WordPress Site Hacked — How to Clean It Up

Higher-risk issue — be cautious and consider professional help sooner.

Your WordPress site is showing spam pages, redirecting visitors to scam sites, or your host has flagged malware — someone else has code running on your site.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

A hacked WordPress site almost always traces back to one of two doors: an outdated plugin or theme with a known security hole, or a stolen or guessed password. Attackers scan the whole internet automatically for both — it is nothing personal, and small-business sites are hit constantly precisely because nobody expects to be a target.

Once inside, the attacker's first move is not the visible damage — it is installing backdoors: small hidden files that let them back in later even after you change every password. The spam pages or redirects you can see are only the surface. This is the crucial thing to understand about cleanup: deleting the visible spam while leaving the backdoors is like changing the locks while a copied key is taped under the doormat.

That is why the most common hacked-site story is reinfection: the owner or a well-meaning friend removes what they can see, the site looks clean for a few days, and then the spam is back — because the attacker simply walked in through the backdoor they left. A real cleanup means finding every hidden file, updating everything, rotating every password and secret key, and then asking Google to review and clear any warnings. Each step matters; skipping one usually means doing the whole thing twice.

What not to do

When to get help

This is one of the few website problems where recommending professional help is simply the honest advice. The password changes, host contact, and evidence-preserving steps above are genuinely yours to do, and doing them today matters. But the cleanup itself — finding every backdoor among thousands of files, closing the hole that let the attacker in, rotating the secret keys most owners never knew existed, and walking Google through its review process — is detective work that rewards experience. The economics favor it too: a professional cleanup is typically a one-time cost, while a DIY cleanup that misses one hidden file tends to mean doing everything again in a week, plus the ongoing cost of a site Google distrusts. If your site takes orders or represents your business, getting it cleaned properly once is almost always the cheaper path.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

How do WordPress sites get hacked?

Almost always through an outdated plugin or theme with a known security hole, or through a stolen or guessed password. Attackers use automated tools that scan millions of sites for these openings, so small sites get hit just as often as big ones — it is opportunistic, not personal.

Can I clean a hacked WordPress site myself?

You can do the important first steps: change passwords from a clean device, check for unknown admin users, notify your host, and preserve evidence. The deep cleanup — finding hidden backdoor files and closing the original hole — is where DIY attempts usually fall short, and a missed backdoor means reinfection within days.

Why does my site keep getting hacked again after cleanup?

Because the cleanup removed the visible damage but not the hidden backdoor files the attacker installed, or left the original security hole open. Reinfection after a partial cleanup is the most common hacked-site story. A thorough cleanup addresses the files, the entry point, and every password and secret key.

Will restoring a backup fix a hacked WordPress site?

Rarely on its own. The backup may already contain the infection, and even a clean restore leaves open the security hole that let the attacker in — so the site gets hacked again the same way. A restore can be part of recovery, but only alongside updates, password rotation, and closing the entry point.

How long does it take to clean a hacked WordPress site?

A professional cleanup of a typical small-business site often takes a day or two, sometimes less. Getting Google to remove warnings after cleanup usually takes a few more days once a review is requested. Partial DIY cleanups tend to take longer overall because the work gets repeated after reinfection.

Does being hacked hurt my Google rankings?

Yes, while it lasts. Google may label the site as hacked or deceptive, which collapses clicks, and spam pages pollute your search results. The good news: after a proper cleanup and a successful review request, warnings are removed and rankings generally recover over the following weeks.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible