To tell if your WordPress site has been hacked, look for six signs that almost always mean a compromise: admin accounts you did not create, visitors redirected to spam sites, a Google “this site may be hacked” warning, content you never published, being locked out of your dashboard with the correct password, and a suspension notice from your host. Confirm any of them with an outside scan before you touch a file.
Most WordPress hacks are not personal. Bots scan the web for a weak password or an outdated plugin, then exploit whatever they find.
We clean these across client sites, and two reactions cause the most damage. One is panic, which leads to deleting files at random. The other is denial, which means ignoring the warning because the site still loads. Neither is the right first move.
Start by working out what you are actually dealing with. This guide covers both halves: how to tell, and what to do next.
What are the signs your WordPress site has been hacked?
The signs range from near-proof to easy to misread. Treating them all as equal is how people panic over nothing or miss a real breach.
It helps to group symptoms by how conclusive each one is. Some almost always mean a compromise. Others deserve a closer look. A third group usually turns out to be something else entirely.
The six signs that almost certainly mean a hack
These rarely have an innocent explanation. If you see any of them, treat the site as compromised and move to the confirmation step:
- Admin user accounts you did not create. Creating a hidden admin is one of the first things an attacker does, because it guarantees a way back in.
- Your site redirects visitors to spam, adult, or unrelated third-party sites.
- Google shows a “Deceptive site ahead” or “This site may be hacked” warning in search results or the browser.
- Someone defaced your homepage, or content appears that you never published.
- You cannot reach your own dashboard despite using the correct password.
- Your hosting provider suspended your account or emailed you about malicious activity.
Signs worth investigating
These often point to a hack, but they occasionally have another cause. Verify before you conclude:
- Unfamiliar .php files in wp-content/uploads. That folder should never hold executable PHP.
- SEO spam: pages, posts, or pharmaceutical keywords on hidden pages you did not create. Attackers build these to manipulate search engines.
- Your domain sending spam email, or visitors reporting spam that appears to come from you. Check first whether your mail simply broke, since WordPress emails not sending produces confusing symptoms of its own.
- New plugins you did not install, or security plugins that suddenly stopped working.
- A sudden, unexplained drop in traffic. Malware redirecting visitors causes this, and so does a security blocklist. Ordinary page indexing issues cause it too.
Signs that are often a false alarm
People blame hackers for these constantly. Most of the time the cause is mundane:
- A slow site on its own. Heavy traffic, a bloated plugin, or weak hosting explain a slow WordPress website far more often than malware.
- A single error message after an update. That usually means a plugin or theme conflict, and our guide to common WordPress errors covers the usual suspects.
- Layout glitches right after you changed a theme or plugin. A page builder problem looks alarming and rarely involves an attacker.
A misbehaving site is worth checking. On its own it is weak evidence. Pair it with something from the first group before you assume the worst.
How do you check if your WordPress site is hacked?
Confirm with outside tools before you touch a single file. Acting on a guess wastes time and can make a fixable problem worse. Confirmation takes a few minutes and removes the doubt. Run these checks in order.
Check from the outside first
Start with an external remote scanner. A free tool like Sucuri SiteCheck browses your public pages from the outside and flags known malware, injected scripts, and security blocklist status. You install nothing.
Then check Google Safe Browsing. If you have Search Console connected, open the Security Issues report. It tells you whether Google detected a compromise and what type.
Check inside the site
Review your admin users for any account you do not recognise. Connect over SFTP and look at when core files last changed. A fresh modification date on a core file you never edited is a strong signal.
Then scan file contents for the code patterns attackers hide: base64_decode, eval, gzinflate, and unusual include statements. Check wp-config.php, .htaccess, and anything in the uploads folder first. Obfuscated code where none belongs confirms what the external scan suggested.
What if every check comes back clean?
Then you probably have a caching, hosting, or plugin problem rather than a hack. That applies when the external scan is clean, Google reports no issues, every admin user belongs there, and no core file shows unexpected changes.
This is a genuinely useful outcome. It stops you from tearing apart a site nobody breached.
What should you do first if your site is hacked?
Contain the site before you clean it. Restoring a backup or deleting files immediately is the wrong first move. You can lose evidence, reintroduce the infection, or lock yourself out mid-cleanup. Work this sequence in order.
First, put the site into maintenance mode. Visitors should not see a defaced page or meet malware. If you can reach the dashboard, a maintenance plugin does this in seconds. If you cannot, add a rule to the top of your .htaccess file over FTP that sends every visitor except your own IP address away from the site.
Second, force everyone out and lock the doors. Reset all passwords, starting with administrators, then reset your hosting and database passwords too. Rotate the secret keys in wp-config.php using the official WordPress key generator. That invalidates every active session and ejects any attacker who is still logged in. Changing a password on its own does not end an existing session, so this step matters more than it looks.
Third, contact your host. Open a high-priority ticket and say the site is compromised. Ask for any scan logs or details they hold about suspicious files. They see server-level activity you cannot, which makes a good host one of your most useful allies in a cleanup.
Only once the site is contained do you move to removing the infection.
How do you clean a hacked WordPress site?
Cleaning means removing every trace of the infection, then confirming it is gone, without bringing it back.
Before you change anything, back up the current infected state. That sounds odd. It preserves evidence and gives you a fallback if cleaning breaks something, as long as you never restore that copy to a live site.
Run a deep scan with a security plugin such as Wordfence, Sucuri, or MalCare. These inspect files and the database more thoroughly than an external scanner. Remove or replace whatever malicious files they surface.
Then replace WordPress core files with fresh copies, review wp-config.php and .htaccess for injected code, and check the uploads folder for executable PHP. If the database carries a heavy infection and you cannot separate legitimate content from injected content, a known-clean backup from before the hack is often the safer path. Our WordPress malware removal guide walks through the full process.
Here is the honest tradeoff on doing this yourself. A technically confident owner can clean a straightforward infection with the steps above, and it saves money. Hacks hide backdoors, though, and missing one lets the attacker walk back in days later. If you are not fully sure you found everything, paid removal earns its cost, because a failed DIY clean fails silently.
After cleaning, re-scan until you get a clean result. Ask your host to rescan too. If Google flagged you, request a review in Search Console.
How do you keep it from happening again?
Preventing reinfection means closing the entry point the attacker used, not just removing what they left behind. Cleaning a site without hardening it is like mopping the floor while the roof still leaks. The most common reason sites get reinfected is that nobody fixed the original vulnerability.
Update WordPress core, every plugin, and every theme immediately. Outdated software remains the most common attack vector. Delete any plugin or theme you no longer use, since dormant code stays exploitable. Rotate all credentials again now that the site is clean.
Then add two layers. Enable two-factor authentication on every admin account, and add a firewall through a security plugin to block malicious traffic before it reaches your site. Ask your host what hardening they offer at server level too.
The goal is simple: lock the door the bot walked through before you reopen the site. Ongoing maintenance is what keeps that door shut, since most reinfections trace back to an update nobody applied.
What are the most costly mistakes people make?
The expensive mistakes feel like progress and quietly undo your work.
Watch for these four, because each one turns a one-time hack into a recurring nightmare:
- Restoring an infected backup. A backup made after the breach carries the malware straight back in. Always scan a backup before you restore it.
- Cleaning without fixing the entry point. Remove the malware but leave the vulnerable plugin, and the attacker returns through the same hole.
- Rushing back online. A few extra hours in maintenance mode beats another full compromise a week later.
- Ignoring it because the site still loads. A hacked site that looks fine to you may be redirecting visitors, sending spam, or hosting malware that lands your domain on security blocklists. Working does not mean clean.
When should you call for help?
Call in help when the stakes or the complexity outrun your comfort level. Get outside help if the infection keeps returning after you cleaned it. The same applies if your host suspended your account, if the site still shows as unsafe after cleanup, if you lack time to do the work carefully, or if hidden backdoors worry you.
There is no failure in handing it over. A hacked business site loses trust and revenue every hour it stays compromised, and a missed backdoor means paying for the cleanup twice. If the site matters to your livelihood, someone who does this daily almost always costs less than a second breach.
Conclusion
The fastest way to check if your WordPress site is hacked is to look for admin users you did not create, redirects to spam sites, Google security warnings, and content you never added. A slow site alone usually means something else.
Confirm any suspicion with an external scanner and a file check before you act. When the hack is real, contain it first with maintenance mode and a full credential and secret-key reset. Then clean it with a deep scan or a known-clean backup. Finally, close the entry point by updating everything and hardening the site.
The costliest mistakes are restoring an infected backup and cleaning without fixing the vulnerability that let the attacker in.
Frequently asked questions
How do I know if my WordPress site has been hacked?
Look for the signs that rarely have an innocent explanation: admin users you did not create, visitors being redirected to spam sites, a Google “This site may be hacked” warning, content you never published, or a suspension email from your host. Any one of those is enough to treat the site as compromised. A slow site or a single error message on its own is weak evidence and usually has a different cause.
How do I check if my WordPress site is hacked?
Run an external scanner such as Sucuri SiteCheck, then check Google Safe Browsing and the Security Issues report in Search Console. Next, review your admin users for accounts you do not recognise, and check whether core files changed recently. Obfuscated code in wp-config.php or the uploads folder confirms a compromise.
Can a small WordPress site really get hacked?
Yes. Most hacks run automatically rather than targeting anyone, so site size protects nobody. Bots scan continuously for weak passwords, outdated plugins, and known vulnerabilities, then exploit whatever they find. A small personal site with an outdated plugin is just as exploitable as a large one.
How do I know if it is a hack or just a plugin bug?
Confirm with outside tools before assuming either. Run an external scanner and check Google Safe Browsing for a warning. Review your admin users and look at core file modification dates. Clean scans, no unknown admins, and unchanged files point to a caching issue or plugin conflict instead.
Will I lose my site or my data if it is hacked?
Usually not, provided you act carefully. Most infections clean up without losing content, especially with a clean backup from before the breach. The real risk is panic: deleting files blindly or restoring an infected backup causes more damage than the hack. Back up the current state first and work methodically.
Can I clean a hacked WordPress site myself?
Sometimes. A technically confident owner can clean a straightforward infection by scanning, removing malicious files, replacing core files, and hardening the site. Hidden backdoors are the risk, since missing one causes reinfection. If the hack keeps returning or your host suspended you, paid malware removal is worth the cost.
How long does it take to recover from a WordPress hack?
It varies by severity. A straightforward infection caught early takes a few hours to confirm, clean, and harden. A deep compromise with database infection, multiple backdoors, or a host suspension takes a day or more, plus time for Google to clear its warning after you request a review.
How did my WordPress site get hacked in the first place?
Most commonly through an outdated plugin, theme, or core version with a known vulnerability, a weak or reused password, or a compromised hosting account. Attackers rarely pick a specific site. Bots find the weakness automatically. Closing that entry point during recovery matters most, since leaving it open causes most reinfections.
Worried your site is compromised and want it handled right?
If you have spotted the signs and would rather have someone confirm, clean, and secure the site than work through it under pressure, that is what we do. Survyc is an AI-first digital agency that handles WordPress security, malware removal, and hardening for agencies and their clients, working as an embedded part of your team. We find the entry point, remove every backdoor, and hand the site back secured rather than patched. Get in touch or tell us what you are seeing at info@survyc.com.