in the supplied archive.