Table of Contents
- Introduction
- Why my site redirects to spam without me touching anything
- The most common types of spam redirect
- Where the malicious code is usually hidden
- What to do step by step
- Why manual cleanup without experience usually fails
- When to get professional help
- Conclusion
Introduction
You visit your own site, or a customer tells you, and suddenly you end up on an online casino page, a shady pharmacy, or a replica store that has nothing to do with you. You haven't touched anything. You haven't installed any new plugin. And yet your site keeps redirecting on its own.
The good news is that this has a very specific explanation and, in most cases, a clear fix. The bad news is that it means your WordPress has been hacked, and the longer it takes to fix, the more damage it does to your traffic, your rankings and your reputation.
In this article I'll explain exactly why this happens, the most common types of redirect, and what to do to fix it. If you want the full picture of what to do when your WordPress gets hacked, here's the general guide: My WordPress Site Was Hacked: What to Do Step by Step.
Why my site redirects to spam without me touching anything
An attacker who gains access to your WordPress usually doesn't destroy the site on purpose. They're much more interested in keeping it looking normal while using it to generate traffic or ad revenue for other sites: casinos, unregulated online pharmacies, counterfeit brand stores, or phishing pages.
To do that, they inject code that redirects visitors (or search engines) to those sites, without you having to do anything for it to keep working. While you're not looking, the redirect keeps making money for someone else at the expense of your domain and your reputation.
The most common types of spam redirect
Not all redirects behave the same way, which explains why sometimes "nothing looks wrong" when you visit your own site:
- Full redirect: any visitor, including you, gets redirected immediately.
- Mobile-only redirect: many attacks only redirect if they detect the visitor is on a mobile device, precisely so the owner (who usually checks from a desktop) doesn't notice.
- Search-engine-referral-only redirect (cloaking): the code detects if the visitor clicked through from Google, and only then redirects. If you type the URL directly into your browser, the site looks perfectly normal. This kind of cloaking is exactly what usually triggers Google flagging your site as potentially hacked in search results.
- Intermittent redirect: only active at certain times or randomly, to make it harder to detect and reproduce during a quick check.
This is exactly why many people take weeks to notice: they check their own site as a logged-in admin, from their computer, not arriving from a Google search — and the redirect simply never triggers for them.
Where the malicious code is usually hidden
The code responsible for the redirect is almost never in plain sight. The most common places it hides are:
- The .htaccess file, with conditional redirect rules.
- The active theme's functions.php, with PHP code that decides when to redirect.
- wp-config.php, in more sophisticated cases.
- Nulled plugins or themes (pirated "premium" versions) that ship with the backdoor built in from day one.
- Directly in the database, in the
wp_optionstable, where some hacks store the malicious script so it survives a surface-level file cleanup.
What to do step by step
- Don't delete anything yet. You need to identify the entry vector before cleaning, or the problem will come back within days.
- Change every password (WordPress, hosting, FTP) from a clean device.
- Check the redirect from different scenarios: mobile, logged out, arriving from a Google link in incognito mode. This confirms whether it's cloaking or a full redirect.
- Check the .htaccess file for redirect rules you didn't add.
- Don't trust a "cleanup" that's just deleting random plugins — without identifying the real vector, it's very easy to leave the backdoor intact and have the redirect come back.
Why manual cleanup without experience usually fails
It's common for someone to delete the suspicious .htaccess file, breathe a sigh of relief, and then have the redirect come back within days. That happens because .htaccess is almost never the root cause: it's just the visible symptom of a backdoor that's still active somewhere else (a plugin, an uploaded file, the database) and simply rewrites the redirect rule as soon as it detects it was deleted.
A real cleanup has to identify and close that entry point, not just delete the visible effect.
When to get professional help
If your site is redirecting to spam right now, every day that passes is lost traffic, damaged rankings, and customers losing trust in your brand. You can try a manual cleanup if you have the technical experience, but if you want someone to identify the real vector, remove the malware and close the door so it doesn't happen again, here's how I approach hacked WordPress cleanup, with a free 24h diagnosis: Fix a hacked WordPress site
Conclusion
A spam redirect isn't a random glitch or a "bug" in your site: it's the direct consequence of an active hack that someone is exploiting right now. Identifying the type of redirect, finding where the code is hidden, and closing the entry point is what separates a cleanup that lasts from one that repeats two weeks later.