WordPress ·

Hacked WordPress Site? What to Do, Step by Step

By Manu Mathew, Technical Lead Engineer · Last updated 8 October 2026

Isometric illustration of a person swapping cracked dark blocks in a website building, beside backup boxes and a blue shield

You open your website and it redirects to a page you’ve never seen. Or a customer tells you Google shows a warning next to your business name. Either way, your stomach drops.

A hacked WordPress site is stressful, but it’s fixable. The order in which you do things matters more than speed, and a calm, careful clean-up is what stops the problem coming back.

Quick answer

If your WordPress site has been hacked, work in order: note what you see, take a copy of the site as it is, and change every password. Then restore a clean backup or carefully replace infected files. Finally, update everything, find how the attacker got in, and ask Google to review the site.

How do you know your WordPress site has been hacked?

The clearest signs are things you didn’t do yourself: strange pages, redirects, new users or warnings from Google or your host.

Some hacks hide from logged-in owners, so a site that looks fine to you may still be affected. The WordPress.org guide for hacked sites calls these signs indicators of compromise, and suggests writing them down.

What should you do first when your site is hacked?

Contain the damage and keep a record before you delete anything. Rushing to remove files can destroy the clues you need.

  1. Write down what you’ve seen. What looks wrong, when you noticed it, and anything that changed recently, such as a new plugin.
  2. Tell your host. They may see the problem in server logs, and some will help with the clean-up.
  3. Take a copy of the hacked site. Back up the files and database as they are now. It’s evidence, not something to restore.
  4. Change every password. WordPress admin users, hosting, FTP or SFTP, the database, and the email accounts linked to the site.
  5. Remove accounts you don’t recognise. Check WordPress users and hosting users, and turn on two-factor sign-in for the rest.

If the site is collecting payments or personal details, consider putting it into maintenance mode until it’s clean.

How do you clean a hacked WordPress site?

You have three realistic choices: restore a clean backup, clean the existing site, or rebuild. The right one depends on how good your backups are.

Three dashed paths from a cracked site block to a backup box, a magnifying glass over code blocks, and a new building
OptionWhen it suitsWatch out for
Restore a clean backupYou have a backup from before the hackIt may already be infected; you lose newer changes
Clean the existing siteNo clean backup, or recent content mattersTakes care and time; easy to miss a hidden file
RebuildThe site is old, heavily infected or due a refreshMore work, but you start from a known clean state

Whichever you choose, the clean-up should cover the same ground:

A security plugin’s scan helps you find things, but treat its “all clear” as a starting point, not proof.

How do you remove Google’s hacked site warning?

Fix the site first, then ask Google to check it again from Search Console. The warning won’t lift on its own straight away.

Open the Security issues report in Search Console to see what Google found and which pages it flagged. Once you’re sure the problem is fixed, request a review from that report. Google says a review can take from a few days to a few weeks.

Requesting a review before the site is really clean can slow things down, so check the sample pages carefully first. It’s also worth searching site:yourdomain.com for spam pages and removing any that remain.

How do WordPress sites usually get hacked?

Usually through a known weakness that was never fixed, rather than a clever new attack. Finding which one applies to you is what prevents a repeat.

The usual causes are:

If you can’t find the cause, assume it’s still open. Cleaning without closing the gap is how sites end up hacked again a few weeks later.

How do you stop it happening again?

Keep things updated, limit who can sign in, and make sure you can restore a clean copy. Those habits cover the most common ways in.

WordPress’s own hardening guide goes further, and your hosting matters too.

How do I handle a hacked site with a client?

I treat it as an incident with a written record, not a quick fix. The owner should understand what happened and what changed.

My usual steps are:

Frequently asked questions

Can I just restore yesterday’s backup?

Only if you’re sure the backup was taken before the hack, and even then you must fix the weakness the attacker used. Many hacks sit quietly for weeks before anyone notices, so recent backups can be infected too. After restoring, update everything and change all passwords straight away.

Will a security plugin fix a hacked WordPress site?

A security plugin can help you find infected files and block some attacks, but it rarely removes everything on its own. Hidden files, rogue admin users and injected database content are easy to miss. Use the scan as a guide, then check core files, plugins, uploads and users yourself.

Will being hacked hurt my Google rankings?

It can, especially if Google shows a warning or finds spam pages on your site, because visitors avoid flagged results. Once the site is clean and Google has reviewed it, the warning is removed. Cleaning up spam pages and checking Search Console afterwards helps your normal results return.

How much does it cost to fix a hacked WordPress site?

It depends on how badly the site is affected, whether clean backups exist and whether a rebuild makes more sense. A quick restore is very different from a deep clean of a large shop. Ask for an honest look at the site first, then a quote for the work it actually needs.

Do I need to tell my customers?

If the site stores customer details, such as orders, accounts or form entries, those details may have been exposed. Take advice on any legal duty to inform people, and tell your payment provider if payments were involved. For a simple brochure site with no stored data, a clean-up is usually enough.

Need help with a hacked or fragile site?

Whether your site has been hacked or you’d like to make it harder to break into, I’m happy to talk it through. I work on WordPress sites for small businesses as a WordPress developer in Kozhikode, across Kerala and remotely, and the WordPress websites page covers the kinds of work I take on.

You can reach me through the contact section or email me at manu@manu.co.in. Tell me a little about your business and the site, and we’ll go from there.

Back to the blog