Guide

Hacked WordPress site: what to do in the first hour, and after

Updated

A calm, ordered checklist for when your WordPress site has been hacked, written for business owners rather than developers.

Finding out your site has been hacked is unsettling, and the first instinct is to start deleting things. Don't. The order you do things in matters: some steps protect your customers, some protect the evidence, and some make the cleanup faster and less costly.

This guide covers the first hour, how to confirm it really is a hack, what a proper cleanup involves, and how to stop it happening again.

The first hour: a checklist

  1. Don't delete anything. Not the site, not strange files, not unknown users. Deleting removes the trail that shows how the attacker got in, and a half-deleted infection often hides a backdoor that keeps working.
  2. Back up the site as it is, hacked state included. In your hosting panel, look for "Backups" and create a new full backup of files and database, or download both. Label it clearly. It is your evidence, and your safety net if a cleanup step goes wrong.
  3. Protect your visitors. If the site is redirecting people to scam pages, take it offline. Many hosts let you disable a site from the control panel. If you can still log in to WordPress, a maintenance mode plugin shows visitors a holding page. If you can do neither, ask your host to suspend it temporarily.
  4. Change passwords, from a clean computer. Your hosting account, every WordPress administrator, FTP and SFTP accounts, the database password, and the email account linked to the site. Use long, unique passwords and turn on two-factor login wherever it's offered.
  5. Tell your host. They may already know: hosts often suspend hacked sites and email a malware notice. They can tell you what their scanners found, check whether other sites on your account are affected, and sometimes restore a clean server backup.
  6. Write down what you saw. When you first noticed, what visitors reported, and any warning emails. Dates help work out how long the site has been compromised and which backups are clean.

How to tell it's really hacked

Hacks rarely look like a broken site to the owner. They look broken to visitors and search engines. Common signs:

  • Browser warnings. Chrome shows a red page saying "Deceptive site ahead" or "The site ahead contains malware".
  • Spam redirects. Visitors, often only those on phones or arriving from Google, land on a different site. You may not see it yourself while logged in.
  • Strange search results. Search Google for site:yourdomain.com. Pages selling pills, replica goods or casino games, often in other languages, mean spam was injected.
  • Unknown admin users. Under Users in the dashboard, filter by Administrator. Any account you don't recognise is a serious sign.
  • Host suspension or a Search Console alert. In Google Search Console, the Security Issues report lists hacked content Google has found.
  • Injected links. Hidden links to unrelated sites in your footer or page source. Right-click a page, choose "View page source" and search for words that don't belong.

A site that only shows an error or a white screen is more likely broken than hacked. Our guides to the critical error message and the white screen of death cover those.

What a proper cleanup involves

Removing the visible malware is the easy part. A cleanup that holds goes through these stages:

  1. Contain. Snapshot the site, rotate every password and the WordPress security keys in wp-config.php, and remove unknown users.
  2. Clean the files. Replace WordPress core, plugins and themes with fresh copies from their official sources, then review everything else, especially wp-content/uploads, where PHP files should never be.
  3. Clean the database. Spam posts, injected scripts inside content and widgets, and rogue options that reload malware.
  4. Find the way in. Server access logs and file dates usually show whether it was an outdated plugin, a stolen password or a leftover file. Without this step, the hack comes back.
  5. Harden. Remove unused plugins and themes, fix file permissions, disable file editing from the dashboard, and limit login attempts.
  6. Clear the warnings. Request a review in Google Search Console under Security Issues, and ask your host to lift any suspension. Blocklist removal is in their hands, but reviews of a clean site are usually quick.

Why sites get reinfected

Most sites that are hacked twice in a month had one of three problems after the first cleanup:

  • A missed backdoor. Attackers leave small scripts, often disguised with names like wp-cache.php, that let them back in later. One missed file is enough.
  • The hole stayed open. The outdated plugin is still installed, or the leaked password was never changed.
  • Another site on the same hosting account. An old test copy in a subfolder gets reinfected and spreads back.

That's why our cleanup includes a free re-clean if the site is reinfected within 30 days. It's also why we look at the whole hosting account, not just the site that showed symptoms.

How to stop it happening again

  • Update WordPress, plugins and themes promptly. Most hacks use security holes that already had a fix published.
  • Delete plugins and themes you don't use, and never install "nulled" copies of paid plugins.
  • Give administrator rights only to people who need them, and remove old developer accounts.
  • Use unique passwords and two-factor login for WordPress and hosting.
  • Keep daily off-site backups, so a clean restore point always exists.

Most of this is routine, and routine is what gets skipped when nobody owns the site. Our care plans handle it for $249/month: updates tested on a copy of your site first, daily backups, and security monitoring with hack cleanup included.

When to stop and call someone

Do the first-hour checklist yourself. Beyond that, call for help if the site takes payments or holds customer data, if Google is showing a warning, if your host has suspended the account, or if you've cleaned it once and it came back. Our hacked WordPress site cleanup is a flat $899, includes 60 days of the Care plan, and comes with a report of how they got in.

Rather we handle it? Flat $899, free re-clean if reinfected within 30 days. No fix, no charge. Then keep it clean with a care plan.

Start the cleanup

Questions we get asked

Should I delete my hacked WordPress site and start again?

No. Deleting destroys the evidence of how they got in and usually loses content you need. Rebuilding from the same plugins and passwords also leaves the same hole open.

Will a security plugin clean my site?

Scanners are good at finding known malware in files, but they often miss backdoors hidden in the database or in files that look normal. If the way in isn't closed, the infection usually returns.

How long does it take Google to remove the warning?

Once the site is clean, you request a review in Google Search Console under Security Issues. Reviews usually take a few days, but the timing is up to Google.

Why does my site keep getting hacked again?

Usually because a backdoor was missed or the original way in, such as an outdated plugin or a leaked password, was never closed. Reinfection within weeks is a sign the cleanup was incomplete.

What does a professional cleanup cost?

Our hacked site cleanup is a flat $899, with 60 days of the Care plan and a free re-clean if the site is reinfected within 30 days. No fix, no charge.