Table of Contents
- Introduction
- How to know if your WordPress site has been hacked
- Why WordPress sites get hacked
- What to do immediately if you suspect you've been hacked
- Why a free security plugin isn't enough
- How a hacked WordPress site actually gets cleaned (the professional process)
- How to stop it from happening again
- Conclusion
Introduction
If you're reading this, something is probably wrong: your site is redirecting to strange places, Google has warned you that "this site may be hacked," or your host has suspended your account without warning.
A hacked WordPress site is not just a technical problem. It's a business problem: you lose visitors, you lose rankings, and in many cases you lose your customers' trust. And every hour that passes without action, the damage compounds.
In this article we'll look at how to confirm your WordPress site has really been hacked, why it happens, what to do in the first few hours, and how a compromised site actually gets cleaned and secured professionally.
How to know if your WordPress site has been hacked
It's not always obvious. Many hacks are designed to stay hidden for weeks while quietly generating spam traffic or stealing data. These are the most common signs:
- Strange redirects to spam sites, online casinos or pharmacies.
- The "This site may be hacked" warning in Google search results.
- Your host notifying you of "malicious activity" or suspending your account outright.
- Admin users in WordPress that you never created.
- Sudden slowness, server crashes, or abnormal resource usage.
- Chrome or Google Safe Browsing blocking access to your own site.
- Customers reporting spam that appears to come "from your domain".
- Strange files or lines of code (backdoors, obfuscated scripts) on the server.
If you recognise one or more of these signs, it's time to act, not to wait and see if it "fixes itself".
Why WordPress sites get hacked
WordPress powers over 40% of websites on the internet, which makes it a constant target for automated attacks. Most hacks aren't targeted at you specifically: they're bots scanning the internet for sites with known vulnerabilities.
The most common entry vectors are:
- Outdated plugins and themes with publicly known vulnerabilities.
- Weak or reused passwords on the admin user.
- Nulled or pirated software ("free premium" plugins/themes) that ships with backdoors baked in.
- Compromised shared hosting, where another site on the same server infects yours.
- Missing WordPress core updates for months at a time.
It's almost always a combination of several of these factors, not just one.
What to do immediately if you suspect you've been hacked
- Don't delete anything yet. If you have a recent backup, set it aside; if you don't, you don't need one to start diagnosing.
- Change every password — WordPress, hosting, FTP — from a device you know is clean.
- Put the site into maintenance mode if you can, so you stop serving malicious content to visitors while you investigate.
- Don't trust a "cleanup" that's just deleting random plugins. Without knowing the real entry vector, it's easy to leave hidden backdoors that reinfect the site within days.
- Get a professional diagnosis before making big decisions like reinstalling everything from scratch, which can cost you legitimate content.
Why a free security plugin isn't enough
Security plugins (Wordfence, Sucuri and similar free tiers) are useful for prevention, but they have clear limits once a site is already compromised:
- They detect known malware, but many backdoors are specifically designed to evade these signatures.
- They don't identify the real entry vector, so even if they "clean" files, the door the attacker used stays open.
- They don't handle the communication with Google Safe Browsing or your host to restore your reputation.
- They give a false sense of security: "the plugin says it's clean" isn't the same as actually being clean.
They're a solid first layer of preventive defence. They're not a cleanup solution once the hack has already happened.
How a hacked WordPress site actually gets cleaned (the professional process)
A proper cleanup follows a process, not a series of random attempts:
- Full diagnosis: identify every infected file, the exact entry vector, and the real extent of the damage.
- Malware removal: clean core, theme and plugin files without destroying legitimate content.
- Closing the security hole: if the entry point isn't closed, the hack repeats within days or weeks.
- Hardening: strengthen security (two-factor authentication, security headers, blocking file editing from the dashboard) so it's much harder for it to happen again.
- Reputation management: request a review with Google Safe Browsing and coordinate with the host to restore access if it was suspended.
If you'd rather have someone handle this whole process for you, here's how I approach cleanup and security for hacked WordPress sites, with a free 24h diagnosis: Fix a hacked WordPress site
How to stop it from happening again
Cleaning the hack is only half the job. To keep it from repeating:
- Keep WordPress core, plugins and themes always up to date.
- Use unique, strong passwords, with two-factor authentication for the admin account.
- Remove plugins and themes you don't use, even if they're deactivated.
- Consider ongoing monitoring: a monthly scan catches an intrusion attempt before it becomes a real problem.
- Take automatic, regular backups, stored outside your hosting account.
Conclusion
A hacked WordPress site doesn't get fixed by deleting random plugins or waiting for a free plugin to "detect" it. It gets fixed with a real diagnosis, a complete malware cleanup, closing the door the attacker used, and hardening the site so it doesn't happen again.
The sooner you act, the smaller the damage to your traffic, rankings and reputation. If your site is hacked right now, you can request a free 24h diagnosis here: Fix a hacked WordPress site