Insights · WordPress security

How to tell if your WordPress website has been hacked

A compromised WordPress website does not always display an obvious warning. Some infections stay quiet while creating spam pages, redirecting only selected visitors, or leaving backdoors for later access.

Common signs of a hacked WordPress website

+

Visitors are redirected to unrelated or suspicious websites.

+

Unknown administrator accounts appear in WordPress.

+

Google Search Console reports hacked content or security issues.

+

Spam pages appear in search results even though they are not visible in WordPress.

+

Plugins, themes, or core files cannot be updated or replaced.

+

New PHP or .htaccess files return after you delete them.

+

Your host suspends the account for malware or unusual resource usage.

+

The website sends unexpected email, creates cron jobs, or becomes unusually slow.

Check from outside WordPress first

Open the site in a private browser window and test several pages. Search Google for site:yourdomain.com and look for pages or titles you do not recognise. Check Search Console, your hosting dashboard, security emails, server logs, and recent user accounts.

Testing only while logged in can miss conditional redirects that are shown only to visitors from search engines, mobile devices, or particular countries.

Do not rely on the visible symptom

Deleting one suspicious file or replacing a damaged .htaccess file may restore the site temporarily, but it does not prove that the infection is gone. Attackers commonly leave several entry points, database injections, scheduled tasks, hidden users, or modified plugins.

What to do immediately

  1. Preserve a backup of the current files and database before making destructive changes.
  2. Record warnings, redirects, suspicious users, modified files, and messages from your host.
  3. Avoid sending passwords through ordinary contact forms or chat messages.
  4. Do not blindly delete large groups of files unless you understand what the website needs to run.
  5. Plan to rotate WordPress, hosting, database, SFTP, SSH, and API credentials after the cause is understood.

Why websites become infected again

Reinfection usually means the original access path remained open. That may be an outdated plugin, stolen hosting credentials, another compromised website in the same account, a hidden backdoor, an insecure administrator device, or a scheduled process that recreates malware.

A proper cleanup should therefore include both removal and investigation. Restoring the visible pages without closing the entry point is only a temporary repair.

WordPress malware removal

Suspect your site is compromised?

Send the website URL and the symptoms you noticed. You will receive an assessment and a fixed quote before cleanup begins.

Request an assessment →