Security

WordPress Site Redirecting to Spam Sites? How to Find and Fix the Redirect Hack

Why a hacked WordPress site redirects visitors to spam or scam sites (often only on mobile or from Google), where the redirect code hides, how to test for it and how to remove it for good.

WordPress Site Redirecting to Spam Sites? How to Find and Fix the Redirect Hack
On this page
  1. Why you might not see it
  2. How to test for it
  3. Where redirect code hides
  4. How to fix it
  5. Why it keeps coming back
  6. Check Google too
Key takeaways
  • Redirect malware often hides from logged-in owners and triggers only on mobile or from Google.
  • Test in private windows on mobile data, check page source and network requests.
  • Clean .htaccess, theme, plugin, database and JS files, then clear all caches.

Customers say your website sends them to a gambling, dating or fake prize site, but when you open it, everything looks normal. That's typical of a redirect hack: the malicious code is designed to hide from site owners so it survives longer.

Why you might not see it

Redirect malware is often conditional. It may only trigger:

  • For visitors arriving from Google or social media
  • On mobile devices
  • For visitors who aren't logged in to WordPress
  • Once per visitor, using a cookie so repeat visits look normal
  • For certain countries

How to test for it

  • Open your site in a private window on your phone using mobile data
  • Search Google for your business and click through from the results
  • Clear cookies between tests
  • View the page source and look for unfamiliar scripts, especially long obfuscated code
  • Use your browser's developer tools (Network tab) to see requests to unknown domains
  • Run a remote malware scanner

Where redirect code hides

LocationWhat to look for
.htaccess filesRewrite rules sending visitors to external sites based on referrer or device
Theme files (header.php, footer.php, functions.php)Injected scripts or PHP redirect code
Plugin filesCode added to legitimate plugins, or fake plugins with harmless-sounding names
DatabaseScripts injected into posts, widgets, theme options or plugin settings; changed site URL settings
Core filesModified index.php, wp-config.php or files in wp-includes
JavaScript filesMalicious code appended to your theme's or plugins' .js files

How to fix it

  1. Back up the site, then change all passwords
  2. Replace WordPress core, plugins and themes with clean copies
  3. Inspect and clean .htaccess files and the database
  4. Remove unknown admin users and backdoors; see finding backdoors
  5. Clear all caches and the CDN, since cached pages can keep serving the redirect
  6. Test again from mobile, Google and a private window

The full process is in how to remove malware step by step.

Why it keeps coming back

If the redirect returns days later, a backdoor remains or the original vulnerability is still open, such as an outdated plugin or a compromised password. Some infections also reinstall themselves through scheduled tasks.

Check Google too

Redirect hacks often lead to a browser warning or "This site may be hacked" in search results. Check Search Console's Security issues report and request a review once clean; see fixing browser warnings.

Need it fixed urgently? See WordPress malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now