Finding out your site has been hacked is stressful, but it’s rarely personal. Almost all WordPress hacks are automated: bots scan millions of sites for a plugin with a known flaw or a password that’s easy to guess, and yours turned up. That also means the fix follows a familiar pattern.
The most common mistake is rushing. Deleting files and reinstalling things straight away feels productive, but it often destroys the clues that show how the attacker got in, and leaves behind the backdoor they’ll use to come back. Work through these steps in order.
First, check it really is a hack
Some problems look like a hack but aren’t. If your site shows a blank white page, a “There has been a critical error on this website” message or a 500 error, it’s far more likely to be a broken update or a plugin conflict. These are the signs of an actual hack:
- Google shows “This site may be hacked” under your site, or browsers show a red “Deceptive site ahead” warning.
- Visitors are redirected to spam, scam or adult sites.
- Google has pages for your site that you didn’t write, often in Japanese or selling pills, fake goods or casino links.
- There are administrator accounts in WordPress that nobody on your team created.
- Your host has emailed you about malware or suspended your account.
Check from a private browser window, and from your phone on mobile data. A lot of malware hides from logged-in administrators and only targets visitors arriving from Google, so the site can look fine to you while your customers see something else. Searching Google for site:yourdomain.com (with your own domain) is a quick way to spot spam pages.
1. Don’t start deleting things
Leave the files alone for now. You’ll need them to work out how the attacker got in, and a hasty clean-up usually misses something. If the site is sending visitors to harmful pages, put it into maintenance mode from your hosting control panel instead, so it’s offline but intact.
2. Take a copy of the site as it is now
Make a full backup of the files and the database, even though they’re infected. Your host’s control panel can usually do this. Label it clearly as the infected copy and keep it somewhere other than the server.
It sounds odd to back up a hacked site, but it means you can compare files later, recover any content you lose in the clean-up, and show someone else what happened if you get help. While you’re there, download the site’s access logs if your host provides them. Many hosts only keep them for a few days, and they’re often the clearest record of how the attacker got in.
3. Change every password
Assume every password connected to the site is known to the attacker. Change them all, from a computer you trust:
- every WordPress administrator account
- your hosting control panel
- SFTP or FTP accounts
- the database password (then update it in
wp-config.phpso the site can still connect) - the email account used to log in to WordPress
Then replace the WordPress security keys in wp-config.php with a fresh set from the WordPress.org secret key generator. This signs everyone out, including anyone who’s logged in with a stolen session.
If your own computer might be infected, fix that first, or your new passwords can be stolen the same way as the old ones.
4. Remove users you don’t recognise
In WordPress, go to Users and filter by Administrator. Delete any account nobody on your team created, and give its content to a real user if WordPress asks.
Some malware hides the accounts it creates from that list. If the number of administrators shown at the top doesn’t match the list, or something doesn’t feel right, check the wp_users table in the database, or ask your host or developer to.
5. Talk to your host
Your host may already know about the problem and can often help more than you’d expect. Ask them:
- Do you have a clean backup from before this started?
- Can you see in the logs how the attacker got in?
- Are other sites on my hosting account infected too?
That last question matters. If you have several sites in one hosting account, an infection on one can spread to the others. Clean only one, and it gets reinfected from its neighbours.
6. Remove the malware
You have three options.
Restore a clean backup. If you know roughly when the hack started and have a backup from before it, restoring is the quickest route. You’ll lose any changes made since, such as orders or form entries, and the gap the attacker used is still there, so go straight on to step 7.
Clean it yourself. If you’re comfortable working with files and the database:
- Replace the
wp-adminandwp-includesfolders with fresh copies of the same WordPress version from WordPress.org. - Delete and reinstall every plugin and theme from its official source. Don’t reuse the copies on the server.
- Look in
wp-content/uploadsfor PHP files. Apart from emptyindex.phpfiles, there’s rarely a good reason for them to be there. - Check
wp-config.php,.htaccessand thewp-content/mu-pluginsfolder for code you didn’t add. - Search the database for injected scripts, especially in posts, widgets and the
wp_optionstable, and check for scheduled tasks you don’t recognise.
Be wary of anything using eval, base64_decode or gzinflate where you wouldn’t expect it. Some legitimate plugins use these too, so compare with a fresh copy before deleting.
Get help. If that list made your heart sink, hand it to someone who does this regularly. A partial clean-up is the main reason sites get hacked again within days: the visible malware is gone, but a backdoor remains.
7. Close the way in
Removing the malware without fixing how it got in is like changing the locks but leaving a window open. The usual causes are:
- a plugin or theme that’s out of date, or has a known flaw with no fix yet (check yours against our list of known plugin vulnerabilities)
- a password that was stolen, reused or easy to guess
- a “nulled” (pirated) plugin or theme, which often comes with malware built in
- another infected site in the same hosting account
Update WordPress, every plugin and every theme. Delete plugins and themes you don’t use, because deactivated ones can still be attacked. Replace any plugin that’s no longer maintained. Turn on two-factor authentication for every administrator.
8. Get Google’s warning removed
Google doesn’t lift a warning by itself straight away. Once your site is clean, open Google Search Console, go to Security & Manual Actions, then Security issues, and request a review. Explain briefly what you found and what you fixed.
Google says malware reviews usually take a few days, and reviews for sites hacked with spam can take several weeks. If the hack created spam pages, make sure they now return a “not found” error, so Google drops them from its results.
9. Keep watching for a few weeks
A site that gets hacked again soon after a clean-up usually still has a backdoor somewhere. For the next few weeks, check for new administrator accounts, look at Google results for your site, and keep an eye on anything your host reports.
Longer term, the things that stop most hacks are dull but effective: keep everything updated, use strong unique passwords with two-factor authentication, and run a firewall and a malware scanner. Keep daily backups somewhere other than your server, for long enough that you can go back to a clean copy even if you only spot a problem weeks later.