8 Signs Your WordPress Site Has Been Hacked (and What to Do)
Hacked websites don't always look hacked. Many infections are designed to stay hidden from the site owner while redirecting visitors, injecting spam or stealing data. Here are the warning signs to watch for, and what to do if you spot them.
8 signs your WordPress site is hacked
1. Visitors are redirected to other websites
A classic sign: people clicking your site from Google or on mobile end up on spam, gambling or fake prize sites, while it looks normal when you visit directly as a logged-in admin.
2. Google shows a warning
Messages like "This site may be hacked" in search results, or a red "Deceptive site ahead" browser warning, mean Google has detected a problem.
3. Strange pages appear in Google
Search site:yourdomain.com on Google. If you see pages you never created, often in other languages or about pharmacy products or loans, spam has been injected.
4. Unknown admin users
Check Users in your dashboard. New administrator accounts you didn't create are a serious red flag.
5. Your hosting company suspends the site
Hosts often suspend accounts that send spam emails or run malicious scripts.
6. The site is suddenly very slow or crashes
Malware running in the background can overload your server.
7. Unexpected files or code
Unfamiliar PHP files in your uploads folder, or strange code at the top of theme files, are common signs of an infection.
8. You can't log in
If your password suddenly stops working and the reset email never arrives, someone may have changed your account details.
What to do if your site is hacked
- Don't panic, and don't delete everything. Your real content can usually be saved.
- Take a backup of the current files and database, even though they're infected. It's useful for recovery and investigation.
- Change all passwords: WordPress admins, hosting, FTP/SFTP and database.
- Scan the site with a security plugin or your host's malware scanner.
- Clean infected files and database entries, and reinstall WordPress core, themes and plugins from official sources.
- Remove unknown users and backdoors. Hackers often leave hidden ways to get back in.
- Request a review in Google Search Console once the site is clean, to remove warnings.
- Harden security so it doesn't happen again (below).
How to prevent it happening again
- Keep WordPress, themes and plugins updated. Outdated plugins are the most common way in.
- Delete plugins and themes you don't use.
- Never install "nulled" (pirated) premium themes or plugins. They often contain malware.
- Use strong, unique passwords and two-factor authentication for admins.
- Install a reputable security plugin or firewall.
- Keep automatic off-site backups so you can restore quickly.
- Choose reliable hosting with good security practices.
Need it fixed fast?
Cleaning a hacked site properly takes experience. Removing the visible symptoms isn't enough if a backdoor remains. If your business depends on your website, get professional help quickly: the longer malware stays, the more damage it does to your reputation and Google rankings.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.