WordPress Site Redirecting to Spam Sites? How to Find and Fix the Redirect Hack
Why a hacked WordPress site redirects visitors to spam or scam sites (often only on mobile or from Google), where the redirect code hides, how to test for it and how to remove it for good.

On this page
- Redirect malware often hides from logged-in owners and triggers only on mobile or from Google.
- Test in private windows on mobile data, check page source and network requests.
- Clean .htaccess, theme, plugin, database and JS files, then clear all caches.
Customers say your website sends them to a gambling, dating or fake prize site, but when you open it, everything looks normal. That's typical of a redirect hack: the malicious code is designed to hide from site owners so it survives longer.
Why you might not see it
Redirect malware is often conditional. It may only trigger:
- For visitors arriving from Google or social media
- On mobile devices
- For visitors who aren't logged in to WordPress
- Once per visitor, using a cookie so repeat visits look normal
- For certain countries
How to test for it
- Open your site in a private window on your phone using mobile data
- Search Google for your business and click through from the results
- Clear cookies between tests
- View the page source and look for unfamiliar scripts, especially long obfuscated code
- Use your browser's developer tools (Network tab) to see requests to unknown domains
- Run a remote malware scanner
Where redirect code hides
| Location | What to look for |
|---|---|
| .htaccess files | Rewrite rules sending visitors to external sites based on referrer or device |
| Theme files (header.php, footer.php, functions.php) | Injected scripts or PHP redirect code |
| Plugin files | Code added to legitimate plugins, or fake plugins with harmless-sounding names |
| Database | Scripts injected into posts, widgets, theme options or plugin settings; changed site URL settings |
| Core files | Modified index.php, wp-config.php or files in wp-includes |
| JavaScript files | Malicious code appended to your theme's or plugins' .js files |
How to fix it
- Back up the site, then change all passwords
- Replace WordPress core, plugins and themes with clean copies
- Inspect and clean .htaccess files and the database
- Remove unknown admin users and backdoors; see finding backdoors
- Clear all caches and the CDN, since cached pages can keep serving the redirect
- Test again from mobile, Google and a private window
The full process is in how to remove malware step by step.
Why it keeps coming back
If the redirect returns days later, a backdoor remains or the original vulnerability is still open, such as an outdated plugin or a compromised password. Some infections also reinstall themselves through scheduled tasks.
Check Google too
Redirect hacks often lead to a browser warning or "This site may be hacked" in search results. Check Search Console's Security issues report and request a review once clean; see fixing browser warnings.
Need it fixed urgently? See WordPress malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


