WordPress Site Hacked — How to Clean It Up
Higher-risk issue — be cautious and consider professional help sooner.
Your WordPress site is showing spam pages, redirecting visitors to scam sites, or your host has flagged malware — someone else has code running on your site.
Common signs of this issue
- Google results for your site show pages you never created — often pharmacy spam, casino pages, or products in another language.
- Visitors clicking through to your site get redirected to scam, gambling, or adult sites.
- Your homepage has been replaced or defaced, or strange links appear in your footer or sidebar.
- Your hosting company emailed a malware warning, suspended the account, or quarantined files.
- The WordPress Users list shows administrator accounts nobody on your team created.
- Browsers or Google show a red warning like "This site may be hacked" or "Deceptive site ahead" before your site loads.
- Customers report spam emails coming from your domain, or your emails suddenly land in spam folders.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- From a clean device — a computer or phone you trust — change your hosting account password, your WordPress admin passwords, and the password of the email address tied to those accounts. If the hacker got in through a stolen password, this closes that door first.
- Open the WordPress Users list and note any administrator accounts you do not recognize. Write down the usernames — they are evidence — and remove or demote them if you can log in.
- Consider taking the site offline temporarily, or ask your host to. A hacked site harms visitors and your reputation every hour it runs; a short maintenance page harms nothing.
- Contact your hosting company and tell them the site is compromised. Many hosts run malware scans and can hand you a report listing exactly which files are infected — free information a cleaner will want.
- Ask your host to preserve a backup of the site as it is now, hacked state and all. It feels backwards, but the infected copy is the evidence a professional uses to find how the attacker got in and every file they touched.
- Check Google Search Console for your site. Look at the Security Issues section for Google's own findings, and check the list of verified owners — attackers sometimes add themselves as an owner to keep control, and that stays even after cleanup unless removed.
- Find your most recent clean backup and note its date. Do not restore it yet — restoring alone rarely fixes the underlying hole — but knowing what you have and how old it is shapes every decision that follows.
- Make a quick list of what the site runs: which plugins, which theme, roughly when things were last updated, and who else has admin access. A cleaner will ask, and having answers ready shortens the job.
What this usually means
A hacked WordPress site almost always traces back to one of two doors: an outdated plugin or theme with a known security hole, or a stolen or guessed password. Attackers scan the whole internet automatically for both — it is nothing personal, and small-business sites are hit constantly precisely because nobody expects to be a target.
Once inside, the attacker's first move is not the visible damage — it is installing backdoors: small hidden files that let them back in later even after you change every password. The spam pages or redirects you can see are only the surface. This is the crucial thing to understand about cleanup: deleting the visible spam while leaving the backdoors is like changing the locks while a copied key is taped under the doormat.
That is why the most common hacked-site story is reinfection: the owner or a well-meaning friend removes what they can see, the site looks clean for a few days, and then the spam is back — because the attacker simply walked in through the backdoor they left. A real cleanup means finding every hidden file, updating everything, rotating every password and secret key, and then asking Google to review and clear any warnings. Each step matters; skipping one usually means doing the whole thing twice.
What not to do
- Don't delete the hacked files and assume you are done — the visible spam is the symptom, and cleanup that stops there is the number one cause of reinfection within days.
- Don't restore an old backup as your only fix. The backup may predate the break-in or may itself be infected, and either way the security hole that let the attacker in is still open.
- Don't change passwords from a computer you suspect might have a virus — if your own machine is compromised, the attacker sees the new passwords too.
- Don't pay anyone who contacts you out of the blue claiming they found the hack and can fix it — that message is often part of the scam.
- Don't quietly hide the problem if the site takes customer information — depending on where you operate, you may have a legal duty to look into what was exposed.
- Don't put off cleanup because the site still mostly works. Every day hacked deepens the damage to your Google standing, your email reputation, and your visitors' trust.
When to get help
This is one of the few website problems where recommending professional help is simply the honest advice. The password changes, host contact, and evidence-preserving steps above are genuinely yours to do, and doing them today matters. But the cleanup itself — finding every backdoor among thousands of files, closing the hole that let the attacker in, rotating the secret keys most owners never knew existed, and walking Google through its review process — is detective work that rewards experience. The economics favor it too: a professional cleanup is typically a one-time cost, while a DIY cleanup that misses one hidden file tends to mean doing everything again in a week, plus the ongoing cost of a site Google distrusts. If your site takes orders or represents your business, getting it cleaned properly once is almost always the cheaper path.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
How do WordPress sites get hacked?
Almost always through an outdated plugin or theme with a known security hole, or through a stolen or guessed password. Attackers use automated tools that scan millions of sites for these openings, so small sites get hit just as often as big ones — it is opportunistic, not personal.
Can I clean a hacked WordPress site myself?
You can do the important first steps: change passwords from a clean device, check for unknown admin users, notify your host, and preserve evidence. The deep cleanup — finding hidden backdoor files and closing the original hole — is where DIY attempts usually fall short, and a missed backdoor means reinfection within days.
Why does my site keep getting hacked again after cleanup?
Because the cleanup removed the visible damage but not the hidden backdoor files the attacker installed, or left the original security hole open. Reinfection after a partial cleanup is the most common hacked-site story. A thorough cleanup addresses the files, the entry point, and every password and secret key.
Will restoring a backup fix a hacked WordPress site?
Rarely on its own. The backup may already contain the infection, and even a clean restore leaves open the security hole that let the attacker in — so the site gets hacked again the same way. A restore can be part of recovery, but only alongside updates, password rotation, and closing the entry point.
How long does it take to clean a hacked WordPress site?
A professional cleanup of a typical small-business site often takes a day or two, sometimes less. Getting Google to remove warnings after cleanup usually takes a few more days once a review is requested. Partial DIY cleanups tend to take longer overall because the work gets repeated after reinfection.
Does being hacked hurt my Google rankings?
Yes, while it lasts. Google may label the site as hacked or deceptive, which collapses clicks, and spam pages pollute your search results. The good news: after a proper cleanup and a successful review request, warnings are removed and rankings generally recover over the following weeks.